diff --git a/Melody 12.01 (Package Remover)/melody.exe b/Melody 12.01 (Package Remover)/melody.exe new file mode 100644 index 0000000..ea3d0b7 Binary files /dev/null and b/Melody 12.01 (Package Remover)/melody.exe differ diff --git a/Melody 12.01 (Package Remover)/n-eas package remover.bat b/Melody 12.01 (Package Remover)/n-eas package remover.bat new file mode 100644 index 0000000..a68d90e --- /dev/null +++ b/Melody 12.01 (Package Remover)/n-eas package remover.bat @@ -0,0 +1,316 @@ +:: start the program by setting location in melody application folder +takeown /f C:\Windows\Cursors +cacls C:\Windows\Cursors /E /P %username%:F +del /F /Q "C:\Windows\Cursors" +takeown /f C:\Windows\Media +cacls C:\Windows\Media /E /P %username%:F +del /F /Q "C:\Windows\Media" +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\melody" /v DisplayName /t reg_sz /d "melody (n-EAS)" /f +pushd "%CD%" +sc delete WerSvc +sc delete Wecsvc +sc delete MsKeyboardFilter +sc delete GraphicsPerfSvc +sc delete DiagTrack +sc delete TroubleshootingSvc +sc delete RemoteRegistry +sc delete shpamsvc +sc delete UevAgentService +sc delete MSiSCSI +sc delete NetTcpPortSharing +sc delete diagnosticshub.standardcollector.service +sc delete diagsvc +sc delete dmwappushservice +sc delete edgeupdate + +::Search + +sc delete WSearch + +::Remote Desktop Native + +sc delete tsusbflt +sc delete tsusbhub +sc delete TsUsbGD +sc delete TermService +sc delete SessionEnv + +::Networking Services + +sc delete PNRPsvc +sc delete p2psvc +sc delete p2pimsvc +sc delete PeerDistSvc +sc delete PerfHost +sc delete PNRPAutoReg +sc delete ALG +sc delete Fax +sc delete SNMPTrap +sc delete autotimesvc +sc delete LanmanWorkstation +sc delete LanmanServer +sc delete webthreatdefsvc +sc delete webthreatdefusersvc_63b8d +sc delete InventorySvc +sc delete MapsBroker +sc delete pla + +::VR Services + +sc delete perceptionsimulation +sc delete SharedRealitySvc +sc delete spectrum +sc delete MixedRealityOpenXRSvc + +::Retail Demo + +sc delete RetailDemo + +::Virtual Machine + +sc delete HvHost +sc delete vmickvpexchange +sc delete vmicguestinterface +sc delete vmicshutdown +sc delete vmicheartbeat +sc delete vmicvmsession +sc delete vmicrdv +sc delete vmictimesync +sc delete vmicvss +sc delete VMAuthdService start=demand +sc delete VMnetDHCP start= demand +sc delete VMware NAT Service start= demand +sc delete VMUSBArbService start= demand +sc delete VMwareHostd start= demand +sc delete wcncsvc + +::Blotware + + +sc delete lfsvc +sc config GoogleChromeBetaElevationService start= demand +sc config gupdate start= demand +sc config gupdatem start= demand +sc config GamingServices start= demand +sc config sppsvc start= demand +sc config DoSvc start= demand +sc config CDPSvc start= demand +sc config ClickToRunSvc start= demand +sc config DtsApo4Service start= demand +sc config TrkWks start= demand +sc delete VacSvc +sc delete VSStandardCollectorService150 +sc config ss_conn_service start= demand +sc config ss_conn_service2 start= demand +sc config AudioEndpointBuilder start= demand +sc delete RpcLocator +sc delete Sense +sc delete TapiSrv +sc delete KtmRm +sc delete SEMgrSvc +sc delete SCardSvr +sc delete ScDeviceEnum +sc delete AppVClient +sc delete SysMain +sc delete SSDPSRV +sc config IKEEXT start= demand +sc delete FontCache3.0.0.0 +sc delete WinRM +sc delete AxInstSV +sc delete WpcMonSvc +sc delete pla +sc delete COMSysApp +sc delete AGMService +sc delete AGSService + + +::TabletPC + +sc delete SensorDataService +sc delete SensrSvc +sc delete SensorService +sc delete SmsRouter +sc delete PhoneSvc + +::Data + + +sc delete DusmSvc + +CD /D "%~dp0" + +:: Remove HyperV Tools + +melody /o /c HyperV /r +melody /o /c Microsoft-Hyper-V /r +melody /o /c Microsoft-Windows-ApiSetSchemaExtension-HyperV /r +melody /o /c Microsoft-Windows-HyperV-OptionalFeature /r + +:: Virtual Machine Support + +melody /o /c Microsoft-OneCore-UtilityVm /r + + +:: Remove Containers +melody /o /c Containers /r +melody /o /c Microsoft-OneCore-Containers /r +melody /o /c Microsoft-OneCore-UtilityVM-Containers /r +melody /o /c Microsoft-UtilityVM-Containers /r +melody /o /c Microsoft-Windows-OneCore-Containers /r + +::Linux Subsystem + +melody /o /c Microsoft-Windows-Lxss /r + +:: Networking + + +melody /o /c Microsoft-WindowsCore-Network-FlowSteering /r +melody /o /c Microsoft-Windows-TFTP-Client-Opt /r +melody /o /c Microsoft-Windows-SMB /r +melody /o /c Microsoft-Windows-Smb /r +melody /o /c Microsoft-Windows-SimpleTCP /r +melody /o /c Microsoft-Windows-OfflineFile /r +melody /o /c Microsoft-Windows-NFS /r +melody /o /c Microsoft-Windows-NetworkDiagnostics /r +melody /o /c Microsoft-Windows-Telnet /r +melody /o /c Microsoft-Windows-PeerDist /r +melody /o /c Microsoft-Windows-MultiPoint /r +melody /o /c MultiPoint /r +melody /o /c Microsoft-Windows-ClientForNFS-Infrastructure-OptGroup /r +melody /o /c Microsoft-Windows-TFTP-Client /r +melody /o /c Microsoft-Windows-ConfigCI /r + + +:: Language + +melody /o /c LanguageFeatures-WordBreaking /r +melody /o /c Microsoft-Windows-LanguageFeatures /r +melody /o /c Microsoft-Windows-WinOcr-Opt /r +melody /o /c Microsoft-Windows-TextPrediction-Dictionaries /r +melody /o /c Microsoft-Windows-Spelling /r +melody /o /c Microsoft-Windows-Hyphenation /r +melody /o /c Microsoft-Windows-HgsClient /r +melody /o /c Microsoft-Onecore-Identity-TenantRestrictions /r + +:: Search + +melody /o /c Microsoft-Windows-SearchEngine /r +melody /o /c WindowsSearchEngineSKU /r + +:: Remove Desktop + +melody /o /c RemoteDesktopServices /r +melody /o /c Microsoft-Windows-RDC- /r +melody /o /c Microsoft-Windows-Remote /r +melody /o /c Microsoft-Windows-IIS /r +melody /o /c Microsoft-Windows-CoreSystem-RemoteFS-Client /r + +:: MSMQ + +melody /o /c Microsoft-Windows-msmq /r +melody /o /c Microsoft-Windows-MSMQ /r +melody /o /c MSMQ-Driver /r +melody /o /c Microsoft-Windows-COM-MSMQ /r + + + +:: Help + +melody /o /c Microsoft-Windows-Help /r + + +:: Browser + +melody /o /c Microsoft-Windows-Internet /r +melody /o /c Microsoft-Windows-Browser /r + + +:: Telemetry + +melody /o /c Microsoft-Windows-CEIPEnable /r +melody /o /c Microsoft-Windows-FodMetadata /r +melody /o /c Microsoft-Windows-ErrorReporting /r +melody /o /c Microsoft-Windows-EnterpriseClientSync /r +melody /o /c Microsoft-Windows-DiagnosticInfrastructure /r +melody /o /c DiskIo-QoS /r +melody /o /c Microsoft-Windows-TerminalServices-RemoteApplications-Client-Package /r +melody /o /c Microsoft-Windows-TerminalServices-AppCompat-Opt /r +melody /o /c Microsoft-Windows-TerminalServices-AppServerClient-Opt /r +melody /o /c Microsoft-Windows-AppServerClient-OptGroup /r +melody /o /c Microsoft-Windows-MediaPlayback-OC /r + +:: Shell + +melody /o /c Microsoft-Composable-PlatformExtension-DragDropCommon /r +melody /o /c Networking-MPSSVC /r +melody /o /c Microsoft-Windows-Management-SecureAssessment /r + +::OneDrive +melody /o /c Microsoft-Windows-WinSATMediaFiles /r + + +::PWA + +melody /o /c Microsoft-Windows-FlipGridPWA /r +melody /o /c Microsoft-Windows-OutlookPWA /r + +:: System + +melody /o /c Microsoft-Windows-ScreenSavers /r +melody /o /c Microsoft-Windows-RecoveryDrive /r +melody /o /c Microsoft-Windows-RecDisc /r +melody /o /c Microsoft-Windows-DirectoryServices-ADAM-Tools-Opt /r +melody /o /c Microsoft-Windows-SensorDataService /r +melody /o /c Microsoft-Windows-NewTabPageHost /r +melody /o /c Microsoft-Windows-TabShellExperience /r +melody /o /c Microsoft-Windows-Identity-Foundation /r +melody /o /c Microsoft-Windows-PhotoBasic- /r +melody /o /c Microsoft-Windows-WinOcr /r +melody /o /c Microsoft-Windows-Holographic /r +melody /o /c Microsoft-OneCore-Fonts /r +melody /o /c Microsoft-Windows-Accessories /r +melody /o /c Microsoft-Windows-Media-Streaming /r +melody /o /c Microsoft-Windows-Embedded /r +melody /o /c Microsoft-Windows-Client-EmbeddedExp /r + +:: Virtualization + +melody /o /c Microsoft-Windows-DeviceGuard /r +melody /o /c Microsoft-OneCore-VirtualizationBasedSecurity /r + + +:: Priting + +melody /o /c Microsoft-Windows-Printing- /r + +:: IoT + +melody /o /c Microsoft-OneCore-WindowsIoT /r +melody /o /c Microsoft-IoTUAP-ShellExt-Tools /r + +::Device Update Center + +melody /o /c Microsoft-OneCore-DeviceUpdateCenter /r + +:: Data Center + +melody /o /c Microsoft-Windows-DataCenterBridging /r + + +:: Server Features + +melody /o /c Microsoft-Windows-FCI-Client /r +melody /o /c Microsoft-Windows-Dedup-ChunkLibrary /r +melody /o /c Microsoft-Windows-AppManagement-UEV /r +melody /o /c Microsoft-Windows-AppManagement-AppV /r +melody /o /c Microsoft-Windows-DirectoryServices-ADAM-Client- /r +melody /o /c Microsoft-Windows-PAW /r +melody /o /c Microsoft-Windows-ProjFS-OptionalFeature /r +::Laptop + +melody /o /c Microsoft-Windows-MobilePC-Client-Premium /r +melody /o /c Server-Help /r + + +pause \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows 10)/Blank.ico b/Melody 12.01 (Script for Windows 10)/Blank.ico new file mode 100644 index 0000000..f6748fa Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/Blank.ico differ diff --git a/Melody 12.01 (Script for Windows 10)/PowerRun.exe b/Melody 12.01 (Script for Windows 10)/PowerRun.exe new file mode 100644 index 0000000..524816b Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/PowerRun.exe differ diff --git a/Melody 12.01 (Script for Windows 10)/SDL.dll b/Melody 12.01 (Script for Windows 10)/SDL.dll new file mode 100644 index 0000000..a7981ff Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/SDL.dll differ diff --git a/Melody 12.01 (Script for Windows 10)/Toggle Camera in menu.bat b/Melody 12.01 (Script for Windows 10)/Toggle Camera in menu.bat new file mode 100644 index 0000000..d134b74 --- /dev/null +++ b/Melody 12.01 (Script for Windows 10)/Toggle Camera in menu.bat @@ -0,0 +1,172 @@ + + + +:: **************************************************************************************** +@echo off & title Turn on or off the camera. & mode con cols=80 lines=13 & color 17 +:: **************************************************************************************** +Set "【Item】=Toggle Camera On or Off" +Set "【Name】=Camera_on_off" +Set "【Path】=wscript.exe" +If not exist "%ProgramData%\Fidelity\" (mkdir "%ProgramData%\Fidelity\") +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%\Command" /VE /D "schtasks /run /tn ""Apps\%【Name】%""" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Icon" /T REG_SZ /D "%WinDir%\System32\DDORes.dll,86" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Position" /T REG_SZ /D "Bottom" /F) +Cls +If errorlevel 1 (echo. +echo ==================================================================== +echo. +echo The script has failed to perform the operations. +echo Press any key to exit. +echo. +echo ==================================================================== +pause > nul & EXIT) +echo. +echo The script is creating an elevated task with highest privileges. +echo Please wait for a while. +echo. +:: **************************************************************************************** +Set "Folder=%ProgramData%\Fidelity\Turn_on_or_off_the_camera" +If not exist "%Folder%" (MkDir "%Folder%") + +Set "Script=%Folder%\+Turn_on_or_off_the_camera.cmd" +If exist "%Script%" (del "%Script%") +( +echo :: **************************************************************************************** +echo @echo off ^& title Turn on or off the camera. ^& mode con cols=68 lines=6 ^& color 17 +echo :: **************************************************************************************** + +echo cd /d "%%~dp0" +echo For /f "tokens=3" %%%%# in ^('REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V "Value"'^) Do ^(Set ✱=%%%%#^) +echo If "%%✱%%"=="Allow" ^(goto Turn_off_the_camera^) ^& Exit +echo :: **************************************************************************************** +echo :Turn_on_the_camera +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V Value /T REG_SZ /D "Allow" /F^) +echo ^(Start "" "Enabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +echo :Turn_off_the_camera +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V Value /T REG_SZ /D "Deny" /F^) +echo ^(Start "" "Disabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +)> "%Script%" + +:: **************************************************************************************** +Set "【VBS】=%Folder%\+Run_the_CMD_script.vbs" +If exist "%【VBS】%" (del "%【VBS】%") +( +echo Path = split^(wscript.scriptFullName, wscript.scriptname^)^(0^) +echo Item = Path ^& "+Turn_on_or_off_the_camera.cmd" +echo CreateObject^("wscript.shell"^).run^("""" ^& Item ^& ""^),0 +echo WScript.Quit +)> "%【VBS】%" +:: **************************************************************************************** +Set "Enabled=%Folder%\Enabled.ps1" +If exist "%Enabled%" (del "%Enabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Camera enabled. Press the Windows + M keys for it to take effect if the camera cannot be used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Enabled%" +:: **************************************************************************************** +Set "Enabled✱=%Folder%\Enabled.vbs" +If exist "%Enabled✱%" (del "%Enabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Enabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Enabled✱%" +:: **************************************************************************************** +Set "Disabled=%Folder%\Disabled.ps1" +If exist "%Disabled%" (del "%Disabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Camera Disabled. Press the Windows + M keys for it to take effect if the camera is being used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Disabled%" +:: **************************************************************************************** +Set "Disabled✱=%Folder%\Disabled.vbs" +If exist "%Disabled✱%" (del "%Disabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Disabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Disabled✱%" +:: **************************************************************************************** +For /f "tokens=*" %%I in ('WhoAmI /user') Do (for %%A in (%%~I) Do (set "【SID】=%%A")) +IF EXIST "%temp%\%【Name】%.xml" (DEL "%temp%\%【Name】%.xml") +IF EXIST "%temp%\Task.vbs" (DEL "%temp%\Task.vbs") + +echo Set X=CreateObject("Scripting.FileSystemObject") >> "%temp%\Task.vbs" +echo Set Z=X.CreateTextFile("%temp%\%【Name】%.xml",True,True)>> "%temp%\Task.vbs" +Set "W=echo Z.writeline " +( +%W%"" +%W%"" +%W%"" +%W%"To run the application/CMD script as an administrator with no UAC prompt." +%W%"" +%W%"" +%W%"" +%W%"" +%W%"%【SID】%" +%W%"InteractiveToken" +%W%"HighestAvailable" +%W%"" +%W%"" +%W%"" +%W%"IgnoreNew" +%W%"false" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"" +%W%"true" +%W%"false" +%W%"" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"false" +%W%"true" +%W%"false" +%W%"PT72H" +%W%"7" +%W%"" +%W%"" +%W%"" +%W%"""%【Path】%""" +%W%"""%【VBS】%""" +%W%"" +%W%"" +%W%"" +)>> "%temp%\Task.vbs" +echo Z.Close >> "%temp%\Task.vbs" +"%temp%\Task.vbs" +Del "%temp%\Task.vbs" +schtasks /create /xml "%temp%\%【Name】%.xml" /tn "Apps\%【Name】%" + +If %errorlevel%==1 (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The script has failed to create the task "%【Name】%". +echo The task might already exist in "Task Scheduler Library"--^>"Apps". +echo Press any key to close this message. +echo ============================================================================ +pause > nul) else (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The item "%【Item】%" has been added into the desktop context +echo menu ^(right-click menu^). +echo The scheduled task is in "Task Scheduler Library"--^>"Apps". +echo Please press any key to close this message. +echo ============================================================================ +pause > nul ) \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows 10)/Toggle Microphone in menu.bat b/Melody 12.01 (Script for Windows 10)/Toggle Microphone in menu.bat new file mode 100644 index 0000000..8b5d9fc --- /dev/null +++ b/Melody 12.01 (Script for Windows 10)/Toggle Microphone in menu.bat @@ -0,0 +1,169 @@ +:: **************************************************************************************** +@echo off & title Turn on or off the microphone. & mode con cols=80 lines=13 & color 17 +:: **************************************************************************************** +Set "【Item】=Toggle Microphone On or Off" +Set "【Name】=Microphone_on_off" +Set "【Path】=wscript.exe" +If not exist "%ProgramData%\Fidelity\" (mkdir "%ProgramData%\Fidelity\") +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%\Command" /VE /D "schtasks /run /tn ""Apps\%【Name】%""" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Icon" /T REG_SZ /D "%WinDir%\System32\DDORes.dll,86" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Position" /T REG_SZ /D "Bottom" /F) +Cls +If errorlevel 1 (echo. +echo ==================================================================== +echo. +echo The script has failed to perform the operations. +echo Press any key to exit. +echo. +echo ==================================================================== +pause > nul & EXIT) +echo. +echo The script is creating an elevated task with highest privileges. +echo Please wait for a while. +echo. +:: **************************************************************************************** +Set "Folder=%ProgramData%\Fidelity\Turn_on_or_off_the_microphone" +If not exist "%Folder%" (MkDir "%Folder%") + +Set "Script=%Folder%\+Turn_on_or_off_the_microphone.cmd" +If exist "%Script%" (del "%Script%") +( +echo :: **************************************************************************************** +echo @echo off ^& title Turn on or off the microphone. ^& mode con cols=68 lines=6 ^& color 17 +echo :: **************************************************************************************** + +echo cd /d "%%~dp0" +echo For /f "tokens=3" %%%%# in ^('REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V "Value"'^) Do ^(Set ✱=%%%%#^) +echo If "%%✱%%"=="Allow" ^(goto Turn_off_the_microphone^) ^& Exit +echo :: **************************************************************************************** +echo :Turn_on_the_microphone +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V Value /T REG_SZ /D "Allow" /F^) +echo ^(Start "" "Enabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +echo :Turn_off_the_microphone +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V Value /T REG_SZ /D "Deny" /F^) +echo ^(Start "" "Disabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +)> "%Script%" + +:: **************************************************************************************** +Set "【VBS】=%Folder%\+Run_the_CMD_script.vbs" +If exist "%【VBS】%" (del "%【VBS】%") +( +echo Path = split^(wscript.scriptFullName, wscript.scriptname^)^(0^) +echo Item = Path ^& "+Turn_on_or_off_the_microphone.cmd" +echo CreateObject^("wscript.shell"^).run^("""" ^& Item ^& ""^),0 +echo WScript.Quit +)> "%【VBS】%" +:: **************************************************************************************** +Set "Enabled=%Folder%\Enabled.ps1" +If exist "%Enabled%" (del "%Enabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Microphone enabled. Press the Windows + M keys for it to take effect if the microphone cannot be used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Enabled%" +:: **************************************************************************************** +Set "Enabled✱=%Folder%\Enabled.vbs" +If exist "%Enabled✱%" (del "%Enabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Enabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Enabled✱%" +:: **************************************************************************************** +Set "Disabled=%Folder%\Disabled.ps1" +If exist "%Disabled%" (del "%Disabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Microphone Disabled. Press the Windows + M keys for it to take effect if the microphone is being used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Disabled%" +:: **************************************************************************************** +Set "Disabled✱=%Folder%\Disabled.vbs" +If exist "%Disabled✱%" (del "%Disabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Disabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Disabled✱%" +:: **************************************************************************************** +For /f "tokens=*" %%I in ('WhoAmI /user') Do (for %%A in (%%~I) Do (set "【SID】=%%A")) +IF EXIST "%temp%\%【Name】%.xml" (DEL "%temp%\%【Name】%.xml") +IF EXIST "%temp%\Task.vbs" (DEL "%temp%\Task.vbs") + +echo Set X=CreateObject("Scripting.FileSystemObject") >> "%temp%\Task.vbs" +echo Set Z=X.CreateTextFile("%temp%\%【Name】%.xml",True,True)>> "%temp%\Task.vbs" +Set "W=echo Z.writeline " +( +%W%"" +%W%"" +%W%"" +%W%"To run the application/CMD script as an administrator with no UAC prompt." +%W%"" +%W%"" +%W%"" +%W%"" +%W%"%【SID】%" +%W%"InteractiveToken" +%W%"HighestAvailable" +%W%"" +%W%"" +%W%"" +%W%"IgnoreNew" +%W%"false" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"" +%W%"true" +%W%"false" +%W%"" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"false" +%W%"true" +%W%"false" +%W%"PT72H" +%W%"7" +%W%"" +%W%"" +%W%"" +%W%"""%【Path】%""" +%W%"""%【VBS】%""" +%W%"" +%W%"" +%W%"" +)>> "%temp%\Task.vbs" +echo Z.Close >> "%temp%\Task.vbs" +"%temp%\Task.vbs" +Del "%temp%\Task.vbs" +schtasks /create /xml "%temp%\%【Name】%.xml" /tn "Apps\%【Name】%" + +If %errorlevel%==1 (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The script has failed to create the task "%【Name】%". +echo The task might already exist in "Task Scheduler Library"--^>"Apps". +echo Press any key to close this message. +echo ============================================================================ +pause > nul & Exit) else (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The item "%【Item】%" has been added into the desktop context +echo menu ^(right-click menu^). +echo The scheduled task is in "Task Scheduler Library"--^>"Apps". +echo Please press any key to close this message. +echo ============================================================================ +pause > nul & Exit) \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows 10)/certificates/MicRooCerAut2011_2011_03_22.crt b/Melody 12.01 (Script for Windows 10)/certificates/MicRooCerAut2011_2011_03_22.crt new file mode 100644 index 0000000..1ae4740 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/MicRooCerAut2011_2011_03_22.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/MicRooCerAut_2010-06-23.crl b/Melody 12.01 (Script for Windows 10)/certificates/MicRooCerAut_2010-06-23.crl new file mode 100644 index 0000000..8166d95 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/MicRooCerAut_2010-06-23.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl new file mode 100644 index 0000000..174c487 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt new file mode 100644 index 0000000..3eb2c12 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Root Certificate Authority 2017.crl new file mode 100644 index 0000000..9ca82c0 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Root Certificate Authority 2017.crt new file mode 100644 index 0000000..86658ae Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl new file mode 100644 index 0000000..77a7065 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt new file mode 100644 index 0000000..d29764b Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl new file mode 100644 index 0000000..257bc74 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt new file mode 100644 index 0000000..90a7a79 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl new file mode 100644 index 0000000..0deac11 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt new file mode 100644 index 0000000..8835c44 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft RSA Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft RSA Root Certificate Authority 2017.crl new file mode 100644 index 0000000..0bcbf32 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft RSA Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft RSA Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft RSA Root Certificate Authority 2017.crt new file mode 100644 index 0000000..7031f88 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft RSA Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl new file mode 100644 index 0000000..8ab0e74 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl differ diff --git a/Melody 12.01 (Script for Windows 10)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt new file mode 100644 index 0000000..8a7a17f Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt differ diff --git a/Melody 12.01 (Script for Windows 10)/command2.bat b/Melody 12.01 (Script for Windows 10)/command2.bat new file mode 100644 index 0000000..f65e8e8 --- /dev/null +++ b/Melody 12.01 (Script for Windows 10)/command2.bat @@ -0,0 +1,881 @@ +:: Start with setting the location + +pushd "%CD%" +CD /D "%~dp0" + +:: Starting +reg.exe add "HKCU\Software\Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32" /f /ve +PowerRun "Toggle Camera in menu.bat" +PowerRun "Toggle Microphone in menu.bat" +PowerRun.exe Regedit.exe /S fidelityreg_reg11.reg +Regedit.exe /S fidelityreg_reg11.reg +:: Enable DirectPlay + +"powershell.exe" Enable-WindowsOptionalFeature -Online -FeatureName LegacyComponents -all -NoRestart +"powershell.exe" Enable-WindowsOptionalFeature -Online -FeatureName DirectPlay -all -NoRestart + +:: Installing Microsoft's Certs (because they removed sometime)... + +echo Now installing Root certs +for /f "delims=" %%f in ('dir /b "%~dp0\certificates\*"') do ( + echo Installing %%f... + certutil -f -addstore Root "%~dp0\certificates\%%f" +) + +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fidelity" /v DisplayName /t reg_sz /d "Melody 12.0 (EAS, partially applied)" /f + +:: Removal of Components + + +::Handwriting + +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~af-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~bs-LATN-BA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ca-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~cy-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~eu-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ga-IE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~gd-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~gl-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~hi-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~id-ID~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~lb-LU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~mi-NZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ms-BN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ms-MY~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nn-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nso-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~rm-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~rw-RW~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sq-AL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sr-CYRL-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sr-LATN-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sw-KE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~tn-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~wo-SN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~xh-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-TW~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zu-ZA~0.0.1.0 /NoRestart + + +::OCR + +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ar-SA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~bg-BG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~bs-LATN-BA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~hu-HU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sr-CYRL-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sr-LATN-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-TW~0.0.1.0 /NoRestart + +::Speech Recongnition + +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-AU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-TW~0.0.1.0 /NoRestart + + +::TTS Packs + +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ar-EG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ar-SA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~bg-BG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ca-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-AT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-AU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-IE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~he-IL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hi-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hu-HU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~id-ID~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ms-MY~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nl-BE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ta-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~th-TH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~vi-VN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-TW~0.0.1.0 /NoRestart + +::Network Drivers +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Intel.E1i68x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Intel.E2f68~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Vmware.Vmxnet3~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Realtek.Rtcx21x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmpciedhd63~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmwl63al~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmwl63a~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwbw02~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwew00~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwew01~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwlv64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwns64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwsw00~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw02~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw04~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw06~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw08~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw10~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Marvel.Mrvlpcie8897~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Athw8x~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Athwnx~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Qcamain10x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Ralink.Netr28x~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl8187se~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl8192se~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl819xp~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl85n64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane01~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane13~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane~~~~0.0.1.0 /NoRestart + +::Windows Tools +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.IoTDeviceUpdateCenter~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.PowerShell.ISE~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.WordPad~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OneCoreUAP.OneSync~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Client~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OneCoreUAP.OneSync~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Print.Fax.Scan~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:MathRecognizer~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Media.WindowsMediaPlayer~~~~0.0.12.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Accessibility.Braille~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Analog.Holographic.Desktop~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.StepsRecorder~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.Support.QuickAssist~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.WirelessDisplay.Connect~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Browser.InternetExplorer~~~~0.0.11.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Hello.Face.20134~~~~0.0.1.0 /NoRestart +:: Applying Network Settings + +netsh int tcp set heuristics disabled +netsh int tcp set supp internet congestionprovider=ctcp +netsh int tcp set global rss=enabled +netsh int tcp set global chimney=disabled +netsh int tcp set global ecncapability=enabled +netsh int tcp set global timestamps=disabled +netsh int tcp set global initialRto=3000 +netsh int tcp set global timestamps=disabled +netsh int tcp set global rsc=disabled +netsh int tcp set global nonsackttresiliency=disabled +netsh int tcp set global MaxSynRetransmissions=2 +netsh int tcp set global fastopen=enabled +netsh int tcp set global fastopenfallback=enabled +netsh int tcp set global pacingprofile=off +netsh int tcp set global hystart=disabled +netsh int tcp set heuristics disabled +netsh int tcp set global dca=enabled +netsh int tcp set global netdma=enabled +netsh int 6to4 set state state=enabled +netsh int udp set global uro=enabled +netsh winsock set autotuning on +netsh int tcp set supplemental template=custom icw=10 +netsh interface teredo set state enterprise +netsh int tcp set security mpp=disabled +netsh int tcp set security profiles=disabled +netsh interface ipv4 set subinterface "Wi-Fi" mtu=1500 store=persistent +netsh interface ipv6 set subinterface "Ethernet" mtu=1500 store=persistent +netsh interface ipv6 set subinterface "Ethernet" mtu=1500 store=persistent +netsh interface ipv4 set subinterface "Wi-Fi" mtu=1500 store=persistent +netsh int tcp set global autotuning=experimental +netsh advfirewall firewall set rule group="Remote Assistance" new enable=no + +for /f "tokens=3*" %%s in ('Reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards" /f "ServiceName" /s^|findstr /i /l "ServiceName"') do ( + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Psched\Parameters\Adapters\%%s" /v "NonBestEffortLimit" /t Reg_DWORD /d "0" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "DeadGWDetectDefault" /t Reg_DWORD /d "1" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "PerformRouterDiscovery" /t Reg_DWORD /d "1" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpInitialRTT" /t Reg_DWORD /d "0" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TCPNoDelay" /t Reg_DWORD /d "1" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpAckFrequency" /t Reg_DWORD /d "1" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpDelAckTicks" /t Reg_DWORD /d "0" /f >nul + ) + + +for %%i in (svchost explorer edge steam steamclient operagx Fornite-Win64-Shipping EA explorer chrome notepad++ steamwebviewer winword powerpnt excel mysummercar metin2 csgo VALORANT-Win64-Shipping javaw FortniteClient-Win64-Shipping ModernWarfare r5apex) do ( + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Application Name" /t Reg_SZ /d "%%i.exe" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Version" /t Reg_SZ /d "1.0" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Protocol" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local Port" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local IP" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local IP Prefix Length" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote Port" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote IP" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote IP Prefix Length" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "DSCP Value" /t Reg_SZ /d "46" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Throttle Rate" /t Reg_SZ /d "-1" /f +) + +for /f %%r in ('Reg query "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}" /f "PCI\VEN_" /d /s^|Findstr HKEY_') do ( +Reg add %%r /v "AutoDisableGigabit" /t Reg_SZ /d "0" /f +Reg add %%r /v "EnableGreenEthernet" /t Reg_SZ /d "0" /f +Reg add %%r /v "GigaLite" /t Reg_SZ /d "0" /f +Reg add %%r /v "PowerSavingMode" /t Reg_SZ /d "0" /f +) + +reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPerServer /t REG_DWORD /d 8 /f +reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPer1_0Server /t REG_DWORD /d 8 /f +reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPerServer /t REG_DWORD /d 8 /f +reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPer1_0Server /t REG_DWORD /d 8 /f + +for /f %%a in ('Reg query HKLM /v "*WakeOnMagicPacket" /s ^| findstr "HKEY"') do ( +for /f %%i in ('Reg query "%%a" /v "*EEE" ^| findstr "HKEY"') do (Reg add "%%i" /v "*EEE" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "*FlowControl" ^| findstr "HKEY"') do (Reg add "%%i" /v "*FlowControl" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableSavePowerNow" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableSavePowerNow" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnablePowerManagement" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnablePowerManagement" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableDynamicPowerGating" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableDynamicPowerGating" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableConnectedPowerGating" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableConnectedPowerGating" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "AutoPowerSaveModeEnabled" ^| findstr "HKEY"') do (Reg add "%%i" /v "AutoPowerSaveModeEnabled" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "AdvancedEEE" ^| findstr "HKEY"') do (Reg add "%%i" /v "AdvancedEEE" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "ULPMode" ^| findstr "HKEY"') do (Reg add "%%i" /v "ULPMode" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "ReduceSpeedOnPowerDown" ^| findstr "HKEY"') do (Reg add "%%i" /v "ReduceSpeedOnPowerDown" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnablePME" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnablePME" /t Reg_SZ /d "0" /f) +) + +PowerShell -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell -ArgumentList '-NoProfile -ExecutionPolicy Bypass -File ""%~dp0.\ma.ps1""' -Verb RunAs}" + +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001" /v "*RSSProfile" /t REG_SZ /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "ParamDesc" /t REG_SZ /d "RSS load balancing profile" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "default" /t REG_SZ /d "1" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "type" /t REG_SZ /d "enum" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "1" /t REG_SZ /d "ClosestProcessor" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "2" /t REG_SZ /d "ClosestProcessorStatic" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "3" /t REG_SZ /d "NUMAScaling" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "4" /t REG_SZ /d "NUMAScalingStatic" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "5" /t REG_SZ /d "ConservativeScaling" /f + +powershell -Command "Disable-NetAdapterChecksumOffload -Name * -IpIPv4 -TcpIPv4 -TcpIPv6 -UdpIPv4 -UdpIPv6" + +:: Services Part + +sc config MsKeyboardFilter start= disabled +sc config GraphicsPerfSvc start= disabled +sc config DiagTrack start= disabled +sc config TroubleshootingSvc start= disabled +sc config RemoteRegistry start= disabled +sc config shpamsvc start= disabled +sc config UevAgentService start= disabled +sc config MSiSCSI start= disabled +sc config NetTcpPortSharing start= disabled +sc config diagnosticshub.standardcollector.service start= disabled +sc config diagsvc start= disabled +sc config dmwappushservice start= disabled +sc config edgeupdate start= disabled + +::Search + +sc config WSearch start= disabled + +::Remote Desktop Native + +sc config tsusbflt start= disabled +sc config tsusbhub start= disabled +sc config TsUsbGD start= disabled +sc config TermService start= disabled +sc config SessionEnv start= disabled + +::Networking Services + +sc config PNRPsvc start= disabled +sc config p2psvc start= disabled +sc config p2pimsvc start= disabled +sc config PeerDistSvc start= disabled +sc config PerfHost start= disabled +sc config PNRPAutoReg start= disabled +sc config ALG start= disabled +sc config Fax start= disabled +sc config SNMPTrap start= disabled +sc config autotimesvc start= disabled +sc config LanmanWorkstation start= disabled +sc config LanmanServer start= disabled +sc config webthreatdefsvc start= disabled +sc config webthreatdefusersvc_63b8d start= disabled +sc config InventorySvc start= disabled +sc config MapsBroker start= disabled +sc config pla start= disabled + +::VR Services + +sc config perceptionsimulation start= disabled +sc config SharedRealitySvc start= disabled +sc config spectrum start= disabled +sc config MixedRealityOpenXRSvc start= disabled + +::Retail Demo + +sc config RetailDemo start= disabled + +::Virtual Machine + +sc config HvHost start= disabled +sc config vmickvpexchange start= disabled +sc config vmicguestinterface start= disabled +sc config vmicshutdown start= disabled +sc config vmicheartbeat start= disabled +sc config vmicvmsession start= disabled +sc config vmicrdv start= disabled +sc config vmictimesync start= disabled +sc config vmicvss start= disabled +sc config VMAuthdService start=demand +sc config VMnetDHCP start= demand +sc config VMware NAT Service start= demand +sc config VMUSBArbService start= demand +sc config VMwareHostd start= demand +sc config wcncsvc start= disabled +reg add "HKLM\SYSTEM\CurrentControlSet\Services\MessagingService" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKCU\Control Panel\Sound" /v "Beep" /t REG_SZ /d "no" /f + +::Blotware + + +sc config lfsvc start= disabled +sc config GoogleChromeBetaElevationService start= demand +sc config gupdate start= demand +sc config gupdatem start= demand +sc config GamingServices start= demand +sc config sppsvc start= demand +sc config DoSvc start= demand +sc config CDPSvc start= demand +sc config ClickToRunSvc start= demand +sc config DtsApo4Service start= demand +sc config TrkWks start= demand +sc config VacSvc start= disabled +sc config VSStandardCollectorService150 +sc config ss_conn_service start= demand +sc config ss_conn_service2 start= demand +sc config AudioEndpointBuilder start= demand +sc config RpcLocator start= disabled +sc config Sense start= disabled +sc config TapiSrv start= disabled +sc config KtmRm start= disabled +sc config SEMgrSvc start= disabled +sc config SCardSvr start= disabled +sc config ScDeviceEnum start= disabled +sc config AppVClient start= disabled +sc config SysMain start= disabled +sc config SSDPSRV start= disabled +sc config IKEEXT start= demand +sc config FontCache3.0.0.0 start= disabled +sc config WinRM start= disabled +sc config AxInstSV start= disabled +sc config WpcMonSvc start= disabled +sc config pla start= disabled +sc config COMSysApp start= disabled +sc config AGMService start= disabled +sc config AGSService start= disabled +sc stop TroubleshootingSvc +sc config TroubleshootingSvc start=disabled +sc stop MapsBroker +sc config MapsBroker start=disabled +sc stop SysMain +sc config SysMain start=disabled +sc config DusmSvc start= disabled +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpcMonSvc" /v "Start" /t REG_DWORD /d "4" /f + +:: Driver Service 2 +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\rdbss" /v "Start" /t REG_DWORD /d "1" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\pcmcia" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\lltdio" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\hwpolicy" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\vdrvroot" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\tcpipreg" /v "Start" /t REG_DWORD /d "2" / +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\TrustedInstaller" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\srvnet" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\rspndr" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\Schedule" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\ControlSet001\Services\TrkWks" /v "Start" /t REG_DWORD /d "3" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GoogleChromeElevationService" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BcastDVRUserService" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PhoneSvc" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fax" /v "Start" /t REG_DWORD /d "4" /f + +::TabletPC + +sc config SensorDataService start= disabled +sc config SensrSvc start= disabled +sc config SensorService start= disabled +sc config SmsRouter start= disabled +sc config PhoneSvc start= disabled +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DEFRAGSVC" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MessagingService_1c6e8" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\webthreatdefusersvc_77ac1" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MessagingService" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc" /v "Start" /t REG_DWORD /d "2" /f +REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\irmon" /v Start /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AxInstSV" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRM" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\luafv" /v "Start" /t REG_DWORD /d "4" /f + +::Task Disabler +::.net + +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical" /disable + +::ad tms management + +schtasks /Change /TN "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)" /disable +schtasks /Change /TN "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)" /disable + +::Mentenanta + +schtasks /Change /TN "\Microsoft\Windows\Chkdsk\ProactiveScan" /disable +schtasks /Change /TN "\Microsoft\Windows\Chkdsk\SyspartRepair" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery" /disable +schtasks /Change /TN "\Microsoft\Windows\Defrag\ScheduledDefrag" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskCleanup\SilentCleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\FileHistory\File History (maintenance mode)" /disable +schtasks /Change /TN "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE" /disable +schtasks /Change /TN "\Microsoft\Windows\Registry\RegIdleBackup" /disable + +:: telemetry +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\BthSQM" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Consolidator" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" /disable +schtasks /change /TN "\Microsoft\Windows\Autochk\Proxy" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\AitAgent" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\PcaPatchDbTask" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\ProgramDataUpdater" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\StartupAppTask" /disable +schtasks /Change /TN "Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /disable +schtasks /Change /TN "Microsoft\Windows\DiskFootprint\Diagnostics" /disable +schtasks /Change /TN "Microsoft\Windows\Windows Error Reporting\QueueReporting" /disable +schtasks /Change /TN "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem" /disable +schtasks /Change /TN "\Microsoft\Windows\NetTrace\GatherNetworkInfo" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClient" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\Scheduled" /disable +schtasks /Change /TN "\Microsoft\Windows\Application Experience\PcaPatchDbTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Device information\Device" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Setup\Metadata Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" /disable +schtasks /Change /TN "\Microsoft\Windows\Location\Notifications" /disable +schtasks /Change /TN "\Microsoft\Windows\Speech\SpeechModelDownloadTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Maintenance\WinSAT" /disable +schtasks /Change /TN "\Microsoft\Windows\PI\Sqm-Tasks" /disable +del /F /Q "C:\Windows\System32\Tasks\Microsoft\Windows\SettingSync\*" +schtasks /Change /TN "\Microsoft\Windows\AppListBackup\Backup" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Information\Device" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Information\Device User" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Setup\Metadata Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\Scheduled" /disable +schtasks /Change /TN "\Microsoft\Windows\DirectX\DXGIAdapterCache" /disable +schtasks /Change /TN "\Microsoft\Windows\DirectX\DirectXDatabaseUpdater" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskFootprint\Diagnostics" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskFootprint\StorageSense" /disable +schtasks /Change /TN "\Microsoft\Windows\DUSM\dusmtask" /disable +schtasks /Change /TN "\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClient" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\LocalUserSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\MouseSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\PenSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\TouchpadSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\International\Synchronize Language Settings" /disable +schtasks /Change /TN "\Microsoft\Windows\Kernel\La57Cleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\Location\WindowsActionDialog" /disable +schtasks /Change /TN "\Microsoft\Windows\Management\Provisioning\Logon" /disable +schtasks /Change /TN "\Microsoft\Windows\Management\Provisioning\Cellular" /disable +schtasks /Change /TN "\Microsoft\Windows\Maps\MapsToastTask" /disable +schtasks /Change /TN "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents" /disable +schtasks /Change /TN "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic" /disable +schtasks /Change /TN "\Microsoft\Windows\NlaSvc\WiFiTask" /disable +schtasks /Change /TN "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask" /disable +schtasks /Change /TN "\Microsoft\Windows\RetailDemo\CleanupOfflineContent" /disable +schtasks /Change /TN "\Microsoft\Windows\Servicing\StartComponentCleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\Shell\FamilySafetyRefreshTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Shell\FamilySafetyMonitor" /disable +schtasks /Change /TN "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Sysmain\ResPriStaticDbSync" /disable +schtasks /Change /TN "\Microsoft\Windows\SystemRestore\SR" /disable +schtasks /Change /TN "\Microsoft\Windows\TPM\Tpm-HASCertRetr" /disable +schtasks /Change /TN "\Microsoft\Windows\TPM\Tpm-Maintenance" /disable +schtasks /Change /TN "\Microsoft\Windows\UPnP\UPnPHostConfig" /disable +schtasks /Change /TN "\Microsoft\Windows\WlanSvc\CDSSync" /disable +schtasks /Change /TN "\Microsoft\Windows\WwanSvc\NotificationTask" /disable +schtasks /Change /TN "\Microsoft\Windows\WwanSvc\OobeDiscovery" /disable + + +::automatic App Update Windows +schtasks /Change /TN "Microsoft\Windows\WindowsUpdate\Automatic Update" /disable + +:: Office Telemetry Disable + +schtasks /Change /TN "\Microsoft\Office\OfficeTelemetryAgentFallBack2016" /disable +schtasks /Change /TN "\Microsoft\Office\OfficeTelemetryAgentLogOn2016" /disable + + +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange" /disable + +:: Remove Telemetry + +takeown /f C:\Windows\System32\smartscreen.exe +cacls C:\Windows\System32\smartscreen.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\smartscreen.exe" +takeown /f C:\Windows\System32\smartscreenps.dll +cacls C:\Windows\System32\smartscreenps.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\smartscreenps.dll" +takeown /f C:\Windows\System32\DeviceCensus.exe +cacls C:\Windows\System32\DeviceCensus.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\DeviceCensus.exe" +takeown /f C:\Windows\System32\CompatTelRunner.exe +cacls C:\Windows\System32\CompatTelRunner.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\CompatTelRunner.exe" +takeown /f C:\Windows\System32\dmclient.exe +cacls C:\Windows\System32\dmclient.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\dmclient.exe" +takeown /f C:\Windows\hh.exe +cacls C:\Windows\hh.exe /E /P %username%:F +del /F /Q "C:\Windows\hh.exe" +takeown /f C:\Windows\HelpPane.exe +cacls C:\Windows\HelpPane.exe /E /P %username%:F +del /F /Q "C:\Windows\HelpPane.exe" + + +:: Boot Parameters +bcdedit /set allowedinmemorysettings 0 +bcdedit /set hypervisorlaunchtype Off +bcdedit /set tscsyncpolicy Enhanced +bcdedit /set debug No +bcdedit /set isolatedcontext No +bcdedit /set bootmenupolicy Legacy +bcdedit /set usefirmwarepcisettings No +bcdedit /set sos Yes +bcdedit /set x2apicpolicy Enable +bcdedit /set vsmlaunchtype Off +bcdedit /set usephysicaldestination No +bcdedit /set ems No +bcdedit /set firstmegabytepolicy UseAll +bcdedit /set configaccesspolicy Default +bcdedit /set linearaddress57 optin +bcdedit /set noumex Yes +bcdedit /set bootems No +bcdedit /set graphicsmodedisabled No +bcdedit /set extendedinput Yes +bcdedit /set highestmode Yes +bcdedit /set forcefipscrypto No +bcdedit /set perfmem 0 +bcdedit /set clustermodeaddressing 1 +bcdedit /set usefirmwarepcisettings No +bcdedit /set uselegacyapicmode No +bcdedit /set onecpu No +bcdedit /set halbreakpoint No +bcdedit /set forcelegacyplatform No +bcdedit /set tpmbootentropy ForceDisable +bcdedit /timeout 0 +bcdedit /set allowedinmemorysettings 0x0 +bcdedit /set isolatedcontext No +bcdedit /set configaccesspolicy Default +bcdedit /set MSI Default +bcdedit /set usephysicaldestination No +bcdedit /set usefirmwarepcisettings No +bcdedit /set linearaddress57 OptOut +bcdedit /set increaseuserva 268435328 +bcdedit /set firstmegabytepolicy UseAll +bcdedit /set avoidlowmemory 0x8000000 +bcdedit /set nolowmem Yes +bcdedit /set allowedinmemorysettings 0x0 +bcdedit /set vm No +bcdedit /set pae ForceEnable +bcdedit /set useplatformclock No +bcdedit /set {current} recoveryenabled no +bcdedit /create {0cb3b571-2f2e-4343-a879-d86a476d7215} /d +bcdedit /set {bootmgr} bootsequence {0cb3b571-2f2e-4343-a879-d86a476d7215} +bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO,,DISABLE-VBS +bcdedit /set {current} disableelamdrivers yes +bcdedit /set vsmlaunchtype off +bcdedit /set recoveryenabled NO +bcdedit -set NOINTEGRITYCHECKS OFF +bcdedit -set TESTSIGNING OFF +bcdedit /set tscsyncpolicy legacy +bcdedit /set x2apicpolicy enable +bcdedit /set disabledynamictick yes +bcdedit /deletevalue useplatformclock +bcdedit /set useplatformtick yes +bcdedit /set nx AlwaysOff +bcdedit /set bootmenupolicy Legacy + + +:: Copy Files to Windows Folder +xcopy secdrv.sys ""C:\Windows\system32\drivers" /Y +xcopy "*.ico" "C:\Windows" /Y + +:: Mitigation Stuff + +powershell "ForEach($v in (Get-Command -Name \"Set-ProcessMitigation\").Parameters[\"Disable\"].Attributes.ValidValues){Set-ProcessMitigation -System -Disable $v.ToString().Replace(\" \", \"\").Replace(\"`n\", \"\") -ErrorAction SilentlyContinue}" +powershell "Set-ProcessMitigation -System -Enable CFG" +powershell "Set-ProcessMitigation -Name vgc.exe -Enable AuditDynamicCode" +powershell "Set-ProcessMitigation -Name vgc.exe -Enable CFG" +powershell "Set-ProcessMitigation -Name csgo.exe -Disable CFG" +powershell "Set-ProcessMitigation -Name FarCry6.exe -Disable CFG" + +echo Security Tweaks + +Reg add "HKLM\System\CurrentControlSet\Control\Class{4d36e96c-e325-11ce-bfc1-08002be10318}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{4d36e967-e325-11ce-bfc1-08002be10318}" /v "LowerFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{6bdd1fc6-810f-11d0-bec7-08002be2092f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{71a27cdd-812a-11d0-bec7-08002be2092f}" /v "LowerFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{71a27cdd-812a-11d0-bec7-08002be2092f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{ca3e7ab9-b4c3-4ae6-8251-579ef933890f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f + +xcopy "*.exe" "C:\Windows\System32" /Y + + +:: File Remover +takeown /f C:\Windows\System32\GamePanel.exe +cacls C:\Windows\System32\GamePanel.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanel.exe" +takeown /f C:\Windows\System32\wermgr.exe +cacls C:\Windows\System32\wermgr.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\wermgr.exe" +takeown /f C:\Windows\System32\wersvc.dll +cacls C:\Windows\System32\wersvc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\wersvc.dll" +takeown /f C:\Windows\System32\werui.dll +cacls C:\Windows\System32\werui.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werui.dll" +takeown /f C:\Windows\System32\WerEnc.dll +cacls C:\Windows\System32\WerEnc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\WerEnc.dll" +takeown /f C:\Windows\System32\WerFault.exe +cacls C:\Windows\System32\WerFault.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\WerFault.exe" +takeown /f C:\Windows\System32\wercplsupport.dll +cacls C:\Windows\System32\wercplsupport.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\wercplsupport.dll" +takeown /f C:\Windows\System32\werdiagcontroller.dll +cacls C:\Windows\System32\werdiagcontroller.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werdiagcontroller.dll" +takeown /f C:\Windows\System32\lfsvc.dll +cacls C:\Windows\System32\lfsvc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\lfsvc.dll" +takeown /f C:\Windows\System32\WerEnc.dll +cacls C:\Windows\System32\WerEnc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\WerEnc.dll" +takeown /f C:\Windows\System32\werui.dll +cacls C:\Windows\System32\werui.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werui.dll" +takeown /f C:\Windows\System32\WerFaultSecure.exe +cacls C:\Windows\System32\WerFaultSecure.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\WerFaultSecure.exe" +takeown /f C:\Windows\System32\gameux.dll +cacls C:\Windows\System32\gameux.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\gameux.dll" +takeown /f C:\Windows\System32\GamePanelExternalHook.dll +cacls C:\Windows\System32\GamePanelExternalHook.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanelExternalHook.dll" +takeown /f C:\Windows\System32\GamePanel.exe +cacls C:\Windows\System32\GamePanel.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanel.exe" +takeown /f C:\Windows\System32\gamemode.dll +cacls C:\Windows\System32\gamemode.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\gamemode.dll" +takeown /f C:\Windows\System32\GameBarPresenceWriter.exe +cacls C:\Windows\System32\GameBarPresenceWriter.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GameBarPresenceWriter.exe" +takeown /f C:\Windows\System32\zipcontainer.dll +cacls C:\Windows\System32\zipcontainer.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\zipcontainer.dll" +takeown /f C:\Windows\System32\msfeeds.dll +cacls C:\Windows\System32\msfeeds.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\msfeeds.dll" +takeown /f C:\Windows\System32\MsSpellCheckingHost.exe +cacls C:\Windows\System32\MsSpellCheckingHost.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\MsSpellCheckingHost.exe" +takeown /f C:\Windows\System32\ieapfltr.dll +cacls C:\Windows\System32\ieapfltr.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\ieapfltr.dll" +takeown /f C:\Windows\System32\MsSpellCheckingFacility.dll +cacls C:\Windows\System32\MsSpellCheckingFacility.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\MsSpellCheckingFacility.dll" +takeown /f C:\Windows\System32\LocationNotificationWindows.exe +cacls C:\Windows\System32\LocationNotificationWindows.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\LocationNotificationWindows.exe" +takeown /f C:\Windows\System32\msfeedssync.exe +cacls C:\Windows\System32\msfeedssync.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\msfeedssync.exe" +takeown /f C:\Windows\winhlp32.exe +cacls C:\Windows\winhlp32.exe /E /P %username%:F +del /F /Q "C:\Windows\winhlp32.exe" +takeown /f C:\Windows\System32\WpcMon.exe +cacls "C:\Windows\System32\WpcMon.exe" /E /P %username%:F +del /F /Q "C:\Windows\System32\WpcMon.exe" +takeown /f C:\Windows\System32\atieclxx.exe +cacls "C:\Windows\System32\atieclxx.exe" /E /P %username%:F +del /F /Q "C:\Windows\System32\atieclxx.exe" + +:: Windows Error Reporting +Reg.exe add "HKLM\Software\Microsoft\Windows\Windows Error Reporting\Assert Filtering Policy" /v "ReportAndContinue" /t REG_DWORD /d "0" /f +sc delete WerSvc +sc delete wercplsupport + +:: Disable Windows Update Driver Search + +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching" /v "SearchOrderConfig" /t REG_DWORD /d "3" /f +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverMetadata" /v "PreventDeviceMetadataFromNetwork" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\Update" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\Update" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" /v "DontSearchWindowsUpdate" REG_DWORD /d "1" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" /v "DontPromptForWindowsUpdate" REG_DWORD /d "1" /f + +:: Copying SDL in System 32... + +copy "%~dp0\SDL.dll" "C:\Windows\System32\SDL.dll" /Y +copy "%~dp0\SDL.dll" "C:\Windows\SysWOW64\SDL.dll" /Y + +:: Windows Defender Configuration + +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System" /v "EnableSmartScreen" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter" /v "EnabledV9" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender" /v "DisableRoutinelyTakingAction" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\SmartScreen" /v "ConfigureAppInstallControlEnabled" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "1" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "2" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "4" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "5" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\UX Configuration" /v "Notification_Suppress" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v DontReportInfectionInformation /t REG_DWORD /d 1 /f + +netsh Advfirewall set allprofiles state on + + +:: Another Tweaks +for /f %%i in ('Reg query "HKLM\SYSTEM\CurrentControlSet\Services" /s /f DmaRemappingCompatible ^| find /i "Services\" ') do ( +Reg add "%%i" /v "DmaRemappingCompatible" /t Reg_DWORD /d "0" /f ) +reg add "HKU\!USER_SID!\Control Panel\Mouse" /v "SmoothMouseXCurve" /t REG_BINARY /d "0000000000000000c0cc0c0000000000809919000000000040662600000000000033330000000000" /f +reg add "HKU\!USER_SID!\Control Panel\Mouse" /v "SmoothMouseYCurve" /t REG_BINARY /d "0000000000000000000038000000000000007000000000000000a800000000000000e00000000000" /f +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fidelity" /v DisplayName /t reg_sz /d "Melody 12.0 (EAS)" /f +shutdown /r /f /t 0 + + + diff --git a/Melody 12.01 (Script for Windows 10)/fidelityreg_reg11.reg b/Melody 12.01 (Script for Windows 10)/fidelityreg_reg11.reg new file mode 100644 index 0000000..3240007 --- /dev/null +++ b/Melody 12.01 (Script for Windows 10)/fidelityreg_reg11.reg @@ -0,0 +1,8434 @@ +Windows Registry Editor Version 5.00 + +;001.Optimize GPU Usage (set system and productivity Apps to iGPU) + +[HKEY_CURRENT_USER\Software\Microsoft\DirectX\UserGpuPreferences] +"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"="AutoHDREnable=1;GpuPreference=1;" +"C:\Windows\System32\rundll32.exe"="AutoHDREnable=1;GpuPreference=1;" +"C:\\Windows\\System32\\bdeunlock.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bdechangepin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipDLS.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ScriptRunner.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplySettingsTemplateCatalog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Microsoft.Uev.CscUnpinTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UevAppMonitor.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Microsoft.Uev.SyncController.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chgport.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chgusr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\query.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\logoff.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qappsrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qprocess.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\reset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rwinsta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tscon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tsdiscon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tskill.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\quser.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qwinsta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\baaupdate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\logagent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mfpmp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PackageInspector.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\manage-bde.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PresentationSettings.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AgentService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\repair-bde.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipRenew.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CustomShellHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AssignedAccessGuard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mavinject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BitLockerDeviceEncryption.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpshell.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AppVClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BdeHdCfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CameraSettingsUIHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RemoteAppLifetimeManager.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpsign.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fveprompt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iotstartup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fvenotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WPDShextAutoplay.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BdeUISrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbengine.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MsSpellCheckingHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bootim.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinBioDataModelOOBE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UevAppMonitor.exe.config" +"C:\\Windows\\System32\\AppV\\AppVStreamingUX.exe.config" +"C:\\Windows\\System32\\PresentationHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rstrui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\srdelayed.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SrTasks.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SpaceAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\provlaunch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EduPrintProv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UNPUXHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UNPUXLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UpdateNotificationMgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Spectrum.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SIHClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\xwizard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\takeown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vssadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\where.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cacls.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eventcreate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsavailux.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ftp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\grpconv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runas.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systeminfo.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\taskkill.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tasklist.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\timeout.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\waitfor.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\whoami.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mstsc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TSTheme.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wkspbroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TSWbPrxy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSa.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSaProxy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSaUacHelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sessionmsg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TieringEngineService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpclip.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpinput.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TapiUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dialer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tcmsetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MultiDigiMon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tabcal.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\FsIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dvdplay.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\calc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\charmap.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\credwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\certreq.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\certutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\klist.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ksetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nltest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regini.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regsvr32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setspn.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regedt32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ResetEngine.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SysResetErr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systemreset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemResetPlatform\\SystemResetPlatform.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\migwiz\\mighost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pwlauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fodhelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Fondue.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\OptionalFeatures.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CheckNetIsolation.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msiexec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mblctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msconfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LocationNotificationWindows.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mmc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsActionDialog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cliconfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\odbcad32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\odbcconf.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iscsicpl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iscsicli.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\IESettingSync.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ie4uinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ie4ushowIE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\F12\\IEChooser.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ieUnatt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iexpress.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wextract.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mshta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wiaacmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wiawow64.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bridgeunattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eventvwr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpresult.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpupdate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\esentutl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eudcedit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wecutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\easinvoker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EhStorAuthn.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DpiScaling.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dxpserver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceProperties.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DisplaySwitch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsRemoveDevice.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SyncHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DevicePairingWizard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ComputerDefaults.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DataExchangeHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompMgmtLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\convert.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\find.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ktmutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\label.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\openfiles.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\replace.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Robocopy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\stordiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\choice.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\clip.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\doskey.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\forfiles.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\print.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\subst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cttune.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cttunesvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\help.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msdtc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CastSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserDataSource.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\curl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tar.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spaceman.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spaceutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EDPCleanup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MDMAppInstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ARP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\finger.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\HOSTNAME.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MRINFO.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NETSTAT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ROUTE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sort.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TCPSVCS.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\xcopy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\auditpol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mountvol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\net.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\net1.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netsh.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PATHPING.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PING.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\reg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TRACERT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\attrib.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipUp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskusage.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\findstr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\icacls.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ipconfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CIDiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\comp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\recover.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sdclt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PerceptionSimulation\\PerceptionSimulationService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tcblaunch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\securekernel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SgrmBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SgrmLpac.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\upnpcont.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BioIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NgcIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dusmtask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinBioPlugIns\\FaceFodUninstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GamePanel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GameBarPresenceWriter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\oobeldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\windeploy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\audit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\AuditShD.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MBR2GPT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\Setup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\poqexec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PkgMgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dism\\DismHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmdkey.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dpapimig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LsaIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RmClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecEdit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\icsunattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NetHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmmon32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmstp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmdl32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasautou.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasdial.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasphone.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ntprint.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\printui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceEject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\powercfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sigverif.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\drvinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\hdwwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pnputil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wowreg32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\InfDefault-"="GpuPreference=1;" +"C:\\Windows\\System32\\ndadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\newdev.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\driverquery.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PnPUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\FirstLogonAnim.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\msoobe.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\UserOOBEBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netbtugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netiougc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nbtstat.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NetCfgNotifyObjectHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\djoin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\getmac.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\shrpubw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesAdvanced.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesComputerName.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesDataExecutionPrevention.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesHardware.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesPerformance.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesProtection.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesRemote.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sxstrace.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Sysprep\\sysprep.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSCollect.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSReset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\changepk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LicensingUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\phoneactivate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UpgradeResultsUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GenValObj.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\slui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SppExtComObj.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sppsvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech\\SpeechUX\\SpeechUXWiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\snmptrap.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\immersivetpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rmttpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tpmvscmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\OpenWith.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ThumbnailExtractionHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verclsid.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WallpaperHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\prevhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rundll32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mcbuilder.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MSchedExe.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WUDFCompanionHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WUDFHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AxInstUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\consent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LanguageComponentsInstallerComHandler.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LockAppHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\la57setup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lpk-"="GpuPreference=1;" +"C:\\Windows\\System32\\lpksetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lpremove.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DsmUserTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netcfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runonce.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\secinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\colorcpl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dccw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dism.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\proquota.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserAccountControlSettings.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\shutdown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\efsui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cipher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\edpnotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeCP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rekeywiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dnscacheugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nslookup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lodctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\unlodctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ddodiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\omadmclient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\omadmprc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DmOmaCpMo.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\coredpussvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceEnroller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmcertinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmcfghost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CredentialUIBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SensorDataService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\prproc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Windows.Media.BackgroundPlayback.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sfc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wusa.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\wbemtest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\scrcons.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplyTrustOffline.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CustomInstallExec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\deploymentcsphelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\expand.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ReAgentc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RelPost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MuiUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dxdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fontdrvhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winlogon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DiagSvcs\\DiagnosticsHub.StandardCollector.Service.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\drivers\\ExecutionContext.sys" +"C:\\Windows\\System32\\ucsvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fltMC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lsass.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ntoskrnl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\services.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\smss.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\csrss.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Boot\\winload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AggregatorHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dtdump.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runexehelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdrleakdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wpr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pacjsworker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\userinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wininit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceCensus.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dllhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\conhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\extrac32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\makecab.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\svchost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\compact.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dwm.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dcomcnfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Locator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Com\\MigRegDB.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RpcPing.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mtstocom.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Com\\comrepl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dllhst3g.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setupcl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setupugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wimserv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chkdsk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chkntfs.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wsqmcons.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\autochk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\browser_broker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\browserexport.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Boot\\winresume.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winresume.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bthudtask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsquirt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bitsadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\refsutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidcertstorecheck.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidpolicyconverter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SndVol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidtel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompatTelRunner.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sdbinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pcalua.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\aitstatic.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LaunchTM.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pcaui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Taskmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Utilman.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EaseOfAccessDialog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Narrator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\osk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sethc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AtBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Magnify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EoAExperiences.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CloudExperienceHostBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplicationFrameHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthSystray.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ShellAppRuntime.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\desktopimgdownldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsAdminFlows.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\VSSVC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\convertvhd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wuauclt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotifyIcon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsUpdateElevatedInstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotification.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotificationUx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MoNotificationUx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UsoClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech_OneCore\\common\\SpeechModelDownload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech_OneCore\\common\\SpeechRuntime.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceCredentialDeployment.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LegacyNetUXHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wevtutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dasHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DiskSnapshot.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verifier.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Register-CimProvider.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WinMgmt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WmiPrvSE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winrs.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winrshost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WMIC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSManHTTPConfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wsmprovhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LogonUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mpnotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wlrmdr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskpart.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskraid.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vds.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vdsldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fixmapi.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Netplwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PasswordOnWakeSettingFlyout.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserAccountBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LaunchWinApp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verifiergui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tzsync.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wksprt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\InputSwitchToastHandler.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UIMgrBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ctfmon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\taskhostw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\at.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\schtasks.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MdmDiagnosticsTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\alg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PackagedCWALauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mmgaserver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AuthHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\backgroundTaskHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\VaultCmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\licensingdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CertEnrollCtrl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RuntimeBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BackgroundTransferHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ByteCodeGenerator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WWAHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WaaSMedicAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\upfc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wuapihost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ttdinject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tttracer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sihost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pospaymentsworker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RemotePosWorker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LicenseManagerShellext.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ISM.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchFilterHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchIndexer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchProtocolHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\directxdatabaseupdater.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dispdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Windows.WARP.JITService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dxgiadaptercache.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeSH.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TokenBrokerCookies.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AppHostRegistrationVerifier.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dstokenclean.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinRTNetMUAHostServer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PickerHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\execmodelproxy.dll" +"C:\\Windows\\System32\\ExecModelClient.dll" +"C:\\Windows\\System32\\SystemUWPLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DataStoreCacheDumpTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CredentialEnrollmentManager.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wlanext.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LockScreenContentServer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SlideToShutDown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systray.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RunLegacyCPLElevated.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\control.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fontview.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wifitask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tzutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\w32tm.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmclient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dsregcmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UtcDecoderHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TpmTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\HealthAttestationClientAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TpmInit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CloudNotifications.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\mofcomp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\unsecapp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WMIADAP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WmiApSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_isv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_ssp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_ssp_isv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\printfilterpipelinesvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\provtool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PrintIsolationHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spoolsv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PinEnrollmentBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WpcTok.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WpcMon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApproveChildRequest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ofdeploy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DmNotificationBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MDMAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeBCHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Eap3Host.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bcdboot.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bcdedit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bootsect.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\audiodg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SpatialAudioLicenseSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompPkgSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\agentactivationruntimestarter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\IcsEntitlementHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ShellUpdateAgentTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\XblGameSaveTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\en-US\\notepad.exe.mui" +"C:\\Windows\\System32\\notepad.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TsWpfWrp.exe"="GpuPreference=1;" + +; 002. IRQ Priority + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouclass\Parameters] +"ThreadPriority"=dword:0000001f + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\mouhid\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DXGKrnl\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\USBXHCI\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\USBHUB3\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\amdkmdap\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvlddmkm\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\amd_sata\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BTUSB\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BthLEEnum\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BthHFEnum\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\umbus_A1614B8FA282BCE3\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RTWlanE\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RtkBtManServ\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RtkBtFilter\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\rtump64x64\Parameters] +"ThreadPriority"=dword:0000001f + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl] +"IRQ4294967253Priority"=dword:00000001 +"IRQ4294967254Priority"=dword:00000001 +"IRQ4294967259Priority"=dword:00000001 +"IRQ4294967256Priority"=dword:00000001 +"IRQ4294967257Priority"=dword:00000001 +"IRQ4294967258Priority"=dword:00000001 +"IRQ4294967260Priority"=dword:00000002 +"IRQ4294967261Priority"=dword:00000002 +"IRQ4294967262Priority"=dword:00000001 +"IRQ39Priority"=dword:00000001 +"IRQ1024Priority"=dword:00000001 +"IRQ4294967287Priority"=dword:00000001 +"IRQ4294967288Priority"=dword:00000001 +"IRQ4294967289Priority"=dword:00000001 +"IRQ4294967290Priority"=dword:00000001 +"IRQ4294967291Priority"=dword:00000001 +"IRQ4294967292Priority"=dword:00000001 +"IRQ4294967293Priority"=dword:00000001 +"IRQ4294967294Priority"=dword:00000001 +"IRQ1Priority"=dword:00000001 +"IRQ6Priority"=dword:00000001 +"IRQ7Priority"=dword:00000001 +"IRQ25Priority"=dword:00000001 +"IRQ36Priority"=dword:00000001 +"IRQ55Priority"=dword:00000001 +"IRQ57Priority"=dword:00000001 +"IRQ8Priority"=dword:00000001 +"Win32PrioritySeparation"=dword:00000038 + + +; 003. MMSSVC + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Audio] +"Affinity"=dword:00000007 +"Background Only"="True" +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000006 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Low Latency] +"Affinity"=dword:00000000 +"Background Only"="False" +"BackgroundPriority"=dword:00000000 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000002 +"Scheduling Category"="High" +"SFIO Priority"="High" +"Latency Sensitive"="True" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Audio] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000001 +"Priority"=dword:00000002 +"Scheduling Category"="High" +"SFIO Priority"="High" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Capture] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000005 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\DisplayPostProcessing] +"Affinity"=dword:00000000 +"Background Only"="True" +"BackgroundPriority"=dword:00000008 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000008 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Distribution] +"Affinity"=dword:00000000 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000004 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Playback] +"Affinity"=dword:00000007 +"Background Only"="False" +"BackgroundPriority"=dword:00000004 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000003 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Pro Audio] +"Affinity"=dword:00000007 +"Background Only"="False" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000001 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Window Manager] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000005 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\DisplayPostProcessing] +"Affinity"=dword:00000000 +"Background Only"="True" +"BackgroundPriority"=dword:00000018 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000012 +"Priority"=dword:00000008 +"Scheduling Category"="High" +"SFIO Priority"="High" +"Latency Sensitive"="True" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games] +"Affinity"=dword:00000000 +"Background Only"="False" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000006 +"Scheduling Category"="High" +"SFIO Priority"="High" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile] +"NoLazyMode"=dword:00000001 +"AlwaysOn"=dword:00000001 +"NetworkThrottlingIndex"=dword:ffffffff +"SystemResponsiveness"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider] +"RestoreConnection"=dword:00000001 +"WakeUp"=dword:00000000 + +; 004. Contextual Menu + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay] +"Icon"="display.dll,-1" +"MUIVerb"="Turn off display" +"Position"="Bottom" +"SubCommands"="" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\01menu] +"Icon"="powercpl.dll,-513" +"MUIVerb"="Turn off display" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\01menu\command] +@="nircmd.exe cmdwait 1000 monitor async_off" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\02menu] +"MUIVerb"="Lock computer and Turn off display" +"CommandFlags"=dword:00000020 +"Icon"="imageres.dll,-59" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\02menu\command] +@="cmd /c \"nircmd.exe cmdwait 1000 monitor async_off & rundll32.exe user32.dll, LockWorkStation\"" + + + +[HKEY_CLASSES_ROOT\exefile\shell\Priority] +"MUIVerb"="Run with priority" +"SubCommands"="" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\001flyout] +@="Realtime" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\001flyout\command] +@="cmd.exe /c start \"\" /Realtime \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\002flyout] +@="High" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\002flyout\command] +@="cmd.exe /c start \"\" /High \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\003flyout] +@="Above normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\003flyout\command] +@="cmd.exe /c start \"\" /AboveNormal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\004flyout] +@="Normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\004flyout\command] +@="cmd.exe /c start \"\" /Normal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\005flyout] +@="Below normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\005flyout\command] +@="cmd.exe /c start \"\" /BelowNormal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\006flyout] +@="Low" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\006flyout\command] +@="cmd.exe /c start \"\" /Low \"%1\"" + + + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shell\Windows.PermanentDelete] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E9571AB2-AD92-4ec6-8924-4E5AD33790F5}" +"Icon"="shell32.dll,-240" +"Position"="Bottom" + + + +[HKEY_CLASSES_ROOT\Msi.Package\shell\Extract\command] +@="msiexec.exe /a \"%1\" /qb TARGETDIR=\"%1 Contents\"" + + +[HKEY_CLASSES_ROOT\VBSFile\Shell\runas\command] +@="C:\\Windows\\System32\\WScript.exe \"%1\" %*" + + +[HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\batfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\cmdfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\docxfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\fonfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\htmlfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\inffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\inifile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\JSEFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\otffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\pfmfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\regfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\rtffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\ttcfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\ttffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\txtfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\VBEFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\VBSFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\WSFFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash] +"MUIVerb"="Hash" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\01SHA1] +"MUIVerb"="SHA1" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\01SHA1\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA1 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\02SHA256] +"MUIVerb"="SHA256" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\02SHA256\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA256 | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\03SHA384] +"MUIVerb"="SHA384" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\03SHA384\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA384 | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\04SHA512] +"MUIVerb"="SHA512" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\04SHA512\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA512 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\05MACTripleDES] +"MUIVerb"="MACTripleDES" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\05MACTripleDES\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm MACTripleDES | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\06MD5] +"MUIVerb"="MD5" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\06MD5\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm MD5 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\07RIPEMD160] +"MUIVerb"="RIPEMD160" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\07RIPEMD160\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm RIPEMD160 | format-list" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\UEV\Agent] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WorkFolders] +"AutoProvision"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRE] +"DisableSetup"=dword:00000001 + +[HKEY_CLASSES_ROOT\*\shell\TakeOwnership] +@="Take Ownership" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"NeverDefault"="" + +[HKEY_CLASSES_ROOT\*\shell\TakeOwnership\command] +@="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l' -Verb runAs\"" +"IsolatedCommand"= "powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\Directory\shell\TakeOwnership] +@="Take Ownership" +"AppliesTo"="NOT (System.ItemPathDisplay:=\"C:\\Users\" OR System.ItemPathDisplay:=\"C:\\ProgramData\" OR System.ItemPathDisplay:=\"C:\\Windows\" OR System.ItemPathDisplay:=\"C:\\Windows\\System32\" OR System.ItemPathDisplay:=\"C:\\Program Files\" OR System.ItemPathDisplay:=\"C:\\Program Files (x86)\")" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"Position"="middle" + +[HKEY_CLASSES_ROOT\Directory\shell\TakeOwnership\command] +@="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" /r /d y && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l /q' -Verb runAs\"" +"IsolatedCommand"="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" /r /d y && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l /q' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\Drive\shell\runas] +@="Take Ownership" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"Position"="middle" +"AppliesTo"="NOT (System.ItemPathDisplay:=\"C:\\\")" + +[HKEY_CLASSES_ROOT\Drive\shell\runas\command] +@="cmd.exe /c takeown /f \"%1\\\" /r /d y && icacls \"%1\\\" /grant *S-1-3-4:F /t /c" +"IsolatedCommand"="cmd.exe /c takeown /f \"%1\\\" /r /d y && icacls \"%1\\\" /grant *S-1-3-4:F /t /c" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart] +"Icon"="shell32.dll,-16739" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\001flyout] +"MUIVerb"="Force apps to close, and full shutdown and restart PC with no time-out or warning" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\001flyout\command] +@="shutdown /r /f /t 0" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\002flyout] +"MUIVerb"="Full shutdown and restart PC with warning" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\002flyout\command] +@="shutdown /r" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\003flyout] +"MUIVerb"="Full shutdown and restart PC. After rebooted, restart any opened registered apps." +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\003flyout\command] +@="shutdown /g /t 0" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\004flyout] +"MUIVerb"="Restart to Advanced Startup Options" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\004flyout\command] +@="shutdown /r /o /f /t 0" + + +[-HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs] + +[HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs] +@="Install" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs\Command] +@="cmd /k dism /online /add-package /packagepath:\"%1\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars] +"MUIVerb"="Environment variables" +"Icon"="sysdm.cpl,-1" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\01UserVars] +"MUIVerb"="User variables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\01UserVars\Command] +@="rundll32.exe sysdm.cpl,EditEnvironmentVariables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\02SystemVars] +"HasLUAShield"="" +"MUIVerb"="System variables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\02SystemVars\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process rundll32 -ArgumentList '/s,/c, sysdm.cpl,EditEnvironmentVariables' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\*\shell\Copy Content to Clipboard] +"MUIVerb"="Copy Content to Clipboard" +"Icon"="DxpTaskSync.dll,-52" +"Position"="Center" + +[HKEY_CLASSES_ROOT\*\shell\Copy Content to Clipboard\Command] +@="cmd /c clip < \"%1\"" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Safely Remove Hardware] +"MUIVerb"="Safely Remove Hardware" +"Icon"="hotplug.dll,-100" +"Position"="Center" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Safely Remove Hardware\Command] +@="C:\\Windows\\system32\\control.exe hotplug.dll" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall] +"MUIVerb"="Windows Firewall" +"Icon"="FirewallControlPanel.dll,-1" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command001] +"MUIVerb"="Windows Firewall" +"Icon"="FirewallControlPanel.dll,-1" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command001\Command] +@="RunDll32.exe shell32.dll,Control_RunDLL firewall.cpl" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command002] +"MUIVerb"="Windows Firewall with Advanced Security" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command002\Command] +@="mmc.exe /s wf.msc" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command003] +"MUIVerb"="Configure Allowed Apps" +"Icon"="FirewallControlPanel.dll,-1" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command003\Command] +@="explorer.exe shell:::{4026492F-2F69-46B8-B9BF-5654FC07E423} -Microsoft.WindowsFirewall\\pageConfigureApps" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command004] +"MUIVerb"="Turn On Windows Firewall" +"HasLUAShield"="" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command004\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall set allprofiles state on' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command005] +"MUIVerb"="Turn Off Windows Firewall" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command005\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall set allprofiles state off' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command006] +"MUIVerb"="Reset Windows Firewall" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command006\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall reset' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\KillNRTasks] +"icon"="taskmgr.exe,-30651" +"MUIverb"="Kill all not responding tasks" +"Position"="Top" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\KillNRTasks\command] +@="CMD.exe /C taskkill.exe /f /fi \"status eq Not Responding\" & Pause" + + +[HKEY_CURRENT_USER\Software\Classes\*\shellex\ContextMenuHandlers\PintoStartScreen] +@="{470C0EBD-5D73-4d58-9CED-E91E22E23282}" + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex\ContextMenuHandlers] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex\ContextMenuHandlers\PintoStartScreen] +@="{470C0EBD-5D73-4d58-9CED-E91E22E23282}" + + + +[-HKEY_CLASSES_ROOT\DesktopBackground\Shell\AdvancedBootOptions] + + +[HKEY_CLASSES_ROOT\*\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + +[HKEY_CLASSES_ROOT\Directory\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shell\windows.copyaspath] +"CanonicalName"="{707C7BC6-685A-4A4D-A275-3966A5A3EFAA}" +"CommandStateHandler"="{3B1599F9-E00A-4BBF-AD3E-B3F99FA87779}" +"CommandStateSync"="" +"Description"="@shell32.dll,-30336" +"Icon"="imageres.dll,-5302" +"InvokeCommandOnSelection"=dword:00000001 +"MUIVerb"="@shell32.dll,-30329" +"VerbHandler"="{f3d06e7c-1e45-4a26-847e-f9fcdee59be0}" +"VerbName"="copyaspath" + +[HKEY_CLASSES_ROOT\Drive\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + + +; 1.6. Restart File Explorer + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer] +"icon"="explorer.exe" +"Position"="Center" +"SubCommands"="" +"MUIVerb"="Restart/Pause File Explorer " + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\01menu] +"MUIVerb"="Restart File Explorer" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\01menu\command] +@="cmd.exe /c taskkill /f /im explorer.exe & start explorer.exe" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\02menu] +"MUIVerb"="Pause File Explorer" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\02menu\command] +@="cmd.exe /c @echo off & echo. & echo Stopping explorer.exe process . . . & echo. & taskkill /f /im explorer.exe & echo. & echo. & echo Waiting to start explorer.exe process when you are ready . . . & pause && start explorer.exe && exit" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\DismContextMenu] +"Icon"="WmiPrvSE.exe" +"MUIVerb"="Repair Windows Image" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\CheckHealth] +"HasLUAShield"="" +"MUIVerb"="Check Health of Windows Image" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\CheckHealth\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, Dism /Online /Cleanup-Image /CheckHealth' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\RestoreHealth] +"HasLUAShield"="" +"MUIVerb"="Repair Windows Image" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\RestoreHealth\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, Dism /Online /Cleanup-Image /RestoreHealth' -Verb runAs\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions] +"HasLUAShield"="" +"MUIVerb"="Check for Corruptions" + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, sfc.exe /scannow' -Verb runAs\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions_log] +"HasLUAShield"="" +"MUIVerb"="View Scan Logs" + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions_log\command] +@="PowerShell (Select-String [SR] $env:windir\\Logs\\CBS\\CBS.log -s).Line >\"$env:userprofile\\Desktop\\SFC_LOG.txt\"" + + + +;; 1.2.Windows Terminal + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked] +"{9F156763-7844-4DC4-B2B1-901F640F5155}"="" + +[HKEY_CLASSES_ROOT\Directory\shell\OpenWindowsTerminalProfiles] +"MUIVerb"="Open in Windows Terminal" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile] +"MUIVerb"="Default Profile" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile\command] +@="cmd.exe /c start wt.exe -d \"%1\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile] +"MUIVerb"="Command Prompt" +"Icon"="imageres.dll,-5323" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile\command] +@="cmd.exe /c start wt.exe -p \"Command Prompt\" -d \"%1\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile] +"MUIVerb"="PowerShell" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile\command] +@="cmd.exe /c start wt.exe -p \"Windows PowerShell\" -d \"%1\"" + +[HKEY_CLASSES_ROOT\Directory\Background\shell\OpenWindowsTerminalProfiles] +"MUIVerb"="Open in Windows Terminal" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile] +"MUIVerb"="Default Profile" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile\command] +@="cmd.exe /c start wt.exe -d \"%V\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile] +"MUIVerb"="Command Prompt" +"Icon"="imageres.dll,-5323" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile\command] +@="cmd.exe /c start wt.exe -p \"Command Prompt\" -d \"%V\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile] +"MUIVerb"="PowerShell" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile\command] +@="cmd.exe /c start wt.exe -p \"Windows PowerShell\" -d \"%V\"" + + +; 1.2.1 Windows Terminal for Directory + +[HKEY_CLASSES_ROOT\Directory\shell\WindowsTerminalAsAdmin] +"HasLUAShield"="" +"MUIVerb"="Open in Windows Terminal as Administrator" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile] +"MUIVerb"="Open in Windows Terminal as Administrator - Default Profile" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\02Cmd] +"MUIVerb"="Open in Windows Terminal as Administrator - Command Prompt" +"Icon"="imageres.dll,-5324" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\02Cmd\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Command Prompt\"\"\"','-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\03PS] +"MUIVerb"="Open in Windows Terminal as Administrator - PowerShell" +"HasLUAShield"="" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\03PS\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Windows PowerShell\"\"\"','-d','.')\"" + +; Directory\Background + +[HKEY_CLASSES_ROOT\Directory\Background\shell\WindowsTerminalAsAdmin] +"HasLUAShield"="" +"MUIVerb"="Open in Windows Terminal as Administrator" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile] +"MUIVerb"="Open in Windows Terminal as Administrator - Default Profile" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\02Cmd] +"MUIVerb"="Open in Windows Terminal as Administrator - Command Prompt" +"Icon"="imageres.dll,-5324" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\02Cmd\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Command Prompt\"\"\"','-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\03PS] +"MUIVerb"="Open in Windows Terminal as Administrator - PowerShell" +"HasLUAShield"="" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\03PS\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Windows PowerShell\"\"\"','-d','.')\"" + +;005. Removal of Components in Registry + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HomeFolderDesktop\NameSpace\DelegateFolders\{3134ef9c-6b18-4996-ad04-ed5912e00eb5}] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\HomeFolderDesktop\NameSpace\DelegateFolders\{3134ef9c-6b18-4996-ad04-ed5912e00eb5}] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Play] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Play] + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\Windows.IsoFile\shell\burn] + +[-HKEY_CLASSES_ROOT\MediaCenter.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.DVR-MSFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3G2\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3GP\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ADTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AIFF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AU\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AVI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.FLAC\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M2TS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.m3u\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M4A\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MIDI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MK3D\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MOV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP3\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP4\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MPEG\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.TTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WPL\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WVX\shell\Enqueue] + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpeg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpe\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.png\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.gif\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.tif\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.tiff\Shell\3D Edit] + +[-HKEY_CLASSES_ROOT\Directory\Background\shell\WSL] + +[-HKEY_CLASSES_ROOT\Directory\shell\WSL] + +[-HKEY_CLASSES_ROOT\Drive\shell\WSL] + +[-HKEY_CLASSES_ROOT\MediaCenter.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.DVR-MSFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3G2\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3GP\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ADTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AIFF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AU\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AVI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.FLAC\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M2TS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.m3u\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M4A\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MIDI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MK3D\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MOV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP3\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP4\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MPEG\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.TTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WPL\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WVX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\*\shell\UpdateEncryptionSettingsWork] + +[-HKEY_CLASSES_ROOT\Directory\shell\UpdateEncryptionSettings] + +[HKEY_CLASSES_ROOT\IE.AssocFile.URL\ShellEx\ContextMenuHandlers\{09799AFB-AD67-11d1-ABCD-00C04FC30936}] + +[-HKEY_CLASSES_ROOT\Drive\shell\Optimize using PerfectDisk] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\print] + +[-HKEY_CLASSES_ROOT\batfile\shell\print] + +[-HKEY_CLASSES_ROOT\cmdfile\shell\print] + +[-HKEY_CLASSES_ROOT\docxfile\shell\print] + +[-HKEY_CLASSES_ROOT\fonfile\shell\print] + +[-HKEY_CLASSES_ROOT\htmlfile\shell\print] + +[-HKEY_CLASSES_ROOT\inffile\shell\print] + +[-HKEY_CLASSES_ROOT\inifile\shell\print] + +[-HKEY_CLASSES_ROOT\JSEFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\otffile\shell\print] + +[-HKEY_CLASSES_ROOT\pfmfile\shell\print] + +[-HKEY_CLASSES_ROOT\regfile\shell\print] + +[-HKEY_CLASSES_ROOT\rtffile\shell\print] + +[-HKEY_CLASSES_ROOT\ttcfile\shell\print] + +[-HKEY_CLASSES_ROOT\ttffile\shell\print] + +[-HKEY_CLASSES_ROOT\txtfile\shell\print] + +[-HKEY_CLASSES_ROOT\VBEFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\VBSFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\WSFFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\Drive\shell\unlock-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\manage-bde] + + + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\SendTo] +@="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\*\shell\UpdateEncryptionSettingsWork] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\Directory\shell\UpdateEncryptionSettings] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked] +"{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}"="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\Folder\ShellEx\ContextMenuHandlers\Library Location] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Drive\shell\change-passphrase] + +[-HKEY_CLASSES_ROOT\Drive\shell\change-pin] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\Drive\shell\encrypt-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\encrypt-bde-elev] + +[-HKEY_CLASSES_ROOT\Drive\shell\manage-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\resume-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\resume-bde-elev] + +[-HKEY_CLASSES_ROOT\Drive\shell\unlock-bde] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ModernSharing] + +[-HKEY_CLASSES_ROOT\Directory\Background\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\PropertySheetHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\LibraryFolder\background\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\CLSID\{09A47860-11B0-4DA5-AFA5-26D86198A780}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\DesktopBackground\Shell\ControlledFolderAccess] + +[-HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications] +"Windows Photo Viewer"="-" + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Photo Viewer\Capabilities] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Bitmap] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.JFIF] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Jpeg] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Png] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Wdp] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\photoviewer.dll] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DiagnosticLogCSP] + + +;006. Add Files for NEW Menu + + +[HKEY_CLASSES_ROOT\.cpp\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.c\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.py\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.js\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.code\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.aup\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.php\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.cmd\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.ini\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.ini\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.reg\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.txt\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.bat\ShellNew] +"NullFile"="" +"ItemName"=hex(2):40,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ + 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ + 00,61,00,63,00,70,00,70,00,61,00,67,00,65,00,2e,00,64,00,6c,00,6c,00,2c,00,\ + 2d,00,36,00,30,00,30,00,32,00,00,00 + +[HKEY_CLASSES_ROOT\.html\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.vbs\ShellNew] +"NullFile"="" +"ItemName"=hex(2):40,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\ + 73,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,73,\ + 00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,34,00,38,00,\ + 30,00,32,00,00,00 + + +; 007. App Priority + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acrobat.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acrobat.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acrotray.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acrotray.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Among Us.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Among Us.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\audiodg.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\audiodg.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BananaBugs.exe] +"MaxLoaderThreads"=dword:00000002 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BananaBugs.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bitwarden.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bitwarden.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BlueMail.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BlueMail.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bookworm.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bookworm.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\candycrushsaga.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\candycrushsaga.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe] +"MaxLoaderThreads"=dword:00000004 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Chuzzle.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Chuzzle.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CIU.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CIU.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\converter.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\converter.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csgo.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csgo.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrss.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrss.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cyberpunk2077.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cyberpunk2077.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discord.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discord.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ditto.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ditto.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DoomEternalx64vk.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DoomEternalx64vk.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DragonCity.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DragonCity.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwm.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwm.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EABackgroundService.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EABackgroundService.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EarTrumpet.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EarTrumpet.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eurotrucks2.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eurotrucks2.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ext2Srv.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FarCry6.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fontdrvhost.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FortniteClient-Win64-Shipping.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FortniteClient-Win64-Shipping.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon3.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon3.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon4.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon4.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon5.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon5.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\game] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\game\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GameOverlayUI.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GameOverlayUI.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GeometryDash.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GeometryDash.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyCtrl.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyCtrl.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyHelp32.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyHelp64.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc32.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc32.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc64.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc64.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-iii.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-iii.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-lc.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-lc.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-sa.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-sa.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-vc.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-vc.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GTAV.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GTAV.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IDMan.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IDMan.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iScrRec.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iScrRec.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lghub_updater.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lghub_updater.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightroom.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightroom.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightshot.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightshot.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ludo King.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ludo King.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MegaRun-WinStore.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MegaRun-WinStore.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\metin2client.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\metin2client.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly_Plus.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly_Plus.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpc-hc64.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe] +"MaxLoaderThreads"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Muck.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Muck.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysummercar.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysummercar.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Notepad++.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Notepad++.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NVDisplay.Container.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfficeClickToRun.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfficeClickToRun.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe] +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\operagx.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\operagx.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photoshop.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photoshop.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PizzaFrenzy.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PizzaFrenzy.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlantsVsZombies.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlantsVsZombies.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlayGtaV.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlayGtaV.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rambox.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rambox.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVCpl64.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re6.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re6.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re7.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re7.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re8.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re8.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Resolve.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Resolve.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RuntimeBroker.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RuntimeBroker.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ShellExperienceHost.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SnowRunner.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SnowRunner.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SonicMania.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SonicMania.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Spotify.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Spotify.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SpotifyStartupTask.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SpotifyStartupTask.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11Srv.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11Srv.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11_64.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11_64.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Steam.exe] +"MaxLoaderThreads"=dword:00000001 +"mpc-hc64.exe"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Steam.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steamwebhelper.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steamwebhelper.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Teams.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Teams.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Terraria.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Terraria.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2_BE.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2_BE.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Update.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Update.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vgc.exe] +"MitigationOptions"=hex:00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VideoEditorPlus.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VideoEditorPlus.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WheresMyWater2.WindowsStore.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WheresMyWater2.WindowsStore.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinBM.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinBM.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WmiPrvSE.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WmiPrvSE.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zoom.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zoom.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + + +; 008. Connections + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] +"explorer.exe"=dword:00000002 +"sllauncher.exe"=dword:00000006 +"winword.exe"=dword:0000000d +"mspub.exe"=dword:0000000d +"powerpnt.exe"=dword:0000000d +"outlook.exe"=dword:0000000d +"onenote.exe"=dword:0000000d +"excel.exe"=dword:0000000d +"msaccess.exe"=dword:0000000d +"csgo.exe"=dword:0000000d +"jaraw.exe"=dword:0000000d +"chrome.exe"=dword:0000000d +"msedge.exe"=dword:0000000d +"edge.exe"=dword:0000000d +"opera.exe"=dword:0000000d +"firefox.exe"=dword:0000000d + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] +"explorer.exe"=dword:00000002 +"sllauncher.exe"=dword:00000006 +"winword.exe"=dword:0000000d +"mspub.exe"=dword:0000000d +"powerpnt.exe"=dword:0000000d +"outlook.exe"=dword:0000000d +"onenote.exe"=dword:0000000d +"excel.exe"=dword:0000000d +"msaccess.exe"=dword:0000000d +"csgo.exe"=dword:0000000d +"jaraw.exe"=dword:0000000d +"chrome.exe"=dword:0000000d +"msedge.exe"=dword:0000000d +"edge.exe"=dword:0000000d +"opera.exe"=dword:0000000d +"firefox.exe"=dword:0000000d + + +;009. +20GB Disk Space + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power] +"HibernateEnabled"=dword:00000000 +"HiberbootEnabled"=dword:00000000 +"ExitLatency "=dword:00000001 +"DisableVsyncLatencyUpdate"=dword:00000001 +"DisableSensorWatchdog"=dword:00000001 +"ExitLatencyCheckEnabled"=dword:00000001 +"Latency"=dword:00000001 +"LatencyToleranceDefault"=dword:00000000 +"LatencyToleranceFSVP"=dword:00000000 +"LatencyToleranceIdleResiliency"=dword:00000000 +"LatencyTolerancePerfOverride"=dword:00000000 +"LatencyToleranceScreenOffIR"=dword:00000000 +"LatencyToleranceVSyncEnabled"=dword:00000000 +"RtlCapabilityCheckLatency "=dword:00000001 +"MfBufferingThreshold"=dword:00000000 +"CoalescingTimerInterval"=dword:00000000 +"CsEnabled"=dword:00000000 +"EnergyEstimationEnabled"=dword:00000000 +"PerfCalculateActualUtilization"=dword:00000000 +"SleepReliabilityDetailedDiagnostics"=dword:00000000 +"EventProcessorEnabled"=dword:00000000 +"QosManagesIdleProcessors"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management] +"PagingFiles"=hex(7):00,00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager] +"ShippedWithReserves"=dword:00000000 +"PassedPolicy"=dword:00000000 + + +;010. Realtek HDA Tweaks + +[HKEY_CURRENT_USER\Software\Realtek\Audio\RtkNGUI64\General] +"JDPopup"=dword:00000001 +"CplExecuted_104386C7_104386C7"=dword:00000001 +"LastFixDefaultTime"=hex:e2,07,0c,00,02,00,04,00,00,00,20,00,33,00,fd,00 +"RenderDefaultFixed"=dword:00000001 +"CaptureDefaultFixed"=dword:00000001 +"Language"=dword:00000000 +"CplExecuted_103C830C_103C830C"=dword:00000001 +"AutoSelectChannelByJackConf"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Realtek\Audio\RtkNGUI64\PowerMgnt] +"Enabled"=dword:00000001 +"DelayTime"=dword:00000003 +"OnlyBattery"=dword:00000000 +"PowerState"=dword:00000000 + +;011. Disable System Restore + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] +"DisableSR"=dword:00000001 + +;012. Add Open With.. for URL Files + + +[HKEY_CLASSES_ROOT\IE.AssocFile.URL\ShellEx\ContextMenuHandlers\{09799AFB-AD67-11d1-ABCD-00C04FC30936}] + +;013. Prefetch Disable + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters] +"EnablePrefetcher"=dword:00000000 +"EnableSuperfetch"=dword:00000000 +"BootId"=- +"BaseTime"=- + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main] +"AllowPrelaunch"=dword:00000000 + +;014. Disable Keyboard shortcuts with Accesibility + + +[HKEY_CURRENT_USER\Control Panel\Accessibility\HighContrast] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\Keyboard Response] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\MouseKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\SoundSentry] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\StickyKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\TimeOut] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\ToggleKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\SlateLaunch] +"ATapp"=- + +[HKEY_CURRENT_USER\Control Panel\Accessibility\TimeOut] +"Flags"="0" + + +;015. Disable Animation and Transparency + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects] +"VisualFxSetting"=dword:00000003 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"DITest"=dword:00000000 + +[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\DWM] +"CompositionPolicy"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\DWM] +"CompositionPolicy"=dword:00000000 + + +[HKEY_USERS\.DEFAULT\Control Panel\Desktop] +"ForegroundLockTimeout"=dword:00000000 +"MenuShowDelay"="0" +"MouseWheelRouting"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] +"DesktopHeapLogging"=dword:00000000 +"DwmInputUsesIoCompletionPort"=dword:00000000 +"EnableDwmInputProcessing"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Dwm] +"AnimationAttributionEnabled"=dword:00000000 +"AnimationAttributionHashingEnabled"=dword:00000000 +"OneCoreNoBootDWM"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Dwm] +"ForceEffectMode"=- + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DWM] +"DWMWA_TRANSITIONS_FORCEDISABLED"=dword:00000001 +"DisallowFlip3d"=dword:00000001 +"DisallowColorizationColorChanges"=dword:00000001 +"DisallowAnimations"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\DWM] +"Composition"=dword:00000000 +"EnableAeroPeek"=dword:00000000 +"AlwaysHibernateThumbnails"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\International] +"s1159"="AM" +"s2359"="PM" +"sCurrency"="$" +"sDate"="." +"sDecimal"="," +"sGrouping"="3;0" +"sList"="." +"sLongDate"="dddd, dd.MM.yyyy" +"sMonDecimalSep"="." +"sMonGrouping"="3;0" +"sMonThousandSep"="," +"sNativeDigits"="0123456789" +"sNegativeSign"="-" +"sPositiveSign"="" +"sShortDate"="dd.MM.yyyy" +"sThousand"="." +"sTime"=":" +"sTimeFormat"="HH:mm:ss" +"sShortTime"="HH:mm" +"iFirstDayOfWeek"="0" +"iLZero"="1" +"iMeasure"="0" +"iNegCurr"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MultiTaskingView\AllUpView] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Desktop] +"DragFullWindows"="1" +"FontSmoothing"="2" +"FontSmoothingType"=dword:00000002 +"MenuShowDelay"="0" +"UserPreferencesMask"=hex:90,12,01,80,10 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize] +"EnableTransparency"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager] +"ThemeActive"="0" + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MultitaskingView\AllUpView] +"AllUpView"=dword:00000000 +"Remove TaskView"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer] +"AltTabSettings"=dword:00000001 +"ExplorerStartupTraceRecorded"=dword:00000000 +"UserSignedIn"=dword:00000001 +"TelemetrySalt"=dword:00000000 +"SIDUpdatedOnLibraries"=dword:00000001 +"LocalKnownFoldersMigrated"=dword:00000001 +"SlowContextMenuEntries"=- +"FirstRunTelemetryComplete"=- +"PostAppInstallTasksCompleted"=dword:00000001 +"NoPreviousVersionsPage"=dword:00000001 +"MultipleInvokePromptMinimum"=dword:00001388 +"AltTabSettings"=dword:00000001 +"link"=hex:00,00,00,00 +"ExcludedFromStableAnaheimDownloadPromotionSL"=dword:00000001 +"IrisClientRefresh"=dword:00000000 +"Reason Setting"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\People] +"PeopleBand"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics] +"PaddedBorderWidth"="0" + +[HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics] +"MinAnimate"="0" +"MaxAnimate"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE] +"DisableExternalDMAUnderLock"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability] +"TimeStampInterval"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"DisableThumbnails"=- + +[HKEY_CLASSES_ROOT\*] +"DefaultDropEffect"=dword:00000001 + +[HKEY_CLASSES_ROOT\AllFilesystemObjects] +"DefaultDropEffect"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] +"ThumbnailQuality"=dword:00000032 +"SmartScreenEnabled"="Off" +"NoPreviousVersionsPage"=dword:00000001 +"HubMode"=dword:00000001 +"Max Cached Icons"="4096" +"EnableAutoTray"=dword:00000001 +"DesktopProcess"=dword:00000001 +"ShowRecent"=dword:00000000 +"ShowFrequent"=dword:00000000 + +;016. DirectX API Optimization + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000000 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + + +;017. Internet Security Zone Setiings + + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones] +"SelfHealCount"=dword:00000001 +"SecuritySafe"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones] +"SelfHealCount"=dword:00000001 +"SecuritySafe"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] +"CertificateRevocation"=dword:00000001 +"DisableCachingOfSSLPages"=dword:00000000 +"PrivacyAdvanced"=dword:00000001 +"SecureProtocols"=dword:00002aa0 +"EnableNegotiate"=dword:00000001 +"MigrateProxy"=dword:00000001 +"ProxyEnable"=dword:00000000 +"WarnonZoneCrossing"=dword:00000000 +"EnableHttp1_1"=dword:00000001 +"ProxyHttp1.1"=dword:00000001 +"EnableHTTP2"=dword:00000001 +"EnablePunycode"=dword:00000001 +"UrlEncoding"=dword:00000000 +"DisableIDNPrompt"=dword:00000000 +"ShowPunycode"=dword:00000000 +"WarnonBadCertRecving"=dword:00000001 +"WarnOnPostRedirect"=dword:00000001 +"SyncMode5"=dword:00000003 + + +[HKEY_USERS\.DEFAULT\Microsoft\Windows\CurrentVersion\Internet Settings] +"CertificateRevocation"=dword:00000001 +"DisableCachingOfSSLPages"=dword:00000000 +"PrivacyAdvanced"=dword:00000001 +"SecureProtocols"=dword:00002aa0 +"EnableNegotiate"=dword:00000001 +"MigrateProxy"=dword:00000001 +"ProxyEnable"=dword:00000000 +"WarnonZoneCrossing"=dword:00000000 +"EnableHttp1_1"=dword:00000001 +"ProxyHttp1.1"=dword:00000001 +"EnableHTTP2"=dword:00000001 +"EnablePunycode"=dword:00000001 +"UrlEncoding"=dword:00000000 +"DisableIDNPrompt"=dword:00000000 +"ShowPunycode"=dword:00000000 +"WarnonBadCertRecving"=dword:00000001 +"WarnOnPostRedirect"=dword:00000001 +"SyncMode5"=dword:00000003 + + +;018. Microsoft Windows's Keylogger Disable + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AppModel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Cellcore] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Circular Kernel Context Logger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\CloudExperienceHostOobe] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DataMarket] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DiagLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\HolographicDevice] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\iclsClient] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\iclsProxy] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\LwtNetLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Mellanox-Kernel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Microsoft-Windows-AssignedAccess-Trace] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Microsoft-Windows-Setup] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\NBSMBLOGGER] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\PEAuthLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\RdrLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\ReadyBoot] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SetupPlatform] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SetupPlatformTel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SocketHeciServer] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SpoolerLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SQMLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TCPIPLOGGER] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TileStore] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Tpm] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TPMProvisioningService] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\UBPM] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WFP-IPsec Trace] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiDriverIHVSession] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiDriverIHVSessionRepro] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiSession] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WinPhoneCritical] +"Start"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\PwdlessAggregator] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\PwdlessAggregator\{fb3cd94d-95ef-5a73-b35c-6c78451095ef}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{025d2741-697b-5e0e-7e77-9a36140251f7}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{2504bc27-0e8b-5fed-7a9f-d86972086285}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{46b13027-2dfd-46e1-832d-e41e2810e6e5}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{59dd67cc-7ce1-52f8-cf74-fe8a257a2b6b}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{a8b932c2-51ec-5c22-63fc-0115fd79b9e0}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{cee50f59-e321-4691-9bb7-9b75494f6aab}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{d48679eb-8aa3-4138-be24-f1648C874e49}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{025d2741-697b-5e0e-7e77-9a36140251f7}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{59dd67cc-7ce1-52f8-cf74-fe8a257a2b6b}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{a8b932c2-51ec-5c22-63fc-0115fd79b9e0}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{e77a560c-3696-4ac0-911c-545ceca6be3c}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{18D6CBEB-1E21-500A-27E2-8BA2BEAC7C00}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{3D6120A6-0986-51C4-213A-E2975903051D}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{59DD67CC-7CE1-52F8-CF74-FE8A257A2B6B}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{8BE48F34-1F58-4180-8C12-DBE6E6E71A81}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{AC8D9176-9E0-5047-9B60-1AABC45281B8}] +"Enabled"=dword:00000000 +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{B39B8CEA-EAAA-5A74-5794-4948E222C663}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{BBC9A2C9-EEED-58D4-9483-6C87118F9EC6}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{CEE50F59-E321-4691-9BB7-9B75494F6AAB}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{D059A021-6947-44FB-976A-B18C9B73D1D8}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{1377561d-9312-452c-ad13-c4a1c9c906e0}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{1a1dfad0-6d37-5521-1d72-1f87dd20423c}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{3E0D88DE-AE5C-438A-BB1C-C2E627F8AECB}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{76AD4308-DF7C-5F43-E668-FCEA4FA1179D}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{b6acef34-fab6-5909-6b6b-b1c2cc84057f}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{D1094A14-063E-7A21-A301-F2FE3BA23F62}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{EC4BA041-1DFE-5F76-EF6D-0251DA19D178}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Host] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Host\0] +"Status"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\PwdlessAggregator] +"HbStart"=dword:00000000 +"HbStop"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdateHeartbeatScan] + +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdatePolicyScenarioReliabilityAggregator] +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdateReboot] +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UusFailover] +"HbStart"=dword:00000000 + + +;019. Disable Telemetry + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppV\CEIP] +"CEIPEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\FirewallAPI] +"Active"=dword:00000000 +"ControlFlags"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\PlugPlay\SETUPAPI] +"Active"=dword:00000000 +"ControlFlags"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\SCM\Regular] +"TracingDisabled"=dword:00000001 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\AsimovUploader] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventMonitors] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling] +"PowerThrottlingOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\EnergyEstimation\TaggedEnergy] +"DisableTaggedEnergyLogging"=dword:00000001 +"TelemetryMaxApplication"=dword:00000000 +"TelemetryMaxTagPerApplication"=dword:00000000 + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection] +"AllowTelemetry"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CloudContent] +"DisableWindowsConsumerFeatures"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Narrator\NoRoam] +"WinEnterLaunchEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorPort] +"TelemetryPerformanceEnabled"=dword:00000000 +"TelemetryErrorDataEnabled"=dword:00000000 +"Tele­metry­DeviceHealthEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub\hubg] +"DisableOnSoftRemove"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction] +"Enable"="N" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl] +"AutoReboot"=dword:00000000 +"CrashDumpEnabled"=dword:00000000 +"DumpFile"=hex(2):70,00,75,00,6c,00,61,00,00,00 +"DumpLogLevel"=dword:00000000 +"EnableLogFile"=dword:00000000 +"LogEvent"=dword:00000000 +"MinidumpDir"=hex(2):70,00,75,00,6c,00,61,00,00,00 +"MinidumpsCount"=dword:00000000 +"Overwrite"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard] +"ExitOnMSICW"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection] +"DisableDiagnosticDataViewer"=dword:00000001 +"DisableOneSettingsDownloads"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 +"DisableTelemetryOptInChangeNotification"=dword:00000000 +"DisableTelemetryOptInSettingsUx"=dword:00000000 +"AllowCommercialDataPipeline"=dword:00000000 +"AllowDesktopAnalyticsProcessing"=dword:00000000 +"AllowDeviceNameInTelemetry"=dword:00000000 +"AllowTelemetry"=dword:00000000 +"AllowUpdateComplianceProcessing"=dword:00000000 +"AllowWUfBCloudProcessing"=dword:00000000 +"DisableDeviceDelete"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000000 +"LimitDumpCollection"=dword:00000001 +"LimitEnhancedDiagnosticDataWindowsAnalytics"=dword:00000001 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection] +"AllowTelemetry"=dword:00000000 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 +"DisableDiagnosticDataViewer"=dword:00000001 +"DisableOneSettingsDownloads"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 +"DisableTelemetryOptInChangeNotification"=dword:00000000 +"DisableTelemetryOptInSettingsUx"=dword:00000000 +"AllowCommercialDataPipeline"=dword:00000000 +"AllowDesktopAnalyticsProcessing"=dword:00000000 +"AllowDeviceNameInTelemetry"=dword:00000000 +"AllowUpdateComplianceProcessing"=dword:00000000 +"AllowWUfBCloudProcessing"=dword:00000000 +"DisableDeviceDelete"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000000 +"LimitDumpCollection"=dword:00000001 +"LimitEnhancedDiagnosticDataWindowsAnalytics"=dword:00000001 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] +"TargetGroup"="Workstations" +"TargetGroupEnabled"=dword:00000000 +"WUServer"="http://x.x.x.x:8530" +"WUStatusServer"="http://x.x.x.x:8530" +"DeferUpgrade"=dword:00000001 +"DisableOSUpgrade"=dword:00000001 +"SetActiveHoursMaxRange"=dword:00000001 +"ActiveHoursMaxRange"=dword:00000012 +"AllowAutoWindowsUpdateDownloadOverMeteredNetwork"=dword:00000001 +"NoAutoRebootWithLoggedOnUsers"=dword:00000001 +"NoAUShutdownOption"=dword:00000001 +"NoAUAsDefaultShutdownOption"=dword:00000001 +"AlwaysAutoRebootAtScheduledTime"=dword:00000001 +"AlwaysAutoRebootAtScheduledTimeMinutes"=dword:0000000f +"EnableFeaturedSoftware"=dword:00000000 +"DisableWindowsUpdateAccess"=dword:00000001 +"SetAutoRestartNotificationDisable"=dword:00000001 +"SetActiveHours"=dword:00000001 +"ActiveHoursStart"=dword:00000007 +"ActiveHoursEnd"=dword:00000016 +"SetPolicyDrivenUpdateSourceForFeatureUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForQualityUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForDriverUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForOtherUpdates"=dword:00000000 +"DoNotConnectToWindowsUpdateInternetLocations"=dword:00000001 +"DisableDualScan"=dword:00000001 +"SetUpdateNotificationLevel"=dword:00000001 +"UpdateNotificationLevel"=dword:00000001 +"AcceptTrustedPublisherCerts"=dword:00000001 +"ElevateNonAdmins"=dword:00000001 +"BranchReadinessLevel"=dword:00000002 +"TargetReleaseVersion"=dword:00000000 +"DisableWUfBSafeguards"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\TraceManager] +"MiniTraceSlotContentPermitted"=dword:00000000 +"MiniTraceSlotEnabled"=dword:00000000 +"alternativeTraceScenarioId"="" +"alternativeTraceStartTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceStopTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceHasStopTime"=dword:00000000 +"alternativeTracePriority"=dword:00000000 +"alternativeTraceIsExclusive"=dword:00000000 +"alternativeTraceIsAutoLogger"=dword:00000000 +"alternativeTraceProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceIsThrottled"=dword:00000000 +"alternativeTraceRequiredBufferSpace"=dword:00000000 +"alternativeTraceThrottleState"=dword:00000000 +"aotScenarioId"="" +"aotStartTime"=hex(b):00,00,00,00,00,00,00,00 +"aotSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"aotStopTime"=hex(b):00,00,00,00,00,00,00,00 +"aotMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"aotHasStopTime"=dword:00000000 +"aotPriority"=dword:00000000 +"aotIsExclusive"=dword:00000000 +"aotIsAutoLogger"=dword:00000000 +"aotProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"aotIsThrottled"=dword:00000000 +"aotRequiredBufferSpace"=dword:00000000 +"aotThrottleState"=dword:00000000 +"miniTraceScenarioId"="" +"miniTraceStartTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceStopTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceHasStopTime"=dword:00000000 +"miniTracePriority"=dword:00000000 +"miniTraceIsExclusive"=dword:00000000 +"miniTraceIsAutoLogger"=dword:00000000 +"miniTraceProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceIsThrottled"=dword:00000000 +"miniTraceRequiredBufferSpace"=dword:00000000 +"miniTraceThrottleState"=dword:00000000 +"diagScenarioId"="" +"diagStartTime"=hex(b):00,00,00,00,00,00,00,00 +"diagSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"diagStopTime"=hex(b):00,00,00,00,00,00,00,00 +"diagMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"diagHasStopTime"=dword:00000000 +"diagPriority"=dword:00000000 +"diagIsExclusive"=dword:00000000 +"diagIsAutoLogger"=- +"diagProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"diagIsThrottled"=dword:00000000 +"diagRequiredBufferSpace"=dword:00000000 +"diagThrottleState"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack] +"DiagTrackStatus"=dword:00000002 +"DiagTrackAuthorization"=dword:00000375 +"ConnectivityNoNetworkTime"=dword:00000000 +"ConnectivityRestrictedNetworkTime"=dword:00000000 +"UploadPermissionReceived"=dword:00000000 +"ShowedToastAtLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters] +"DisableParallelAandAAAA"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient] +"DisableSmartNameResolution"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Wacom\Analytics] +"Analytics_On"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\ProviderControl] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SettingsRequests\] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Tenants] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\TriggerListener] +"MatchEngineBufferSize"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventTranscriptKey] +"EnableEventTranscript"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\OmittedIds] +"w:B04E2543-63EB-D3C6-4722-FBFE64FA31C0"=dword:00000000 +"w:5B08FD5C-0859-F5E6-7503-0D19552D498E"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Features] +"EventTagDropUserIds"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InputPersonalization] +"RestrictImplicitInkCollection"=dword:00000001 +"RestrictImplicitTextCollection"=dword:00000001 +"Installed"=dword:00000000 +"Shutdown"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SpeechGestures] +"RDCPolicyCollectionLevel"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy] +"HasAccepted"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP] +"RestartTimer"=dword:00000000 +"ForceEncryptedData"=dword:00000001 +"ForceEncryptedPassword"=dword:00000002 +"SecureVPN"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LLTD] +"EnableLLTDIO"=dword:00000000 +"AllowLLTDIOOnDomain"=dword:00000000 +"AllowLLTDIOOnPublicNet"=dword:00000000 +"ProhibitLLTDIOOnPrivateNet"=dword:00000001 +"EnableRspndr"=dword:00000000 +"AllowRspndrOnDomain"=dword:00000000 +"AllowRspndrOnPublicNet"=dword:00000000 +"ProhibitRspndrOnPrivateNet"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager] +"FeatureManagementEnabled"=dword:00000000 +"SlideshowEnabled"=dword:00000000 +"OemPreInstalledAppsEnabled"=dword:00000000 +"PreInstalledAppsEnabled"=dword:00000000 +"RotatingLockScreenEnabled"=dword:00000000 +"RotatingLockScreenOverlayEnabled"=dword:00000000 +"SilentInstalledAppsEnabled"=dword:00000000 +"SoftLandingEnabled"=dword:00000000 +"SystemPaneSuggestionsEnabled"=dword:00000000 +"SubscribedContent-338389Enabled"=dword:00000000 +"SubscribedContent-338388Enabled"=dword:00000000 +"PreInstalledAppsEverEnabled"=dword:00000000 +"SubscribedContent-88000326Enabled"=dword:00000000 +"SubscribedContent-338393Enabled"=dword:00000000 +"SubscribedContent-353694Enabled"=dword:00000000 +"SubscribedContent-353696Enabled"=dword:00000000 +"SubscribedContent-353698Enabled"=dword:00000000 +"SubscribedContentEnabled"=dword:00000000 +"RemediationRequired"=dword:00000000 +"ShowSyncProviderNotifications"=dword:00000000 +"SubscribedContent-310093Enabled"=dword:00000000 +"SubscribedContent-314563Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AdvertisingInfo] +"DisabledByGroupPolicy"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\StorageTelemetry] +"DeviceDumpEnabled"=dword:00000000 +"StorageTCCode_0"=dword:00000000 +"StorageTCCode_1"=dword:00000000 +"StorageTCCode_2"=dword:00000000 +"StorageTCCode_3"=dword:00000000 +"StorageTCCode_4"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\LiveKernelReports] +"DeleteLiveMiniDumps"=dword:00000000 + + +;020. Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"NoInstrumentation"=dword:00000001 +"NoRecentDocsMenu"=dword:00000001 +"MemCheckBoxInRunDlg"=dword:00000001 +"NoSMConfigurePrograms"=dword:0000000 +"NoRemoteRecursiveEvents"=dword:00000001 +"NoLowDiskSpaceChecks"=dword:00000001 +"LinkResolveIgnoreLinkInfo"=dword:00000001 +"NoResolveSearch"=dword:00000001 +"NoResolveTrack"=dword:00000001 +"NoInternetOpenWith"=dword:00000001 +"DisableSearchBoxSuggestions"=dword:00000001 +"NoLowDiskSpaceChecks"=dword:00000001 +"ConfirmFileDelete"=dword:00000000 +"HideSCAMeetNow"=dword:00000001 +"NoRecentDocsNetHood"=dword:00000001 +"NoNetConnectDisconnect"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\QuietHours] +"Enable"=dword:00000000 +"AllowCalls"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel] +"AllItemsIconView"=dword:00000002 +"StartupPage"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Serialize] +"StartupDelayInMSec"=dword:00000000 + + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LocationAndSensors] +"DisableLocation"=dword:00000001 +"DisableLocationScripting"=dword:00000001 +"DisableWindowsLocationProvider"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Siuf\Rules] +"NumberOfSIUFInPeriod"=dword:00000000 +"PeriodInNanoSeconds"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"SeparateProcess"=dword:00000001 +"HideFileExt"=dword:00000000 +"DontPrettyPath"=dword:00000001 +"ShowInfoTip"=dword:00000001 +"MapNetDrvBtn"=dword:00000000 +"WebView"=dword:00000000 +"ShowSuperHidden"=dword:00000001 +"MMTaskbarGlomLevel"=dword:00000000 +"Start_ShowRun"=dword:00000001 +"ExtendedUIHoverTime"=dword:00000001 +"ListviewShadow"=dword:00000000 +"TaskbarAnimations"=dword:00000000 +"ListviewAlphaSelect"=dword:00000000 +"ListviewWatermark"=dword:00000000 +"StartShownOnUpgrade"=dword:00000001 +"TaskbarDa"=dword:00000000 +"LaunchTo"=dword:00000001 +"TaskbarMn"=dword:00000000 +"Start_NotifyNewApps"=dword:00000000 +"ShowSecondsInSystemClock"=dword:00000001 +"ShowSyncProviderNotifications"=dword:00000000 +"NavPaneShowAllFolders"=dword:00000000 +"NoNetCrawling"=dword:00000001 +"TaskbarSi"=dword:00000001 +"JointResize"=dword:00000000 +"SnapAssist"=dword:00000000 +"SnapFill"=dword:00000000 +"LastActiveClick"=dword:00000001 +"TaskbarSizeMove"=dword:00000001 +"ShowStatusBar"=dword:00000001 +"HideSCAMeetNow"=dword:00000001 +"NoRecentDocsNetHood"=dword:00000001 +"IconsOnly"=dword:00000000 +"Start_TrackProgs"=dword:00000000 +"Start_TrackDocs"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shutdown] +"CleanShutdown"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\AuxilliaryPins] +"MailPin"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel] +"AllItemsIconView"=dword:00000002 +"StartupPage"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] +"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] +"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pci\Parameters] +"ASPMOptOut"=dword:00000001 + + +;021. AutoPlay + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\ShowPicturesOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\WPD] + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\WPD\ImageSource] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\CameraAlternate] + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\CameraAlternate\ShowPicturesOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\StorageOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers\StorageOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers] +"DisableAutoplay"=dword:00000000 + + +;022. Internet Optimization + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ServiceProvider] +"DnsPriority"=dword:00000006 +"LocalPriority"=dword:00000004 +"NetbtPriority"=dword:00000007 +"HostPriority"=dword:00000005 +"HostsPriority"=dword:00000005 +"Class"=dword:00000008 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters] +"EnableWsd"=dword:00000000 +"DisableDynamicDiscovery"=dword:00000001 +"EnablePMTUDiscovery"=dword:00000000 +"EnablePMTUBDetect"=dword:00000000 +"EnableICMPRedirect"=dword:00000001 +"DisableTaskOffload"=dword:00000000 +"TcpMaxDupAcks"=dword:00000002 +"Tcp1323Opts"=dword:00000001 +"TcpTimedWaitDelay"=dword:00000002 +"MaxFreeTcbs"=dword:00010000 +"TCPCongestionControl"=dword:00000001 +"SackOpts"=dword:00000000 +"DefaultTTL"=dword:00000040 +"CongestionAlgorithm"=dword:00000001 +"MultihopSets"=dword:0000000f +"FastCopyReceiveThreshold"=dword:00004000 +"FastSendDatagramThreshold"=dword:00004000 +"DelayedAckFrequency"=dword:00000000 +"DelayedAckTicks"=dword:00000000 +"UseDomainNameDevolution"=dword:00000000 +"IGMPLevel"=dword:00000000 +"GlobalMaxTcpWindowSize"=dword:00256960 +"TcpWindowSize"=dword:00256960 +"MaxConnectionsPer1_0Server"=dword:00000016 +"MaxConnectionsPerServer"=dword:00000016 +"MaxUserPort"=dword:00065534 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\Standard TCP/IP Port\Ports] +"LprAckTimeout"=dword:00000002 +"StatusUpdateEnabled"=dword:00000001 +"StatusUpdateInterval"=dword:0000000a + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\QoS] +"Do not use NLA"=dword:00000001 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Winsock] +"UseDelayedAcceptance"=dword:00000000 +"MaxSockAddrLength"=dword:00000010 +"MinSockAddrLength"=dword:00000010 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard] +"ExitOnMSICW"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkConnectivityStatusIndicator] +@="" +"NoActiveProbe"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender] +"DisableRoutinelyTakingAction"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender] +"DisableRoutinelyTakingAction"=dword:00000001 + +[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\QoS] +"Do not use NLA"="1" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSMQ\Parameters] +"TCPNoDelay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces] +"TcpAckFrequency"=dword:00000001 +"TCPNoDelay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TCPIP\v6Transition] +"Teredo_ClientPort"=dword:00000000 +"Teredo_DefaultQualified"="Enabled" +"Teredo_RefreshRate"=dword:0000001e +"Teredo_ServerName"="win10.ipv6.microsoft.com" +"Teredo_State"="Enterprise Client" + +;023. Disable Sound at Startup + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootControl] +"BootProgressAnimation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Boot] +"DisableStartupSound"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet] +"ActiveDnsProbeContent"="208.67.222.222" +"ActiveDnsProbeContentV6"="2620:119:35::35" +"ActiveDnsProbeHost"="resolver1.opendns.com" +"ActiveDnsProbeHostV6"="resolver1.opendns.com" +"ActiveWebProbeContent"="success" +"ActiveWebProbeContentV6"="success" +"ActiveWebProbeHost"="detectportal.firefox.com" +"ActiveWebProbeHostV6"="detectportal.firefox.com" +"ActiveWebProbePath"="success.txt" +"ActiveWebProbePathV6"="success.txt" + +[HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\WiFi\AllowAutoConnectToWiFiSenseHotspots] +"value"=dword:00000000 + +;024. Region Part + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CodePage] +"1250"="c_1251.nls" +"1251"="c_1251.nls" +"1252"="c_1251.nls" +"1253"="c_1251.nls" +"1254"="c_1251.nls" +"1255"="c_1251.nls" + +;025. GPU-n Driver Optimization + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"PlatformSupportMiracast"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\NVIDIA Corporation\Global\NVTweak\Devices\509901423-0\Color] +"NvCplUseColorCorrection"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] +"Optional"="" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\FTS] +"EnableRID61684"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\Global\NVTweak] +"DisplayPowerSaving"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Scheduler] +"EnablePreemption"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0000] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"TdrLevel"=dword:00000000 +"UseGpuTimer"=dword:00000001 +"RmGpsPsEnablePerCpuCoreDpc"=dword:00000001 +"PowerSavingTweaks"=dword:00000000 +"DisableWriteCombining"=dword:00000001 +"EnableRuntimePowerManagement"=dword:00000000 +"PrimaryPushBufferSize"=dword:00000001 +"FlTransitionLatency"=dword:00000000 +"D3PCLatency"=dword:00000000 +"RMDeepLlEntryLatencyUsec"=dword:00000000 +"PciLatencyTimerControl"=dword:00000020 +"Node3DLowLatency"=dword:00000001 +"LOWLATENCY"=dword:00000001 +"RmDisableRegistryCaching"=dword:00000001 +"RMDisablePostL2Compression"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Power] +"UseGpuTimer"=dword:00000001 +"RmGpsPsEnablePerCpuCoreDpc"=dword:00000001 +"PowerSavingTweaks"=dword:00000000 +"DisableWriteCombining"=dword:00000001 +"EnableRuntimePowerManagement"=dword:00000000 +"PrimaryPushBufferSize"=dword:00000001 +"FlTransitionLatency"=dword:00000000 +"D3PCLatency"=dword:00000000 +"RMDeepLlEntryLatencyUsec"=dword:00000000 +"PciLatencyTimerControl"=dword:00000020 +"Node3DLowLatency"=dword:00000001 +"LOWLATENCY"=dword:00000001 +"RmDisableRegistryCaching"=dword:00000001 +"RMDisablePostL2Compression"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceNoContext"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceMonitorOff"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceActivelyUsed"=dword:00000001 +"DefaultLatencyToleranceTimerPeriod "=dword:00000001 +"DefaultLatencyToleranceOther"=dword:00000001 +"DefaultLatencyToleranceNoContextMonitorOff"=dword:00000001 +"DefaultLatencyToleranceNoContext"=dword:00000001 +"DefaultLatencyToleranceMemory"=dword:00000001 +"DefaultLatencyToleranceIdle1MonitorOff"=dword:00000001 +"DefaultLatencyToleranceIdle1"=dword:00000001 +"DefaultLatencyToleranceIdle0MonitorOff"=dword:00000001 +"DefaultLatencyToleranceIdle0"=dword:00000001 +"DefaultD3TransitionLatencyIdleVeryLongTime"=dword:00000001 +"DefaultD3TransitionLatencyIdleShortTime"=dword:00000001 +"DefaultD3TransitionLatencyIdleNoContext"=dword:00000001 +"DefaultD3TransitionLatencyIdleMonitorOff"=dword:00000001 +"DefaultD3TransitionLatencyIdleLongTime"=dword:00000001 +"DefaultD3TransitionLatencyActivelyUsed"=dword:00000001 +"Latency"=dword:00000001 +"DefaultD3TransitionLatencyActivelyUsed"=dword:00000001 +"TransitionLatency"=dword:00000001 +"MonitorRefreshLatencyTolerance"=dword:00000001 +"MonitorLatencyTolerance"=dword:00000001 +"MiracastPerfTrackGraphicsLatency"=dword:00000001 +"MaxIAverageGraphicsLatencyInOneBucket"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"DpiMapIommuContiguous"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0001] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0002] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0000] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0001] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0002] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0003] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0001] +"LTRSnoopL1Latency"=dword:00000001 +"LTRSnoopL0Latency"=dword:00000001 +"LTRNoSnoopL1Latency"=dword:00000001 +"LTRMaxNoSnoopLatency"=dword:00000001 +"KMD_RpmComputeLatency"=dword:00000001 +"DalUrgentLatencyNs"=dword:00000001 +"memClockSwitchLatency"=dword:00000001 +"PP_RTPMComputeF1Latency"=dword:00000001 +"PP_DGBMMMaxTransitionLatencyUvd"=dword:00000001 +"PP_DGBPMMaxTransitionLatencyGfx"=dword:00000001 +"DalNBLatencyForUnderFlow"=dword:00000001 +"DalDramClockChangeLatencyNs"=dword:00000001 +"BGM_LTRSnoopL1Latency"=dword:00000001 +"BGM_LTRSnoopL0Latency"=dword:00000001 +"BGM_LTRNoSnoopL1Latency"=dword:00000001 +"BGM_LTRNoSnoopL0Latency"=dword:00000001 +"BGM_LTRMaxSnoopLatencyValue"=dword:00000001 +"BGM_LTRMaxNoSnoopLatencyValue"=dword:00000001 +"EnableVceSwClockGating"=dword:00000001 +"EnableUvdClockGating"=dword:00000001 +"DisableVCEPowerGating"=dword:00000000 +"DisableUVDPowerGatingDynamic"=dword:00000000 +"DisablePowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisableFBCForFullScreenApp"="0" +"DisableFBCSupport"=dword:00000000 +"DisableEarlySamuInit"=dword:00000001 +"PP_GPUPowerDownEnabled"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_SclkDeepSleepDisable"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000001 +"PP_ActivityTarget"=dword:0000001e +"PP_ODNFeatureEnable"=dword:00000001 +"EnableUlps"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"PP_AllGraphicLevel_DownHyst"=dword:00000014 +"PP_AllGraphicLevel_UpHyst"=dword:00000000 +"KMD_FRTEnabled"=dword:00000000 +"DisableDMACopy"=dword:00000001 +"DisableBlockWrite"=dword:00000000 +"PP_ODNFeatureEnable"=dword:00000001 +"KMD_MaxUVDSessions"=dword:00000020 +"DalAllowDirectMemoryAccessTrig"=dword:00000001 +"DalAllowDPrefSwitchingForGLSync"=dword:00000000 +"WmAgpMaxIdleClk"=dword:00000020 +"StutterMode"=dword:00000000 +"TVEnableOverscan"=dword:00000000 +"PowerMizerEnable"=dword:00000001 +"PowerMizerLevel"=dword:00000001 +"PowerMizerLevelAC"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000] +"LTRSnoopL1Latency"=dword:00000001 +"LTRSnoopL0Latency"=dword:00000001 +"LTRNoSnoopL1Latency"=dword:00000001 +"LTRMaxNoSnoopLatency"=dword:00000001 +"KMD_RpmComputeLatency"=dword:00000001 +"DalUrgentLatencyNs"=dword:00000001 +"memClockSwitchLatency"=dword:00000001 +"PP_RTPMComputeF1Latency"=dword:00000001 +"PP_DGBMMMaxTransitionLatencyUvd"=dword:00000001 +"PP_DGBPMMaxTransitionLatencyGfx"=dword:00000001 +"DalNBLatencyForUnderFlow"=dword:00000001 +"DalDramClockChangeLatencyNs"=dword:00000001 +"BGM_LTRSnoopL1Latency"=dword:00000001 +"BGM_LTRSnoopL0Latency"=dword:00000001 +"BGM_LTRNoSnoopL1Latency"=dword:00000001 +"BGM_LTRNoSnoopL0Latency"=dword:00000001 +"BGM_LTRMaxSnoopLatencyValue"=dword:00000001 +"BGM_LTRMaxNoSnoopLatencyValue"=dword:00000001 +"EnableVceSwClockGating"=dword:00000001 +"EnableUvdClockGating"=dword:00000001 +"DisableVCEPowerGating"=dword:00000000 +"DisableUVDPowerGatingDynamic"=dword:00000000 +"DisablePowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisableFBCForFullScreenApp"="0" +"DisableFBCSupport"=dword:00000000 +"DisableEarlySamuInit"=dword:00000001 +"PP_GPUPowerDownEnabled"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_SclkDeepSleepDisable"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000001 +"PP_ActivityTarget"=dword:0000001e +"PP_ODNFeatureEnable"=dword:00000001 +"EnableUlps"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"PP_AllGraphicLevel_DownHyst"=dword:00000014 +"PP_AllGraphicLevel_UpHyst"=dword:00000000 +"KMD_FRTEnabled"=dword:00000000 +"DisableDMACopy"=dword:00000001 +"DisableBlockWrite"=dword:00000000 +"PP_ODNFeatureEnable"=dword:00000001 +"KMD_MaxUVDSessions"=dword:00000020 +"DalAllowDirectMemoryAccessTrig"=dword:00000001 +"DalAllowDPrefSwitchingForGLSync"=dword:00000000 +"WmAgpMaxIdleClk"=dword:00000020 +"StutterMode"=dword:00000000 +"TVEnableOverscan"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm] +"NVFBCEnable"=dword:00000001 +"DisablePreemption"=dword:00000001 +"DisableCudaContextPreemption"=dword:00000001 +"DisableWriteCombining"=dword:00000001 +"EnableTiledDisplay"=dword:00000000 +"ComputePreemption"=dword:00000000 +"DisablePreemptionOnS3S4"=dword:00000001 +"EnableCEPreemption"=dword:00000000 + +[HKLM\SYSTEM\CurrentControlSet\Services\DXGKrnl] +"MonitorLatencyTolerance"=dword:00000001 + +[HKLM\SYSTEM\CurrentControlSet\Services\DXGKrnl] +"MonitorRefreshLatencyTolerance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid\Parameters] +"TreatAbsolutePointerAsAbsolute"=dword:00000001 +"TreatAbsoluteAsRelative"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\CDP] +"CdpSessionUserAuthzPolicy"=dword:00000000 +"RomeSdkChannelUserAuthzPolicy"=dword:00000000 + +;026. Session Manager Configuration (Meltown and Spectre) + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"DisablePagingExecutive"=dword:00000001 +"LargeSystemCache"=dword:00000001 +"NonPagedPoolSize"=dword:000000c0 +"PagedPoolSize"=dword:000000c0 +"FeatureSettings"=dword:00000001 +"FeatureSettingsOverride"=dword:00000003 +"FeatureSettingsOverrideMask"=dword:00000003 +"PoolUsageMaximum"=dword:000000c0 +"EnableCfg"=dword:00000000 +"IoPageLockLimit"=dword:ffffffff +"ProtectionMode"=dword:00000000 +"ThirdLevelDataCache"=dword:00008192 +"MoveImages"=dword:00000000 +"PhysicalAddressExtension"=dword:00000001 +"SecondLevelDataCache"=dword:00003072 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel] +"DpcWatchdogProfileOffset"=dword:00000000 +"DpcTimeout"=dword:00000000 +"DpcWatchdogPeriod"=dword:00000000 +"DisableExceptionChainValidation"=dword:00000001 +"KernelSEHOPEnabled"=dword:00000000 +"DpcWatchdogProfileOffset"=dword:00000000 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,20,02,00,00,00,20,00,00 +"MitigationAuditOptions"=hex:20,00,00,20,20,20,22,22,00,00,00,00,00,00,00,00 +"DisableExceptionChainValidation"=dword:00000001 +"MaximumSharedReadyQueueSize"=dword:00000001 +"DisableAutoBoost"=dword:00000001 +"DistributeTimers"=dword:00000001 +"IdealDpcRate"=dword:00000001 +"MaximumDpcQueueDepth"=dword:00000001 +"MinimumDpcRate"=dword:00000001 +"ThreadDpcEnable"=dword:00000001 +"AdjustDpcThreshold"=dword:00000000 +[HKEY_LOCAL_MACHINE\SYSTEM] +"MinimumWorkingSet"=hex(b):00,00,00,00,00,10,00,00 +"MinimumFileCacheSize"=hex(b):00,00,00,00,00,10,00,00 +"increaseuserva"=dword:0fffff80 +"InterruptSteeringDisabled"=dword:00000001 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 +"OverlayTestMode"=dword:00000005 +"UseLargePages"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsMitigation] +"UserPreference"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"MinimumWorkingSet"=hex(b):00,00,00,00,00,10,00,00 +"MinimumFileCacheSize"=hex(b):00,00,00,00,00,10,00,00 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 +"OverlayTestMode"=dword:00000005 +"UseLargePages"=dword:00000001 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xusb22\Parameters] +"IoQueueWorkItem"=dword:0000000a + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters] +"DisabledComponents"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseSensitivity"="10" + + +;027.SecDrv + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SecDrv] +"Type"=dword:00000001 +"Start"=dword:00000003 +"ErrorControl"=dword:00000001 +"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ + 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,00,69,\ + 00,76,00,65,00,72,00,73,00,5c,00,53,00,45,00,43,00,44,00,52,00,56,00,2e,00,\ + 53,00,59,00,53,00,00,00 +"DisplayName"="SecDrv" +"WOW64"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SecDrv\Security] +"Security"=hex:01,00,14,80,8c,00,00,00,98,00,00,00,14,00,00,00,30,00,00,00,02,\ + 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ + 00,00,02,00,5c,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ + 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ + 20,02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\ + 00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,\ + 00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 + +;028.Resource Management + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\I/O System] +"PassiveIntRealTimeWorkerPriority"=dword:00000018 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\KernelVelocity] +"DisableFGBoostDecay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\HardCap0] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\Paused] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapFull] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapFullAboveNormal] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapLow] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapLowBackgroundBegin] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\UnmanagedAboveNormal] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\BackgroundDefault] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Frozen] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenDNCS] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenDNK] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenPPLE] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Paused] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\PausedDNK] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Pausing] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\PrelaunchForeground] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\ThrottleGPUInterference] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Critical] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\CriticalNoUi] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\EmptyHostPPLE] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\High] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Low] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Lowest] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Medium] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\MediumHigh] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\StartHost] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\VeryHigh] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\VeryLow] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\IO\NoCap] +"IOBandwidth"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Memory\NoCap] +"CommitLimit"=dword:ffffffff +"CommitTarget"=dword:ffffffff + +;029. Services + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdpsp] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpbus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CDPUserSvc] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\acpitime] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AcpiPmi] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AcpiDev] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\acpipagr] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GpuEnergyDrv] +"Start"=dword:00000004 + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\AMDLOG] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus_25D3A396F7F029EE] +"Start"=dword:00000004 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell] +"ConvertibleSlateModePromptPreference"=dword:00000000 +"TabletMode"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\perceptionsimulation] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PenService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edgeupdate] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edgeupdatem] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GoogleChromeElevationService] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Credssp] +"DebugLogLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] +"RestrictReceivingNTLMTraffic"=dword:00000002 +"RestrictSendingNTLMTraffic"=dword:00000002 +"SCENoApplyLegacyAuditPolicy"=dword:00000000 +"RestrictAnonymousSAM"=dword:00000001 +"RestrictAnonymous"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Throttle] +"PerfEnablePackageIdle"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Processor] +"CPPCEnable"=dword:00000000 +"AllowPepPerfStates"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge] +"SitePerProcess"=dword:00000001 + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.devicemetadata-ms] + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter] +"EnabledV9"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hola_updater] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CaptureService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSSystemAnalysis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSSystemDiagnosis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSLinkNear] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSLinkRemote] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BcastDVRUserService] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gameflt] +"Start"=dword:00000004 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WerSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndu] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiSystemHost] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GpuEnergyDrv] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\storqosflt] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hvcmon] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GraphicsPerfSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PcaSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DiagTrack] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmwappushservice] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\diagsvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DPS] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\diagnosticshub.standardcollector.service] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiServiceHost] + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WacomPen] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PktMon] +"Start"=dword:00000004 +"Type"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVEdrv] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep] +"Start"=dword:00000004 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysMain] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WSearch] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AMD External Events Utility] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSLinkNear] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSLinkRemote] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSSystemAnalysis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSSystemDiagnosis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BcastDVRUserService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_64] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_32] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_64] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdate] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdatem] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdatem] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisVirtualBus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vid] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\umbus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpbus] +"Start"=dword:00000004 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndu] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisCap] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemUsageReportSvc_QUEENCREEK] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Intel(R) SUR QC SAM] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMS] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEIx64] +"Start"=dword:00000004 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GraphicsPerfSvc] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dam] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Audiosrv] +"ErrorControl"=dword:00000002 + + + +;030. File System Efficency + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem] +"DisableDeleteNotification"=dword:00000001 +"RefsDisableLastAccessUpdate"=dword:00000001 +"Win31FileSystem"=dword:00000000 +"Win95TruncatedExtensions"=dword:00000000 +"LongPathsEnabled"=dword:00000001 +"NtfsDisableLastAccessUpdate"=dword:00000001 +"NtfsMemoryUsage"=dword:00000000 +"NtfsMftZoneReservation"=dword:00000004 +"NtfsDisableSpotCorruptionHandling"=dword:00000001 +"RefsDisableLastAccessUpdate"=dword:00000001 +"NtfsBugcheckOnCorrupt"=dword:00000000 +"LongPathsEnabled"=dword:00000001 +"NTFSDisable8dot3NameCreation"=dword:00000001 +"LongPathsEnabled"=dword:00000001 + + +;031. Delay & Timeout + +[HKEY_CURRENT_USER\Control Panel\Desktop] +"AutoEndTasks"="1" +"MenuShowDelay"="0" +"AutoEndTasks"="1" +"ScreenSaveTimeOut"=- +"SCRNSAVE.EXE"=- +"ForegroundLockTimeout"=dword:00000000 +"MouseWheelRouting"=dword:00000000 +"WaitToKillAppTimeout"="1" +"WaitToKillServiceTimeout"=dword:00000002 +"HungAppTimeout"="2000" +"LowLevelHooksTimeout"=dword:00000005 +"Win8DpiScaling"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\ModernSleep] +"CoalescingTimerInterval"=dword:00000000 + + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control] +"CoalescingTimerInterval"=dword:00000000 +"WaitToKillServiceTimeout"="1" +"DisableRemoteScmEndpoints"dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control] +"WaitToKillServiceTimeout"="1" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PnP] +"PollBootPartitionTimeout"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfNet\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfOS\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfDisk\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfProc\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BackgroundModel\BackgroundAudioPolicy] +"AllowHeadlessExecution"=dword:00000001 +"AllowMultipleBackgroundTasks"=dword:00000001 +"InactivityTimeoutMs"=dword:FFFFFFFF + +;032. Google Chrome + +[HEKY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome] +"TranslateEnabled"=dword:00000001 +"TaskManagerEndProcessEnabled"=dword:00000001 +"UserFeedbackAllowed"=dword:00000000 +"SpellCheckServiceEnabled"=dword:00000000 +"SpellcheckEnabled"=dword:00000000 +"MediaRouterCastAllowAllIPs"=dword:00000001 +"AllowDinosaurEasterEgg"=dword:00000001 +"DefaultGeolocationSetting"=dword:00000002 +"DefaultCookiesSetting"=dword:00000001 +"DefaultFileHandlingGuardSetting"=dword:00000003 +"DefaultFileSystemReadGuardSetting"=dword:00000003 +"DefaultFileSystemWriteGuardSetting"=dword:00000003 +"DefaultPopupsSetting"=dword:00000002 +"DefaultSensorsSetting"=dword:00000002 +"DefaultSerialGuardSetting"=dword:00000002 +"DefaultWebBluetoothGuardSetting"=dword:00000002 +"DefaultWebUsbGuardSetting"=dword:00000002 +"EnableMediaRouter"=dword:00000001 +"ShowCastIconInToolbar"=dword:00000001 +"CloudPrintProxyEnabled"=dword:00000000 +"PrintRasterizationMode"=dword:00000000 +"PrintingEnabled"=dword:00000001 +"DefaultPluginsSetting"=dword:00000001 +"SafeBrowsingProtectionLevel"=dword:00000000 +"SafeBrowsingExtendedReportingEnabled"=dword:00000000 +"HomepageIsNewTabPage"=dword:00000000 +"HomepageLocation"="google.com" +"NewTabPageLocation"="google.com" +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 +"ChromeCleanupEnabled"=dword:00000000 +"ChromeCleanupReportingEnabled"=dword:00000000 +"DefaultSearchProviderName"="sGoogle Encrypted" +"DefaultSearchProviderSearchURL"="https://www.google.com/#q={searchTerms}" +"DefaultSearchProviderEnabled"=dword:01000000 +"AllowCrossOriginAuthPrompt"=dword:00000000 +"AlwaysOpenPdfExternally"=dword:00000001 +"AmbientAuthenticationInPrivateModesEnabled"=dword:00000000 +"AudioCaptureAllowed"=dword:00000001 +"AudioSandboxEnabled"=dword:00000000 +"DnsOverHttpsMode"="off" +"ScreenCaptureAllowed"=dword:00000001 +"SitePerProcess"=dword:00000001 +"TLS13HardeningForLocalAnchorsEnabled"=dword:00000001 +"VideoCaptureAllowed"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome] +"TranslateEnabled"=dword:00000001 +"TaskManagerEndProcessEnabled"=dword:00000001 +"UserFeedbackAllowed"=dword:00000000 +"SpellCheckServiceEnabled"=dword:00000000 +"SpellcheckEnabled"=dword:00000000 +"MediaRouterCastAllowAllIPs"=dword:00000001 +"AllowDinosaurEasterEgg"=dword:00000001 +"DefaultGeolocationSetting"=dword:00000002 +"DefaultCookiesSetting"=dword:00000001 +"DefaultFileHandlingGuardSetting"=dword:00000003 +"DefaultFileSystemReadGuardSetting"=dword:00000003 +"DefaultFileSystemWriteGuardSetting"=dword:00000003 +"DefaultPopupsSetting"=dword:00000002 +"DefaultSensorsSetting"=dword:00000002 +"DefaultSerialGuardSetting"=dword:00000002 +"DefaultWebBluetoothGuardSetting"=dword:00000002 +"DefaultWebUsbGuardSetting"=dword:00000002 +"EnableMediaRouter"=dword:00000001 +"ShowCastIconInToolbar"=dword:00000001 +"CloudPrintProxyEnabled"=dword:00000000 +"PrintRasterizationMode"=dword:00000000 +"PrintingEnabled"=dword:00000001 +"DefaultPluginsSetting"=dword:00000001 +"SafeBrowsingProtectionLevel"=dword:00000000 +"SafeBrowsingExtendedReportingEnabled"=dword:00000000 +"HomepageIsNewTabPage"=dword:00000000 +"HomepageLocation"="google.com" +"NewTabPageLocation"="google.com" +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 +"ChromeCleanupEnabled"=dword:00000000 +"ChromeCleanupReportingEnabled"=dword:00000000 +"DefaultSearchProviderName"="sGoogle Encrypted" +"DefaultSearchProviderSearchURL"="https://www.google.com/#q={searchTerms}" +"DefaultSearchProviderEnabled"=dword:01000000 +"AllowCrossOriginAuthPrompt"=dword:00000000 +"AlwaysOpenPdfExternally"=dword:00000001 +"AmbientAuthenticationInPrivateModesEnabled"=dword:00000000 +"AudioCaptureAllowed"=dword:00000001 +"AudioSandboxEnabled"=dword:00000000 +"DnsOverHttpsMode"="off" +"ScreenCaptureAllowed"=dword:00000001 +"SitePerProcess"=dword:00000001 +"TLS13HardeningForLocalAnchorsEnabled"=dword:00000001 +"VideoCaptureAllowed"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\Extensions\djflhoibgkdhkhhcedjiklpkjnoahfmg\policy\OtherSettings] +"send_errors"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist] +"1"="cjpalhdlnbpafiamejdnhcphjbkeiagm" +"2"="fihnjjcciajhdojfnbdddfaoknhalnja" +"3"="bnomihfieiccainjcjblhegjgglakjdd" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\Recommended] +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\URLBlacklist] +"1"="javascript://*" + + + +;033. Virtualization +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard] +"DeployConfigCIPolicy"=dword:00000000 +"EnableVirtualizationBasedSecurity"=dword:00000000 +"HVCIMATRequired"=dword:00000000 +"RequirePlatformSecurityFeature"=dword:00000000 +"CachedDrtmAuthIndex"=dword:00000000 +"RequireMicrosoftSignedBootChain"=dword:00000000 +"RequirePlatformSecurityFeatures"=dword:00000000 +"Locked"=dword:00000000 + +;034. Input Tweaks + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\TabletTip\1.7] +"HideIPTIPTarget"=dword:00000001 +"HideIPTIPTouchTarget"=dword:00000001 +"IncludeRareChar"=dword:00000000 +"DisableEdgeTarget"=dword:00000001 +"DisableACIntegration"=dword:00000001 +"EnableAutocorrection"=dword:00000000 +"EnableSpellchecking"=dword:00000000 +"EnableTextPrediction"=dword:00000000 +"EnablePredictionSpaceInsertion"=dword:00000000 +"EnableDoubleTapSpace"=dword:00000000 +"EnableInkingWithTouch"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TabletTip\1.7] +"HideIPTIPTarget"=dword:00000001 +"HideIPTIPTouchTarget"=dword:00000001 +"IncludeRareChar"=dword:00000000 +"DisableEdgeTarget"=dword:00000001 +"DisableACIntegration"=dword:00000001 +"EnableAutocorrection"=dword:00000000 +"EnableSpellchecking"=dword:00000000 +"EnableTextPrediction"=dword:00000000 +"EnablePredictionSpaceInsertion"=dword:00000000 +"EnableDoubleTapSpace"=dword:00000000 +"EnableInkingWithTouch"=dword:00000000 + + + +[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings] +"EnableExpressiveInputShellHotkey"=dword:00000001 +"EnableExpressiveInputEmojiMultipleSelection"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\PenWorkspace] +"PenWorkspaceAppSuggestionsEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventTranscriptKey] +"EnableEventTranscript"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorSpeed] +"CursorSensitivity"=dword:00002710 +"CursorUpdateInterval"=dword:00000001 +"IRRemoteNavigationDelta"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorMagnetism] +"AttractionRectInsetInDIPS"=dword:00000005 +"DistanceThresholdInDIPS"=dword:00000028 +"MagnetismDelayInMilliseconds"=dword:00000002 +"MagnetismUpdateIntervalInMilliseconds"=dword:00000001 +"VelocityInDIPSPerSecond"=dword:00000168 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] +"EnableCursorSuppression"=dword:00000000 +"DelayedDesktopSwitchTimemout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\ChainEngine\Config] +"ChainRevAccumulativeUrlRetrievalTimeoutMilliseconds"=dword:0000000e +"ChainUrlRetrievalTimeoutMilliseconds"=dword:0000000e +"CrossCertDownloadIntervalHours"=dword:000000a8 +"Options"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings] +"AutoAccent"=dword:00000000 +"AutoApostrophe"=dword:00000000 +"AutoCap"=dword:00000000 +"AutoCapAllTokens"=dword:00000000 +"AutoCorrectFirstWord"=dword:00000000 +"AutoCorrection"=dword:00000000 +"AutoCorrectVisualDelay"=dword:00000000 +"AutoswitchAfterEmoji"=dword:00000000 +"ContactPenalty"=dword:00000000 +"DictationEnabled"=dword:00000001 +"DictationSupportedLanguages"="en-US;fr-FR;en-GB;de-DE;it-IT;zh-hans-CN;es-ES;en-IN;pt-BR;en-AU;en-CA;fr-CA;es-MX;ro-RO" +"DisablePersonalization"=dword:00000001 +"EmojiSuggestion"=dword:00000001 +"EmojiTranslation"=dword:00000001 +"EnableHwkbAutocorrection"=dword:00000000 +"EnableHwkbMode"=dword:00000000 +"EnableHwkbTextPrediction"=dword:00000000 +"HarvestContacts"=dword:00000000 +"HasTrailer"=dword:00000000 +"HTREnabled"=dword:00000000 +"HwkbAutocorrectionAlwaysOffList"=-" +"InsightsEnabled"=dword:00000000 +"IsVoiceTypingKeyEnabled"=dword:00000001 +"KeyboardMode"=dword:00000000 +"LMDataLoggerEnabled"=dword:00000000 +"MaxCorrections"=dword:00000000 +"MultilingualEnabled"=dword:00000000 +"NotActiveLanguagePenalty"=dword:00000000 +"NotPredictedLanguagePenalty"=dword:00000000 +"PeriodShortcut"=dword:00000000 +"Prediction"=dword:00000000 +"Private"=dword:00000000 +"ProofDataSources"=dword:00000000 +"SearchDataSources"=dword:00000000 +"Spellcheck"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore] +"HarvestContacts"=dword:00000000 +"InsightsEnabled"=dword:00000000 +"LMDataLoggerEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Speech] +"AllowSpeechModelUpdate"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Privacy] +"TailoredExperiencesWithDiagnosticDataEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MSDeploy\3] +"EnableTelemetry"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CPSS\UserPolicy\ImproveInkingAndTyping] +"DefaultValue"=dword:00000000 +"InheritsFromDevice"=dword:00000000 +"LegacyKeyName"="Enabled" +"LegacyKeyType"=dword:00000000 +"LegacyProjection"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Diagnostics\Performance] +"DisableDiagnosticTracing"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CPSS\UserPolicy\InkingAndTypingPersonalization] +"DefaultValue"=dword:00000000 +"InheritsFromDevice"=dword:00000000 +"LegacyKeyType"=dword:00000000 +"LegacyProjection"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings] +"EnableHwkbAutocorrection2"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TabletPC] +"PreventHandwritingDataSharing"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\HandwritingErrorReports] +"PreventHandwritingErrorReports"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PenTraining] +"DisablePenTraining"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace] +"AllowWindowsInkWorkspace"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorSpeed] +"CursorUpdateInterval"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouclass\Parameters] +"MouseDataQueueSize"=dword:00000032 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdclass\Parameters] +"KeyboardDataQueueSize"=dword:00000032 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS] +"Start"=dword:00000004 + +[HKEY_USERS\.DEFAULT\Control Panel\Mouse] +"MouseSpeed"="0" +"MouseThreshold1"="0" +"MouseThreshold2"="0" + + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseSpeed"="0" +"MouseThreshold1"="0" +"MouseThreshold2"="0" + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"Beep"="No" +"ExtendedSounds"="No" + +[HKEY_USERS\.DEFAULT\Control Panel\Sound] +"Beep"="no" +"ExtendedSounds"="no" + +[HKEY_CURRENT_USER\Control Panel\Sound] +"Beep"="no" +"ExtendedSounds"="no" + +[HKEY_CURRENT_USER\Control Panel\Keyboard] +"KeyboardDelay"="0" +"KeyboardSpeed"="10" +"InitialKeyboardIndicators"="2" + +[HKEY_USERS\.DEFAULT\Control Panel\Keyboard] +"InitialKeyboardIndicators"="2" +"KeyboardDelay"="0" +"KeyboardSpeed"="10" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters] +"DefaultReceiveWindow"=dword:00004000 +"DefaultSendWindow"=dword:00004000 +"FastCopyReceiveThreshold"=dword:00004000 +"FastSendDatagramThreshold"=dword:00004000 +"DynamicSendBufferDisable"=dword:00000000 +"IgnorePushBitOnReceives"=dword:00000001 +"NonBlockingSendSpecialBuffering"=dword:00000001 +"DisableRawSecurity"=dword:00000001 +"DoNotHoldNicBuffers"=dword:00000001 +"DisableAddressSharing"=dword:00000001 + +;035. Office Tweaks + + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Lync] +"disableautomaticsendtracking"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common] +"QMEnable"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\Feedback] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\15.0\osm] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry] +"MotherboardUUID"="-" +"DisableTelemetry"=dword:00000001 +"VerboseLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common] +"sentcostumerdata"=dword:00000000 +"qmenable"=dword:00000000 +"updaterealiabilitydata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Feedback] +"enabled"=dword:00000000 +"includescreenshot"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Office\17.0\osm] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\OSM] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\Calendar] +"EnableCalendarLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Security] +"InitEncrypt"=dword:00000002 +"InitSign"=dword:00000002 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Graphics] +"DisableAnimations"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common] +"sendcustomerdata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Feedback] +"enabled"=dword:00000000 +"includescreenshot"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common] +"qmenable"=dword:00000000 +"updatereliabilitydata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\General] +"shownfirstrunoptin"=dword:00000000 +"skydrivesigninoption"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ptwatson] +"ptwoptin"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Firstrun] +"disablemovie"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\OSM] +"Enablelogging"=dword:00000000 +"EnableUpload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Options\Calendar] +"EnableCalendarLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Options\Mail] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options] +"EnableLogging"=dword:00000000 +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options\WordMail] +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options] +"EnableLogging"=dword:00000000 +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\WordMail] +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common] +"sendcustomerdata"=dword:00000000 +"SendCustomerDataOptInReason"=dword:00000000 +"SendCustomerDataOptIn"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\Mail] +"BlockExtContent"=dword:00000000 +"UnblockSpecificSenders"=dword:00000000 +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common] +"QMEnable"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\International\User Profile] +"HttpAcceptLanguageOptOut"=dword:00000001 + + +;036. Google Update + +:: Google Update + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Update] +"Install{8A69D345-D564-463C-AFF1-A69D9E530F96}"=dword:00000005 +"TargetChannel{8A69D345-D564-463C-AFF1-A69D9E530F96}"="stable" +"Update{8A69D345-D564-463C-AFF1-A69D9E530F96}"=dword:00000003 +"Install{4CCED17F-7852-4AFC-9E9E-C89D8795BDD2}"=dword:00000000 +"AutoUpdateCheckPeriodMinutes"=dword:0000a8c0 +"DownloadPreference"="cacheable" +"UpdatesSuppressedStartHour"=dword:00000017 +"UpdatesSuppressedStartMin"=dword:00000030 +"UpdatesSuppressedDurationMin"=dword:00000037 + + + +;037. Windows Update + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] +"BranchReadinessLevel"=dword:00000010 +"DeferFeatureUpdates"=dword:00000001 +"DeferFeatureUpdatesPeriodInDays"=dword:00000000 +"PauseFeatureUpdatesStartTime"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] +"DetectionFrequency"=dword:00000014 +"DetectionFrequencyEnabled"=dword:00000001 +"EnableFeaturedSoftware"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\PolicyState] +"DeferQualityUpdates"=dword:00000001 +"DeferFeatureUpdates"=dword:00000001 +"BranchReadinessLevel"="CB" +"IsDeferralIsActive"=dword:00000001 +"IsWUfBConfigured"=dword:00000000 +"IsWUfBDualScanActive"=dword:00000000 +"FeatureUpdatesDeferralInDays"=dword:00000000 +"ExcludeWUDrivers"=dword:00000001 +"PolicySources"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE] +"DisableExternalDMAUnderLock"=dword:00000001 + +;038. XBOX + +[-HKEY_CURRENT_USER\System\GameConfigStore\Children] + +[-HKEY_CURRENT_USER\System\GameConfigStore\Parents] + +[HKEY_USERS\.DEFAULT\Software\Microsoft\GameBar] +"AutoGameModeEnabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\GameBar] +"AutoGameModeEnabled"=dword:00000000 + + +[HKEY_CURRENT_USER\Software\Microsoft\Games] +"EnableXBGM"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\GameDVR] +"KGLRevision"=- +"KGLToGCSUpdatedRevision"=- +"LastGameActivity"=- +"AppCaptureEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\GameDVR] +"AllowgameDVR"=dword:00000000 + +[HKEY_CURRENT_USER\System\GameConfigStore] +"GameDVR_FSEBehavior"=dword:00000002 + +[HKEY_CURRENT_USER\Software\Microsoft\GameBar] +"AllowAutoGameMode"=dword:00000000 +"AutoGameModeEnabled"=dword:00000000 +"ShowStartupPanel"=dword:00000000 +"ShowGameModeNotifications"=dword:00000000 + +[HKEY_CURRENT_USER\System\GameConfigStore] +"GameDVR_Enabled"=dword:00000000 +"GameDVR_FSEBehaviorMode"=dword:00000002 +"Win32_AutoGameModeDefaultProfile"=- +"Win32_GameModeRelatedProcesses"=- +"GameDVR_HonorUserFSEBehaviorMode"=dword:00000001 +"GameDVR_DXGIHonorFSEWindowsCompatible"=dword:00000001 +"GameDVR_EFSEFeatureFlags"=dword:00000000 +"GameDVR_FSEBehavior"=dword:00000002 + +[-HKEY_CURRENT_USER\System\GameConfigStore\Children] + +[-HKEY_CURRENT_USER\System\GameConfigStore\Parents] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TWinUI\FilePicker\LastVisitedPidlMRU] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Diagnostics] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Census] + +[-HKEY_CURRENT_USER\Briefcase\ShellNew] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameBar] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameChatOverlay] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameChatOverlayMessageSource] +"ActivationType"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{FC96B68C-09EF-4251-A598-19E4BE1B76A9}] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\ApplicationManagement\AllowGameDVR] +"value"=dword:00000000 + +;039. Power Tweaks + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\2a737441-1930-4402-8d77-b2bebba308a3\d4e98f31-5ffe-4ce1-be31-1b38b384c009] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\d639518a-e56d-4345-8af2-b9f32fb26109] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\dab60367-53fe-4fbc-825e-521d069d2456] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\0b2d69d7-a2a1-449c-9680-f91c70521c60] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\12a0ab44-fe28-4fa9-b3bd-4b64f44960a6] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\6b013a00-f775-4d61-9036-a62f7e7a6a5b] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"AcPolicy"=hex:01,00,00,00,00,00,00,00,03,00,00,00,10,00,00,00,02,00,00,00,03,\ + 00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,1a,88,\ + 41,7e,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,32,00,00,00,02,00,00,\ + 00,02,00,00,00,02,00,00,00,01,00,00,00,96,88,41,7e,00,00,00,00,03,00,00,00,\ + 01,00,00,00,03,00,00,00,03,00,00,00,04,00,00,c0,01,00,00,00,05,00,00,00,01,\ + 00,00,00,0a,00,00,00,00,00,00,00,03,00,00,00,01,00,01,00,01,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,00,00,00,\ + 00,d0,09,00,08,00,00,00,3c,13,00,00,30,31,09,00,00,00,00,00,01,64,64,00,02,\ + 00,00,00,04,00,00,c0,00,00,00,00 +"DcPolicy"=hex:01,00,00,00,00,00,00,00,03,00,00,00,10,00,00,00,02,00,00,00,03,\ + 00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,0d,00,\ + 00,00,02,00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,03,09,00,02,00,00,\ + 00,02,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,84,03,00,00,03,00,00,00,\ + 01,00,00,00,03,00,00,00,03,00,00,00,04,00,00,c0,01,00,00,00,05,00,00,00,01,\ + 00,00,00,0a,00,00,00,00,00,00,00,03,00,00,00,01,00,01,00,01,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,2c,01,00,00,\ + 01,88,41,7e,99,01,00,00,d0,7f,54,00,e4,7f,54,00,58,02,00,00,01,64,64,00,02,\ + 00,00,00,04,00,00,c0,00,00,00,00 + +[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\0] +"Policies"=hex:01,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,32,00,03,02,00,00,00,02,00,\ + 00,00,00,00,3d,77,2e,f2,07,00,00,00,00,00,2c,01,00,00,00,00,00,00,58,02,00,\ + 00,01,01,64,64,64,64,91,7c + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling] +"PowerThrottlingOff"=dword:00000001 + + +;040. Control Panel Items (only Windows 10) + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Account Manager" +"InfoTip"="Opens Account Manager" +"System.ControlPanel.Category"="9" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\DefaultIcon] +@="%SystemRoot%\\System32\\netplwiz.exe" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\Shell\Open\command] +@="netplwiz.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Add Advanced User Accounts to Control Panel" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@=" Account Manager" +"InfoTip"="Opens Account Manager" +"System.ControlPanel.Category"="9" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\DefaultIcon] +@="%SystemRoot%\\System32\\netplwiz.exe" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\Shell\Open\command] +@="netplwiz.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Add Advanced User Accounts to Control Panel" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}] +@="WinColor" +"InfoTip"="Change the color of your taskbar, window borders, and Start menu" +"System.ApplicationName"="Microsoft.Personalization" +"System.ControlPanel.Category"=dword:00000001 +"System.Software.TasksFileUrl"="Internal" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}\DefaultIcon] +@="%SystemRoot%\\System32\\imageres.dll,-197" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}\Shell\Open\command] +@="explorer shell:::{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921} -Microsoft.Personalization\\pageColorization" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{106ee807-9e5d-451b-a9c5-74908630cefb}] +@="Color and Appearance" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}] +@=" Disk Manager" +"InfoTip"="Create and format hard disk partitions" +"System.ControlPanel.Category"="2" +"System.ControlPanel.EnableInSafeMode"="3" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}\DefaultIcon] +@="%WinDir%\\System32\\dmdskres.dll,-344" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}\Shell\Open\command] + @="mmc.exe diskmgmt.msc" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{403ac161-c813-4819-b37f-3aacf0e12e0e}] +@="Disk Management" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}] +@="GOD Module" +"InfoTip"="All Control Panel items in a single view" +"System.ControlPanel.Category"="5" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}\DefaultIcon] +@="%SystemRoot%\\System32\\imageres.dll,-27" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}\Shell\Open\Command] +@="explorer.exe shell:::{ED7BA470-8E54-465E-825C-99712043E01C}" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{E91B00A7-97F2-4934-B06A-101C194D2333}] +@="All Tasks" + + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}] +@="GroupPolicy" +"InfoTip"="Starts the Local Group Policy Editor" +"System.ControlPanel.Category"="5" + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}\DefaultIcon] +@="%SYSTEMROOT%\\System32\\gpedit.dll" + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}\Shell\Open\Command] +@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\ + 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,6d,00,\ + 63,00,2e,00,65,00,78,00,65,00,20,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,\ + 00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,\ + 33,00,32,00,5c,00,67,00,70,00,65,00,64,00,69,00,74,00,2e,00,6d,00,73,00,63,\ + 00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{1695E87D-8BC9-4803-A701-D812E7C55223}] +@="Local Group Policy Editor" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}] +@="System Configuration" +"InfoTip"="Perform advanced troubleshooting and system configuration" +"System.ControlPanel.Category"="5" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}\DefaultIcon] +@="msconfig.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}\Shell\Open\Command] +@="msconfig.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}] +@="System Configuration" + +;041. Windows Error Reporting + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"DoReport"=dword:00000000 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 +"OobeCompleted"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"DoReport"=dword:00000000 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 +"OobeCompleted"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\PCHealth\ErrorReporting] +"ShowUI"=dword:00000000 +"DoReport"=dword:00000000 + + + +;042. AppCompat + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat] +"VDMDisallowed"=dword:00000001 +"DisableEngine"=dword:00000001 +"AITEnable"=dword:00000000 +"DisableInventory"=dword:00000001 +"DisablePCA"=dword:00000001 +"DisableUAR"=dword:00000001 +"SbEnable"=dword:00000000 +"AllowTelemetry"=dword:00000000 + +;043. Codecs + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows Media Foundation] +"EnableFrameServerMode"=dword:00000000 + +;044. More Optimization + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppHost] +"EnableWebContentEvaluation"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + + +[HKEY_CURRENT_USER\Control Panel\PowerCfg] +"CurrentPowerPolicy"="4" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters] +"IRPStackSize"=dword:00000032 +"AutoShareWks"=dword:00000000 +"DisableCompression"=dword:00000001 +"EnableAuthenticateUserSharing"=dword:00000000 +"ServiceDllUnloadOnStop"=dword:00000001 +"autodisconnect"=dword:0000000f +"enablesecuritysignature"=dword:00000000 +"requiresecuritysignature"=dword:00000000 +"restrictnullsessaccess"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main] +"AllowPrelaunch"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\0] +"0200"=hex:00,00,00,00,01,00,00,07,00,00,00,00,00,00,00,00,1e,00,00,00,00,00,\ + 00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,ff,\ + 00,ff,00,ff,ff,00,00,00,00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,\ + ff,ff,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 +"1700"=hex:00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,ff,00,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + ff,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB] +"AllowIdleIrpInD3"=dword:00000000 +"EnhancedPowerManagementEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBXHCI\Parameters\Wdf] +"NoExtraBufferRoom"=dword:00000001 + + +;045. PSCHED + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched] +"TimerResolution"=dword:00000001 +"MaxOutstandingSends"=dword:00000000 +"NonBestEffortLimit"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\DiffservByteMappingConforming] +"ServiceTypeGuaranteed"=dword:0000002e +"ServiceTypeNetworkControl"=dword:00000038 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\DiffservByteMappingNonConforming] +"ServiceTypeGuaranteed"=dword:0000002e +"ServiceTypeNetworkControl"=dword:00000038 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\UserPriorityMapping] +"ServiceTypeGuaranteed"=dword:00000005 +"ServiceTypeNetworkControl"=dword:00000007 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"SleepStudyDisabled"=dword:00000001 + + + +;046. Notification Setting + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpnUserService] +"Start"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging] +"EnableModuleLogging"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging] +"EnableScriptBlockLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings] +"NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK"=dword:00000000 +"NOC_GLOBAL_SETTING_ALLOW_NOTIFICATION_SOUND"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.AutoPlay] +"Enabled"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.SecurityAndMaintenance] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.StartupApp] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications] +"NoToastApplicationNotification"=dword:00000000 +"NoToastApplicationNotificationOnLockScreen"=dword:00000001 + +;047. Search Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Search] +"CortanaEnabled"=dword:00000000 +"AnyAboveLockAppsActive"=dword:00000000 +"BingSearchEnabled"=dword:00000000 +"CortanaCapabilities"=dword:00000000 +"CortanaCapabilityFlags"=dword:00000000 +"CortanaConsent"=dword:00000000 +"CortanaInAmbientMode"=dword:00000000 +"DeviceHistoryEnabled"=dword:00000000 +"HasAboveLockTips"=dword:00000000 +"IsAssignedAccess"=dword:00000000 +"IsMicrophoneAvailable"=dword:00000000 +"IsWindowsHelloActive"=dword:00000000 +"Start_TrackDocs"=dword:00000000 +"Start_TrackProgs"=dword:00000000 +"CanCortanaBeEnabled"=dword:00000000 +"DisableSearchBoxSuggestions"=dword:00000001 +"SearchboxTaskbarMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search] +"PreventIndexOnBattery"=dword:00000001 +"PreventIndex"=dword:00000001 +"DisableRemovableDriveIndexing"=dword:00000001 +"DisableWebSearch"=dword:00000001 +"ConnectedSearchUseWeb"=dword:00000000 +"ConnectedSearchUseWebOverMeteredConnections"=dword:00000000 +"AllowCortana"=dword:00000000 +"BingSearchEnabled"=dword:00000000 +"AllowCloudSearch"=dword:00000000 +"BackgroundAppGlobalToggle"=dword:00000000 + +;048. Cloud Content.. + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CloudContent] +"ConfigureWindowsSpotlight"=dword:00000002 +"IncludeEnterpriseSpotlight"=dword:00000000 +"DisableWindowsSpotlightFeatures"=dword:00000001 +"DisableWindowsSpotlightWindowsWelcomeExperience"=dword:00000001 +"DisableWindowsSpotlightOnActionCenter"=dword:00000001 +"DisableWindowsSpotlightOnSettings"=dword:00000001 +"DisableThirdPartySuggestions"=dword:00000001 +"DisableTailoredExperiencesWithDiagnosticData"=dword:00000001 +"DisableWindowsConsumerFeatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications] +"NoCloudApplicationNotification"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History] +"DaysToKeep"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] +"LowRiskFileTypes"=".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.msu;.wav;" + +;049. Crash on Ctrl+Scroll + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt\Parameters] +"CrashOnCtrlScroll"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Parameters] +"CrashOnCtrlScroll"=dword:00000001 + +;050. Touch Latency + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TouchPrediction] +"Latency"=dword:00000001 +"SampleTime"=dword:00000001 +"UseHWTimeStamp"=dword:00000001 + + +;051. Windows Explorer + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Feeds] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DataSharing] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing] + + +[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"GreyMSIAds"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System] +"AllowCrossDeviceClipboard"=dword:00000000 +"DisableAcrylicBackgroundOnLogon"=dword:00000001 +"AllowClipboardHistory"=dword:00000000 +"EnableSmartScreen"=dword:00000000 +"EnableFontProviders"=dword:00000001 +"DisableHHDEP"=dword:00000001 +"DisableForceUnload"=dword:00000001 +"SlowLinkDetectEnabled"=dword:00000000 +"DeleteRoamingCache"=dword:00000001 +"CompatibleRUPSecurity"=dword:00000001 +"AllowBlockingAppsAtShutdown"=dword:00000001 +"AllowClipboardHistory"=dword:00000000 +"EnableActivityFeed"=dword:00000000 +"PublishUserActivities"=dword:00000000 +"UploadUserActivities"=dword:00000000 +"DisableLockScreenAppNotifications"=dword:00000001 +"RSoPLogging"=dword:00000000 +"DisableForceUnload"=dword:00000001 +"EnableSmartScreen"=dword:00000000 +"EnableMmx"=dword:00000000 +"EnableCdp"=dword:00000000 +"AllowBlockingAppsAtShutdown"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes] +"ThemeChangesMousePointers"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] +"NoAutoUpdate"=dword:00000001 +"EnableFeaturedSoftware"=dword:00000000 +"IncludeRecommendedUpdates"=dword:00000000 +"UseUpdateClassPolicySource"=dword:00000001 +"NoAUShutdownOption"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\Local] +"WCMPresent"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\GroupPolicy] +"fDisablePowerManagement"=dword:00000001 +"fSoftDisconnectConnections"=dword:00000000 +"fMinimizeConnections"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseHoverTime"="1" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FindMyDevice] +"AllowFindMyDevice"=dword:00000000 +"LocationSyncEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NvCache] +"OptimizeBootAndResume"=dword:00000000 +"EnablePowerModeState"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{0DA965DC-8FCF-4c0b-8EFE-8DD5E7BC959A}\{7E01ADEF-81E6-4e1b-8075-56F373584694}\{F6CC25DF-6E8F-4cf8-A242-B1343F565884}\{BDB3AF7A-F67E-4d1e-945D-E2790352BE0A}] +@="{db57eb61-1aa2-4906-9396-23e8b8024c32}" +"Operator"=dword:00000002 +"Type"=dword:0000103d +"Value"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{0DA965DC-8FCF-4c0b-8EFE-8DD5E7BC959A}\{7E01ADEF-81E6-4e1b-8075-56F373584694}\{F6CC25DF-6E8F-4cf8-A242-B1343F565884}\{CD9230EE-218E-44b9-8AE5-EE7AA5DAD08F}] +@="{db57eb61-1aa2-4906-9396-23e8b8024c32}" +"Operator"=dword:00000002 +"Type"=dword:0000100a +"Value"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\EdgeUI] +"DisableMFUTracking"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule] +"DisableRpcOverTcp"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client] +"ShowShutdownDialog"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WlanSvc\AnqpCache] +"OsuRegistrationStatus"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Control Panel\Desktop] +"ScreenSaveActive"="0" +"EnablePerProcessSystemDPI"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EnhancedStorageDevices] +"TCGSecurityActivationDisabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PreviousVersions] +"DisableLocalPage"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] +"SystemRestorePointCreationFrequency"=dword:00000000 + +[HKEY_CLASSES_ROOT\SystemFileAssociations\image] +"Treatment"=dword:00000000 + +[HKEY_CLASSES_ROOT\SystemFileAssociations\video] +"Treatment"=dword:00000000 + +;052. Windows Store Apps + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore] +"AutoDownload"=dword:00000002 + + +;053. IE + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Security] +"DisableSecuritySettingsCheck"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security] +"DisableSecuritySettingsCheck"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\SQM] +"DisableCustomerImprovementProgram"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions] +"NoHelpItemSendFeedback"=dword:00000001 +"NoHelpItemTipOfTheDay"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"HideNewEdgeButton"=dword:00000001 + + +;054. Realtek Bluetooth Latency + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\BTHLEDevice\{00001812-0000-1000-8000-00805f9b34fb}_Dev_VID&02046d_PID&b34f_REV&0021_ff773a4381ed\9&1d91d97b&0&0021\Device Parameters] +"RetainWWIrpWhenDeviceAbsent"=dword:00000001 +"HighDutyCycleScanWindow"=dword:00000012 +"HighDutyCycleScanInterval"=dword:00000024 +"LowDutyCycleScanWindow"=dword:00000012 +"LowDutyCycleScanInterval"=dword:00000400 +"LinkSupervisionTimeout"=dword:0000000c +"ConnectionLatency"=dword:00000001 +"ConnectionIntervalMin"=dword:00000001 +"ConnectionIntervalMax"=dword:00000001 + +;055. UAC + Virtualization 2 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] +"ConsentPromptBehaviorAdmin"=dword:00000000 +"ConsentPromptBehaviorUser"=dword:00000000 +"DSCAutomationHostEnabled"=dword:00000000 +"EnableCursorSuppression"=dword:00000000 +"EnableInstallerDetection"=dword:00000000 +"EnableLUA"=dword:00000000 +"EnableSecureUIAPaths"=dword:00000000 +"EnableUIADesktopToggle"=dword:00000000 +"EnableUwpStartupTasks"=dword:00000000 +"EnableVirtualization"=dword:00000000 +"PromptOnSecureDesktop"=dword:00000000 +"scforceoption"=dword:00000000 +"shutdownwithoutlogon"=dword:00000001 +"undockwithoutlogon"=dword:00000001 +"NoInternetOpenWith"=dword:00000001 +"EnableFirstLogonAnimation"=dword:00000000 + + +;056.Notepad Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Notepad] +"StatusBar"=dword:00000001 +"fWrap"=dword:00000001 +"fSavePageSettings"=dword:00000001 +"fSaveWindowPositions"=dword:00000001 +"fWindowsOnlyEOL"=dword:00000000 +"fPasteOriginalEOL"=dword:00000001 + +[HKEY_CLASSES_ROOT\*\shell\Open with Notepad] +"Icon"="notepad.exe,-2" + +[HKEY_CLASSES_ROOT\*\shell\Open with Notepad\command] +@="notepad.exe %1" + + +;057. MRT Tool + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MRT] +"DontOfferThroughWUAU"=dword:00000001 +"DontReportInfectionInformation"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 + + +;058. USB Flags + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\usbflags] +"fid_D1Latency"=dword:00000001 +"fid_D2Latency"=dword:00000001 +"fid_D3Latency"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"UseOLEDTaskbarTransparency"=- +"EncryptionContextMenu"=dword:00000000 +"HideFileExt"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer] +"HidePeopleBar"=dword:00000001 +"NoUseStoreOpenWith"=dword:00000001 +"DisableSearchBoxSuggestions"=dword:00000001 +"NoPinningStoreToTaskbar"=dword:00000000 +"NoWindowMinimizingShortcuts"=dword:00000001 +"NoDataExecutionPrevention"=dword:00000001 +"NoHeapTerminationOnCorruption"=dword:00000001 +"NoNewAppAlert"=dword:00000001 +"DisableContextMenusInStart"=dword:00000000 +"HideRecentlyAddedApps"=dword:00000001 +"ShowOrHideMostUsedApps"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\IPMI] +"BusyWaitPeriod"=dword:000000001 +"BusyWaitTimeoutPeriod"=dword:00000001 +"CommandWaitTimeoutPeriod"=dword:00000001 +"IpmbWaitTimeoutPeriod"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF] +"LogEnable"=dword:00000000 +"LogLevel"=dword:00000000 + +;059. Windows Installer Service in Safe Mode + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer] +@="Service" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] +@="Service" + +[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] +"SyncMode5"=dword:00000003 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] +"SyncMode5"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"DEPOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\QoS] +"Tcp Autotuning Level"="Experimental" +"Application DSCP Marking Request"="Allowed" + +;060.Icon Set + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Icons] +"29"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 +"77"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 +"179"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 + +;061. iSCSI Optimization + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\iSCSI] +"ChangeIQNName"=dword:00000001 +"RestrictAdditionalLogins"=dword:00000001 +"ChangeCHAPSecret"=dword:00000001 +"RequireIPSec"=dword:00000001 +"RequireMutualCHAP"=dword:00000001 +"RequireOneWayCHAP"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer] +"PreventCodecDownload"=dword:00000001 + +;062.File History + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\FileHistory] +"Disabled"=dword:00000001 + + +;063. End + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\MobilityCenter] +"NoMobilityCenter"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes] +"ThemeChangesMousePointers"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters\Config\VpnCostedNetworkSettings] +"NoRoamingNetwork"=dword:00000001 +"NoCostedNetwork"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Maintenance] +"MaintenanceDisabled"=dword:00000001 +"WakeUp"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\StorageHealth] +"AllowDiskHealthModelUpdates"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\StorageSense] +"AllowStorageSenseGlobal"=dword:00000000 +"AllowStorageSenseTemporaryFilesCleanup"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Maps] +"AutoDownloadAndUpdateMapData"=dword:00000000 +"AllowUntriggeredNetworkTrafficOnSettingsPage"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Messaging] +"AllowMessageSync"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetCache] +"SyncAtLogon"=dword:00000000 +"SyncAtLogoff"=dword:00000000 +"SyncEnabledForCostedNetwork"=dword:00000000 +"EconomicalAdminPinning"=dword:00000000 +"NoReminders"=dword:00000001 +"NoMakeAvailableOffline"=dword:00000001 +"NoCacheViewer"=dword:00000001 +"NoConfigCache"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Network Connections] +"NC_PersonalFirewallConfig"=dword:00000000 +"NC_DoNotShowLocalOnlyIcon"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NDIS\Parameters] +"TrackNblOwner"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer] +"DisableLoggingFromPackage"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate] +"DoNotUpdateToEdgeWithChromium"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\OOBE] +"DisablePrivacyExperience"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HomeGroup] +"DisableHomeGroup"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HotspotAuthentication] +"Enabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole] +"DefaultLaunchPermission"=- +"EnableDCOM"="N" +"LegacyImpersonationLevel"=dword:00000002 +"MachineAccessRestriction"=- +"MachineLaunchRestriction"=- + +;064. WCN Registrator + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WCN\UI] +"DisableWcnUi"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars] +"EnableRegistrars"=dword:00000000 +"DisableUPnPRegistrar"=dword:00000000 +"DisableInBand802DOT11Registrar"=dword:00000000 +"DisableFlashConfigRegistrar"=dword:00000000 +"DisableWPDRegistrar"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services] +"fAllowToGetHelp"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service] +"AllowUnencryptedTraffic"=dword:00000000 + +;065. Sandbox Tweaks + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Sandbox] +"AllowVideoInput"=dword:00000001 +"AllowVGPU"=dword:00000000 +"AllowPrinterRedirection"=dword:00000000 +"AllowNetworking"=dword:00000000 +"AllowClipboardRedirection"=dword:00000001 +"AllowAudioInput"=dword:00000001 + + +;066. Event log + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest] +"UseLogonCredential"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters] +"SupportedEncryptionTypes"=dword:7ffffff8 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EdgeUI] +"DisableMFUTracking"=dword:00000001 +"DisableHelpSticker"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EventLog\ProtectedEventLogging] +"EnableProtectedEventLogging"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EventLog\Setup] +"Enabled"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\fssProv] +"EncryptProtocol"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WDI\{affc81e2-612a-4f70-6fb2-916ff5c7e3f8}] +"ScenarioExecutionEnabled"=dword:00000000 +"EnabledScenarioExecutionLevel"=dword:00000000 + +;067. Your Phone API + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client] +"PreventAutoRun"=dword:00000001 +"CEIP"=dword:00000002 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\ms-phone-api] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\tbauth] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\windows.tbauth] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\windows.yourphone.api] + + +;068 ! (reveu 063, 065 si 067) + + +[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download] +"CheckExeSignatures"="no" +"RunInvalidSignatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MdmCommon\SettingValues] +"LocationSyncEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation] +"AllowOfflineFilesforCAShares"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\Maps] +"AutoUpdateEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge] +"TrackingPrevention"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScheduledDiagnostics] +"EnabledExecution"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub\hubg] +"DisableOnSoftRemove"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers] +"authenticodeenabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\SettingSync] +"DisableSettingSync"=dword:00000002 +"DisableSettingSyncUserOverride"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications] +"GlobalUserDisabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppPrivacy] +"LetAppsRunInBackground"=dword:00000002 + +;070. Delivery Optimization Disable + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\DeliveryOptimization] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"DEPOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NVDisplay.ContainerLocalSystem\LocalSystem\NvcDispCorePlugin] +"DisableLoad"=dword:00000001 +"LogFile"="-" +"LogLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Reliability Analysis\WMI] +"WMIEnable"=dword:00000000 + +;070. Remove ControlPanel and Settings Applets + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"NoRemoteRecursiveEvents"=dword:00000001 +"DisableThumbnails"=- +"MemCheckBoxInRunDlg"=dword:00000001 +"NoInstrumentation"=dword:00000001 +"ConfirmFileDelete"=dword:00000000 +"AllowOnlineTips"=dword:00000000 +"NoRemoteRecursiveEvents"=dword:00000001 +"StartMenuFavorites"=dword:00000000 +"Start_ShowHelp"=dword:00000000 +"Start_ShowMyComputer"=dword:00000001 +"Start_ShowRun"=dword:00000001 +"SettingsPageVisibility"="hide:quiethours;tabletmode;multitasking;project;crossdevice;clipboard;remotedesktop;typing;pen;autoplay;;mobile-devices;network-dialup;network-directaccess;maps;appsforwebsites;videoplayback;startupapps;sync;speech;gaming-gamebar;gaming-gamedvr;gaming-broadcasting;gaming-gamemode;;search-permissions;cortana-windowssearch;search-moredetails;privacy;privacy-speech;privacy-speechtyping;privacy-feedback;privacy-activityhistory;privacy-location;privacy-voiceactivation;privacy-notifications;privacy-accountinfo;privacy-contacts;privacy-calendar;privacy-callhistory;privacy-email;privacy-eyetracker;privacy-tasks;privacy-messaging;privacy-radios;privacy-customdevices;privacy-backgroundapps;privacy-appdiagnostics;privacy-automaticfiledownloads;privacy-documents;privacy-pictures;privacy-documents;privacy-broadfilesystemaccess;delivery-optimization;windowsdefender;backup;troubleshoot;findmydevice;;holographic-audio;privacy-holographic-environment;holographic-headset;holographic-management;" + + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl] +"1"="Microsoft.ProgramsAndFeatures" +"2"="Microsoft.DefaultPrograms" +"3"="Microsoft.StorageSpaces" +"4"="Microsoft.FileHistory" +"5"="Microsoft.ActionCenter" +"6"="Microsoft.DateAndTime" +"7"="Microsoft.SpeechRecognition" +"8"="Microsoft.EaseOfAccessCenter" +"9"="Microsoft.DevicesAndPrinters" +"10"="Microsoft.PenAndTouch" +"11"="Microsoft.AutoPlay" +"12"="Microsoft.MobilityCenter" +"13"="Microsoft.Taskbar" +"14"="Microsoft.TextToSpeech" +"15"="Microsoft.Troubleshooting" +"16"="Microsoft.SyncCenter" +"17"="Microsoft.Keyboard" +"18"="Microsoft.Mouse" +"19"="Microsoft.Personalization" +"20"="Microsoft.TabletPCSettings" +"21"="Microsoft.System" +"22"="Microsoft.AdministrativeTools" +"23"="Microsoft.CredentialManager" +"24"="Microsoft.PhoneAndModem" +"25"="Microsoft.RemoteAppAndDesktopConnections" + +;071. Adobe Acrobat Reader + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown] +"bAcroSuppressUpsell"=dword:00000001 +"bDisablePDFHandlerSwitching"=dword:00000001 +"bDisableTrustedFolders"=dword:00000001 +"bDisableTrustedSites"=dword:00000001 +"bEnableFlash"=dword:00000000 +"bEnhancedSecurityInBrowser"=dword:00000001 +"bEnhancedSecurityStandalone"=dword:00000001 +"bProtectedMode"=dword:00000001 +"iFileAttachmentPerms"=dword:00000001 +"iProtectedView"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cCloud] +"bAdobeSendPluginToggle"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\DC\Installer] +"DisableMaintenance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms] +"iURLPerms"=dword:00000003 +"iUnknownURLPerms"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices] +"bToggleAdobeDocumentServices"=dword:00000001 +"bToggleAdobeSign"=dword:00000001 +"bTogglePrefsSync"=dword:00000001 +"bToggleWebConnectors"=dword:00000001 +"bUpdater"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Adobe\Acrobat Reader\DC\Installer] +"DisableMaintenance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cSharePoint] +"bDisableSharePointFeatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWebmailProfiles] +"bDisableWebmail"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWelcomeScreen] +"bShowWelcomeScreen"=dword:00000000 + +;072. intel CPU Tweak + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm\Parameters] +"AcpiFirmwareWatchDog"=dword:00000000 +"AmliWatchdogAction"=dword:00000000 +"AmliWatchdogTimeout"=dword:00000001 +"WatchdogTimeout"=dword:00000001 + + + +;073. WinLogon + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] +"EnableFirstLogonAnimation"=dword:00000000 +"AutoRestartShell"=dword:00000001 + + +;074. Firewall Rules + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] +"{1A6BFAD8-BA8C-4474-8E25-C9DB3D46523F}"="v2.31|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow TCP IN|EmbedCtxt=Fingerprint Unlock Module|" +"{A2D1CA01-D51F-4E64-9229-3D56A29D0D5C}"="v2.31|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow TCP OUT|EmbedCtxt=Fingerprint Unlock Module|" +"{64C4F529-DB31-425A-BA71-FBA3C881ADDC}"="v2.31|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow UDP IN|EmbedCtxt=Fingerprint Unlock Module|" +"{AA2CBA97-F20A-4A2B-98D0-6D1F84A6984D}"="v2.31|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow UDP OUT|EmbedCtxt=Fingerprint Unlock Module|" +"{ADEDD497-D9EB-4573-B73F-86C68AA3F377}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{6139A3AA-99A5-491F-843C-E343C83226F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{8DFBCF37-3975-4054-939D-280B80AC6E86}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{E4D61D8A-D28E-43BC-BA9F-B5E0138266AB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{E7763690-64E1-4AE6-92F6-2A0D87D372A0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{6AEC363C-0E0E-4041-ADC8-0B47ED7EF74E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{1ABEA816-DF00-4EC6-897D-D6BCB81779F8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{FBBDCD38-3A64-4C43-B4A6-C1F40A2AC511}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{D3BA6B7E-E614-49A5-AFE9-454EAD516B02}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{1FB7E5CC-1994-459D-BB57-C8CEA982B76C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{26FEAEAE-8808-4FCC-B50B-CA02A1F047C7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{25344817-661E-4748-932A-118CA38A025D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{7E32EF31-E1D6-4E7E-8D58-5035C9C491CB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{6DA9BD19-8492-4D26-A7AF-4B860CA20C61}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{3651797E-8F96-4813-AD2E-460ADF002D00}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D0C84C00-07C1-4D6D-9B55-CA2BD5DF88EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{05029DD4-6EF0-49FE-A265-C513E5A7DF9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{37D599B3-186C-40CB-B5C8-571F21AA33A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{A0CBF3AC-8C34-49AB-B202-35B0B22FEF88}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{1E803FB5-8410-42E3-843A-81C9874C7F16}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{3C642422-BC3E-4ACD-B7F0-873BACFE49B3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{2BCD3201-BC30-4F7F-81B2-45F59FCE9E52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F9AF067C-4A5E-4E27-886B-7BA01D57288C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{C89EFE6C-D514-483F-8608-799F1D11A309}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{2B50A864-E362-413F-B5FE-968D1D245132}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{2B58C6EB-1517-4EBB-BEA1-5E6B73FB7CF2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{451DCB00-92D3-4E01-8887-C462B74403B8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{57A0B1B2-EF30-4D6C-9FB7-D00CA393076A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{5691EAC0-5F14-4408-8652-46DD343F9238}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{F9B9EC52-6807-4987-988F-498859D5DFE7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{385551D0-2252-4C36-A349-0F6EA655235D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{F84AC383-9EEA-416A-8DC8-F3B62A46F92F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{29184E50-2741-444E-91DA-CF486FA362A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{52105157-D0B0-4863-BA19-D0DFD3054F32}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{EF7399D0-D073-4059-9717-D7F70605DBEE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{4AD5E10F-12E7-4875-9397-2205503D6255}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{3EB9C4E5-BF5C-4E42-8EBE-D88BCBB59FC5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{1B714C6D-DAA5-4277-93EC-092C2AF6D3F0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{CE039632-AD10-4BC5-A7C2-04EEB8F1970B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{75785327-A85E-422E-960A-823B6043C8A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{00F392E1-684A-4B57-8D28-AFD1AF3A33D6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{BD4B74D4-3CC4-46A7-B2CC-CD786CBE2408}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{58A67B88-585B-4E41-B914-140E95345797}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4A97C06B-7032-40B2-BA73-B05CB9B89624}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{82F59B86-B68D-4AF6-A05A-5DB6CBCFCFDD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{EF8FB5D4-A7B0-4642-81C7-AE744D4CB526}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D8463C28-4598-4C25-94C4-7E91E059411B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{94742D91-C3AB-4EFB-A3CF-3E9001D09065}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{0B5EA8E4-2904-4397-9062-B2E62D18D94F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{7EEA5128-2E77-429A-AAA0-1DCE104EA2CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{B5222588-9C53-4CA5-ADB1-5463F5BB381A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{EED9D903-BE0E-49E1-9063-58DD50FE876B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{9BA3B229-DBAA-46C7-B6A0-9C83F159DF70}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{B8CB1011-3DA3-4608-8386-DE12D17669CC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{8791D9AD-53E3-4633-B1A0-7E5433CA2875}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{F9D7DD31-D683-4DE6-A800-A123A39C4BC7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{A41CE4B9-FF56-4D7E-B7BD-124CF5A8A3F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{97A9560C-CED7-449F-B079-08E62B51BD6F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{913BA024-8698-4F60-8C7E-8F5D064242C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{AD537B18-7F52-441C-9D66-CE40DD60DD60}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{9F6C7D64-5F24-40BF-878E-5457D7D7FBCC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{BCE469CF-5FE3-402A-B5B2-3F5D3F312E05}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{F5583B4E-B7F0-4067-8482-998393C95021}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{9B963A37-0068-4A90-8C95-795DBA0D7A16}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{1D787C2A-20A0-4BB6-83D4-2B608D44A651}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{1CE30DC2-EF9A-4249-8421-E74F20FBEAE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{EB3728FE-D673-4B46-9C92-EB1753836C78}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{C8579BB8-4A1B-4D38-95A8-10B2DDBAD0AA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{A5443D36-6407-4A5C-9C26-F849B53800D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D283E223-E9FC-425E-8AD6-A33BAA9478E0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{3541E389-7992-4DB5-ABB1-A28F480FEFAA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{D9A3D2C6-1C0E-48A2-80D7-9282DDEED833}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{F3226711-34BE-411C-8EB6-1B53F1335D12}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{F9C956B0-5D4D-4761-BE5B-9331F57103A6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{5618F44B-E606-4B5E-B4E6-B5DF4F7A39E4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{221B7B28-499B-4113-865A-023E629A2665}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{477E4F55-3DBA-443A-8E26-1BF01CAE6F10}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{E98A936E-FD56-43FB-B4AF-515C9DC49E28}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{F8292803-C899-46F1-B956-820F89B28717}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A9C34DC6-36A9-4A24-84EC-8E2ED3F10E78}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{47706A1F-014E-4567-93B2-07B6D78974C5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{04B25DAB-31BD-42A2-9110-F98202619486}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{65C7F1F9-6F89-4DF8-A853-DBE7F4494939}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{92013DA1-B7F2-4885-A334-402A12D1EB21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{3D7E67B0-BA2E-462A-9760-AE229FC4E1AF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{8E53E989-28F3-44D2-9837-4CBEA1EAD7FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{77C6580C-A3B4-42E4-8D1C-05B0FB6D788B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{D6144267-D624-45FC-B279-B13E49F47901}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{F87E0087-CF47-4310-B96D-83AC94DCAA21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{6046898F-4B34-4C7B-A2E9-7309DB33AFF9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{8A47685B-2CE1-4997-9010-842F5D9E4C10}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{ECB0F8CC-D20D-4E40-AF06-62794E084FBD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{956A255A-0A14-442E-B0E3-671852BB5F20}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{3B75B607-EE3A-47FD-9AE0-1989F2A1E9EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{96EA7030-070C-4A29-AF9F-5A9115A043C3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{5B553C76-0D9C-48C7-A659-DF0765FA33BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{7338396A-D104-45F7-807C-3F882D47394F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{9956434E-7003-4C4B-BCBA-ED7C3585E569}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{B1820254-717D-4011-ABEA-15BA6C578580}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{586048D2-3A85-4436-909D-6CD61404EA84}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{ED0F819A-1E21-49C5-AFB6-763E73B3751C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{E823ABA8-9DD5-4016-A405-02E863B3493D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{994B0AAA-69F0-45C3-B999-EB57F185FAF5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{B529D897-AA88-423A-B57B-5749F062679B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{44D615DF-EA26-45A2-8EA1-04903F524600}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{1D03F092-29D6-4025-8233-1F73692665B0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{0BC5A9C7-6AD2-491F-B34D-8012D59AB9C4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{74A8D3D8-5B4A-4285-8E67-BC79EDB5E22E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{76F33769-EE9C-41E4-A76A-99C0DF92FA28}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{923C619F-AF59-4DE2-AD90-60393B4FC253}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{5A55BE7A-ED8F-46F0-8E4E-F9818499EF6E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{C3580C2E-88A2-419C-A4BD-AF902E919376}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{CCAE9171-B2BF-487F-BFCE-E7C58021D327}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{9604DB6A-5F98-43FE-A57D-E02496D84F0B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{840110FD-C296-49DC-9E8C-F0FF7CF8D338}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{D816EF80-C794-4C32-A738-51454E094BE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{FFE5515C-A5A8-4601-AD1D-1BEC708655A0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{0D08E371-8CD1-4985-89CB-C3F532539931}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{84825376-38FF-43D7-80A6-5E137AE5A569}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{882909F6-40EC-41CF-944C-5EEBA66C9100}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{237C330E-8CA5-4886-83E4-E52F9250D777}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{602B88F3-EF51-41D7-A29A-D440509E4D2C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{54C24BC7-9347-4492-828F-7CF404D50E97}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{444806C9-54E0-4EB3-B29F-7CA1B7F76C17}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{1167EBFA-9095-46E4-B8F0-F4521B2A8D3F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{9A51CF52-8B27-4AFF-8D77-559637CEDC8B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{BB3B0896-276B-44A5-A601-1758E0D47278}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{B32F1CD4-AFB1-4634-9865-05BC344D728E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{98724BDF-7A04-4D5E-AB20-D5B290615B77}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{C800A94C-CF93-44C0-AE32-2A7B0DC9F2EC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{88524DF2-C0DE-4907-B8CC-294928A5EB44}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{18C7302B-58FC-4BAD-94E8-5E4FE08F514A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{BA617ECF-4367-4A99-A370-8F30618CB761}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{1F6BC906-CED4-4232-9A56-51DF78997488}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{5868933A-5A35-4F2F-95D1-7C1F63D311C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{419905C1-4BBB-4D38-84DA-68A6E4431DC1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{7BB8293E-1B33-4377-9AD7-CED99DF04A55}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{3DDEF07C-3614-4C97-8C3B-C4B63D732800}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{8321D4B2-FC5D-4A41-9B11-4E31C993623B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{396CD532-1AB6-462E-80E0-2360B128B998}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{445FC3F9-1647-498E-B89D-D0517369B313}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{18762016-25DA-480E-A31A-BE251DE4A663}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{830CA81E-AEE4-4F7A-BE20-1DD702F42E48}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{6350333A-2A8A-412A-B92B-4EEA2D7B15CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{F6A6EF37-7CAB-4772-8465-C824E049F228}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{4E5BCAEE-1D6A-44D5-9910-FCA06EB4D419}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{4CE2AF1D-897E-424A-AADB-A8F7F3E15D0D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{62EEAD21-7B97-4573-A842-901358A87FCA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{73C961E5-5B42-4D5F-8090-2D520503AC2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4C9597A8-ED5B-4FEE-AF1A-D5B7ACB556DF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{41C9FA3D-AFB3-4C4F-8172-E01D0E1F292F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{996040C7-C60C-471A-A3E9-9F402BB54DE5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{AD125FB1-2F9D-413D-AE8D-E3AA7B7D9C92}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{2A189D20-C0CE-4C3E-8BAD-40A0ABE593DB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{66282D57-7671-4E26-92AB-FBE05D599B0D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{4B333796-5ECE-427A-A270-A94A29D45D7B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{A49BFFBF-6B22-4CBB-905D-9388D0D8E853}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{51BCE67A-6A52-41D5-B819-17CF3E7A7FF9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{2F6D6151-F9B7-4A00-88FE-A6D7AF70DD33}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{970D64EB-EB84-41B1-912D-5B9492E048D2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{2292CC30-3D4F-412A-A7DA-C59F30FD7BD7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{B753A166-5A60-4D15-A8D4-94A79E2D21E3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{2BF836ED-A5ED-4A8E-9106-9E5D3D02737F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{A24D220C-73FF-4DE5-AE4F-1F26CBB25433}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{27A43AEF-27E7-4965-A3CE-C0B309D818D4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{38FF9317-D383-4628-8B75-C2E35469F09E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0D6131BC-DE8D-4B85-987F-56E0C7326CA7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{D42B1A61-42CB-4BA2-9009-DA96CF9B4D39}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{C66DD24F-9F54-4D64-8ABD-DC2C76FC35E2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{1FC41BD3-A102-4484-8567-82C5D99C618D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{D7158814-C472-4F55-B1E1-E783706EB61D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{0A2BA905-07F7-4E41-8C31-2BFF1ACC9818}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{F31B4288-3C78-44F7-BE6A-2C15B30CE308}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{1225F521-B194-4F12-85C7-B0850E58A4B5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{60DF971C-8FF1-4A26-B761-03DAAE2F9E23}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{5952EE95-EFA6-4CFA-BC4B-A3261668C66C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{DEED4512-FE7C-4DE1-B14A-CD122739C1AA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{3F16D408-79DE-4932-A23C-E915A6E2CC00}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{742E95EA-CC2C-43A4-8B8A-EB9E80B55FAE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{7E816C99-850F-426B-8022-EF18117F6D62}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{4EBCDADA-234A-47A2-B1CB-BC35BD16214B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{86C8D379-9E38-443C-8F51-0A0FA761FDAF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{8CD1C63A-3DE9-424D-BA6E-DE8A9494D340}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{C9A494A4-47C1-495A-8680-1AC853DF67B4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A76DC0F8-FCC7-4306-B39A-E177167D675A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{C2794317-6FD2-437C-A781-449C5400F19B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{1A62BFE4-2EB9-43D1-8D57-92A80AF054A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{9B12861A-54D3-4385-B12D-55AD087F80AC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{2CF3E5FB-3D2F-418B-B26E-C02D7D19C763}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{C1728706-D583-4CEF-A6D4-A4013FD07FD9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{85B7E324-FAAF-4846-914B-B1578FD2463D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{930E4CDF-0B9F-4A5B-851C-E9D22E92D0FF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{ED1333B0-A38D-4C62-BEC8-CB89847D40AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{84FDBCD6-0BF4-4557-8010-EA4954C3304D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{55567EBF-38CC-463F-A9C4-81ACEBB5AE3A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{4B897D2B-856C-4D4B-9BA6-421EE5DC6D87}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{087AF2AE-7159-46CD-95E7-DE3D8112EEE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{85F7EF93-965A-4D9A-AFEE-986EFBAD0D19}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{831447DC-C38B-4AB2-B09E-991556598ABC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{4970DDF1-D1EB-4450-B341-E4188360A9A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{7ADFE507-30FB-42F0-8DB9-91D04E572DB6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4B47C2E3-A030-42A4-B8A3-656A76355622}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{E3917AE8-6AD3-41C7-8E73-AA9E308D2E6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{806A68C9-159E-4800-A4F6-7E43157CAC7A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{25D05800-49CD-491F-A193-4F2B7904D5C2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D66BA010-3DCB-4213-89B3-0BCE4B9C31A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{E7A96B26-8C91-498F-99EA-4198C1AA3D5F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{06185A7C-CFCF-4F8B-A11E-A1A8C59241C6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{ADE50361-73ED-402A-BED0-D83CE73FE012}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{0720EDD9-C226-4619-9246-6ED175FE72E6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{45A6720C-90C8-4397-9822-D98E9DBC30F1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{DA92DE42-5811-470E-A116-336A0635EABE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{AB335667-3D21-4921-8524-61C58916A9AF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{59213E32-ABF6-4459-93AA-5B98576B4356}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{54115EBC-91E2-405B-AFAF-08FEF8C89ABD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{7BFA7B88-F361-47AB-82D8-0DC331D7A4C0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{32CB1C98-3F3F-4FB3-97AC-9C6C8052EB3A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{23FD16CF-C432-4158-BCB3-242368F23B01}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{24C576D0-C6AC-402E-A7B9-944EF9131666}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{62C8E5B2-0FBD-4B41-BED2-53CC4C915700}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{B9E323AF-A847-40A7-A2D2-E7E63181EDE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{ABEDF61E-B727-4090-8BFD-25B3F1E0B7FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{9975673F-813F-4503-97BB-E89AAD93C6BD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{7A5A3377-9F40-43C7-B7A3-C16CE651DD2D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{AC4151C0-BCA9-4800-85B0-46F9C3C0A5F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{21315192-4267-490F-A99C-BE823B0CF38D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{2757E499-0A7A-41CB-BBF1-2F1ACF98CEA6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{A4ADAA4B-3BD7-4AA8-8446-5D3A3400F6A1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{AC3C0900-D66D-48CE-BD7C-0F8EBAAAB8E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{34C352A8-E57A-424C-8816-5C6D2C0A0FCC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{5EDF99BF-D5AB-49E3-B59C-C9CA40DA7049}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{E37D60EE-6DDC-4556-8A37-24C209E51A5F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{9BCEB768-1D44-47DC-8495-53480ECB1DC6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{0D0840F0-B77D-41D9-8C71-9DB86952D65E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{53D6BEE5-5883-489D-8E51-12AA49F727DE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{EB9D16ED-98FF-497D-B7CF-89E7EACDFD66}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{B9C32014-5270-4EBE-9570-FE54A3009FCA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{571CB96C-2F3E-4A3D-8EEE-BA85807E15A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{61B6B6BB-85E0-4FFE-B84F-4A7391CDA9E9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{44905744-600D-4B6B-92D3-B9E77CE55BF8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{836BA3D2-4B15-4961-8937-C6FA117DC1B3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{43E2C103-2856-4DAE-AFE6-F77E9BA662E7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{0A28D9A3-C1BF-407D-9EA5-46C23AB2561A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{63D99D74-FA6D-4DF4-BC49-B34D52C1DBC9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{4B946B93-E862-4975-9692-CD3E77F0B07B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{6AC91EFA-85B0-45B3-A51D-1F28461326AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{54453F96-53A4-4A0B-BAA5-ACE5F4685E80}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{5BB6228B-B0E1-41BE-8902-5124236D98D8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{09047D4A-9A01-416F-B7BA-681ABD5C785D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{6F5A9E1D-67D2-4709-BAB3-BC51DEAA0157}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{734F27DF-AF33-4083-9CE5-BE793E6ECD3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{877F399F-0DDF-4376-A079-401739E6E9B7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{736C5DED-45F3-43E7-BB0C-F3E675F0CC59}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{DA4EBA7E-84F6-4298-9351-AE6D3D71BF82}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{9110BA3B-2F0B-4518-8588-700443768238}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{6501C792-B8AA-40AE-89BB-4AF01CC698FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{EDF7CEC0-E4BE-4465-991A-52E5502E024C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{A716A6B1-F721-40A3-848B-2FDD326B3EE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{039B198D-705E-49B3-9E3D-828B56FD59D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{F7162BAF-365F-4D5D-B271-5BD418F01975}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{7EAE5C3D-307B-462A-A858-EA0B594CE82B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{63B55664-E517-41AE-9F09-DFCBFF9AC504}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{CE52B9D1-5897-4F03-9018-5DCDC89EDC2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{BC8BFA97-1F9D-457A-BCF3-109534E78138}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{CB28C9A0-0A12-4F2D-83DC-72BF557F7FEF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{2B5B36AD-4AF6-434A-A1CF-416AFA0FA052}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{E8743456-58A6-48D5-A52E-403C70C6ECA2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{3D3774C7-82FD-4550-8234-E64978B556FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{0810CCDB-D870-4EF4-BDB3-389917F04E80}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{50A0D057-8D59-4043-826B-7B6EC25210C8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{7577A582-AD09-4B6D-B4B9-F15A8BE752DC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{428F75FB-A150-4C1F-9B88-C2AEFA2B3A84}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{AE1F4440-4039-4A5B-BA84-B33D3E67EAD0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0AEEE225-A289-48BE-B94E-BB445DF9A42E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{41D429AD-F908-4F95-BB4D-277783A8CC9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{A7DAD158-0F9E-4D00-9B49-A7B8BA331BF0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{DE9CE2F9-7A55-4500-909F-5BB366F374BF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{CEEEF407-DCDC-42EA-B6A4-264D4D4625E2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{0B98B4C7-39C1-4CF0-A4E5-6B372EBE071F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{911A2BBC-E15E-4222-8E23-466106BFB6A3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{2E0D7F15-6DBE-442E-881A-49EC18F614D9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{3FDD1303-5E7C-4402-8ACC-2ABDEED6E896}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{44869CA9-EB15-4A02-A008-D9DEE9567A3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{A329DBE3-8C51-4ECE-BCC3-BEA6B2E0EF97}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{85A7D7D1-4FFD-47C3-86C0-0F0EF2625C3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{27DA754C-5D39-4064-887E-88AA167F3260}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{34E149FD-E60A-4271-91E8-12D99BDB0976}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{CB781C8C-90EB-4DDE-8412-8536BC822384}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{023390C2-B321-43E9-8646-789858902107}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{2D85B4F9-2C3E-46EC-AF8A-FC3E1C862AD4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{BB1DA088-376C-4A7A-A5DA-B398F3E43CEB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{D8A6F997-5AA9-45AD-A3B5-57162AF354B4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{8D4FAF89-BCEC-4D7D-806F-D8638B75F26E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{4B269D81-79E5-470F-9567-1692900473BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{0E8FECED-2F14-4411-BD47-66D744198A07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{F1F6330E-A436-401C-9901-9366DFDBBBAA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{766BB2D7-2195-49FB-9A12-47217072423C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{613B658A-93ED-42DA-A805-4856BE8F09D7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{E8CC2A7E-B4A9-45C3-AC5E-4EA0B3D36DCF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{BF628C87-FFC6-41B3-914D-2F23FB3358BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{B3A2B215-AABD-42E3-A508-1D4D0FC77CCD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{48AF6C0E-92F6-44C3-ABCF-0299708BFCC0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{3D9F00A0-ED7B-46E9-B276-4E29971252A9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{15E652CB-3192-4815-862A-C638037BC8CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{EBD18A9C-033C-4887-B2BD-CB460DB7B464}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{E2394666-7621-406A-86CD-15879139D22E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{BC4C1B01-03EA-4D93-B48A-A8ADACC4A5EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{13BF5504-C27F-46EA-9C52-415E342E2741}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{A900B289-6FD2-4833-A338-EB252FD7F16B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{0378E5CD-F0D4-4504-8A2D-6A825C04483A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{FF161DC3-5648-412C-80BF-9524551A9DBF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D94DDCEF-FF3E-4303-8F34-2ED2F926B712}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{3EC90262-3C8D-4E5F-8B48-33B579C6A2E1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{00A9B852-1B3B-4827-8A67-3FC043FEF4BA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{B64C51D2-17FF-4FAF-B9E1-E1023415406B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{8F3D470C-7132-4CEC-8308-0BB6745234A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{5123CE83-E233-49B6-989F-F4FDC19A090A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{672D504D-ADD9-4543-8A04-999325C53EDC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{B7335824-5F8D-4E3F-A5D2-FAEB3652B6F6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{E93E102F-08D0-424F-BDE4-2501D8B06630}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{05246B97-56B9-4EF3-A45F-CAB9234DD283}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{987E7F8C-FF0B-4331-872A-2F867D6B65A3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{8B08229B-38E4-4C00-BB4B-7C9A2809763C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{D1D54CB9-4FA2-44F4-B586-C5CCED80B5F4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{0E8EE5DA-A7E6-4DFC-A211-0E3826EBA949}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0010D7F5-4065-4F68-9F81-5F9B83B56B52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{A471A1E9-EADA-449F-A126-EB56C9DE418C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{7EDFF1D1-6283-4E08-A3A2-47134A78B427}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{2A5982EE-EC73-4115-B344-A9448D92261C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{B5A6CF6A-72BB-4C39-9613-BC921768FFF5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{E8BF7E1A-E228-4B7D-AADF-EA022F64A255}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{FFCAC4AB-263F-4D27-8E1F-48685F20BAEC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{17FFCF9D-AD3B-4889-B049-048D167EB1AB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{11CAC8B9-494A-4C98-B177-72A7CB7642D8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D30CFC0E-367A-430A-9EFD-2051E8ECB800}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{FEA81D5A-8D2C-46F9-AACD-102BE4F39A81}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{38C44A11-D9F0-4CEA-8C59-B224FC27920F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{B60744A3-3626-4327-BD82-285D4A745426}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{33EAE836-6546-4CB6-ABF1-4CB6A094D0CD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{883B687D-BA7F-4C43-B587-06715F39CEEF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{120CBB2C-EDC5-436F-BB0A-7DA7629C5929}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{9A946423-9CEF-4479-9EE9-EBF0CC2B7EC8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{7EA26CF7-AFDF-4195-8648-97890CA74DB0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{480AB8B6-ECC0-4FE2-AFE5-78D5F6A5BED2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{5E5967A5-FA55-48EB-B946-4533B93B84A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{47C6CA3A-080B-44FD-A1D8-8C1062044C56}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{EC3F2033-CE4D-4AE1-9882-E5FC66E872A6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{333DDC02-E7B3-436B-BB5D-113F000AA6E3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{63FBCF2C-3E7E-404C-8B9E-ADE0000F5834}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{052F30EC-4923-43A0-BD81-0997CCD110E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{A54A5799-50F6-4188-94DE-6F900B290C6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{1E2B04C4-8124-4182-A58A-5EEA6F06826A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{90261EB1-2221-4D5E-A676-3A53F36C40EF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{D87B24B6-98DC-462C-931E-8AB13E84B7D2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{F922DB43-EEB2-4DA4-86E9-C7722689084D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{FE0557F0-BB04-481C-A46B-8B469CB4DE95}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{2C860004-8BEC-443B-951C-D025192EB5BF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{85FD87E8-5C74-4670-AF47-BDCBE616CA07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{07D9D872-01A5-4F20-9ECF-555F0A2E0084}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{D755B785-6173-4B55-A993-793F5BF27928}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{2A339B18-F114-44A9-BB4C-E95A271600F5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{040B4775-3792-4287-995E-40E1ACED7F3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{081AD8EB-777B-4BC3-89B7-C5EA36CEB736}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{AB01407D-587C-4E9B-ACD8-DA05707E6811}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{FE0775D8-123A-4F81-9AED-8E7520EDC213}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{B2C3263E-F590-4338-9E8C-26ECE9313E95}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{CD46A599-9D05-468A-BE92-CA0B99EC4A47}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{69DFCE55-558C-4EED-A517-74BD1FD086AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{902BC3B7-1199-4C96-9512-6A7A5B5436C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{5809923C-16F1-4E5F-94D0-78854FA5B892}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{2DEF269D-4A61-4067-98BA-4402D5E60146}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{2B25BA5B-FD5A-40DC-A7A8-E9646E618123}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{1A8D33B4-0B26-434D-BA22-22251825D207}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{287217C6-AA67-4B88-9D06-31F5CB5AD859}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{8225FCB1-1685-4867-A9B4-2BCA0EE9C898}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{26F855F5-C42E-4713-8685-69B1EB146ED3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{6C7103FE-84FA-4C63-A686-9D48E50364CE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{DC6C833E-7509-4640-98FD-6F66AE91A1D7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{56E744E0-60C4-43BF-8DE8-0C057255DEE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{AE4152F0-A7DA-4193-B1F1-25B5C47893FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{F7FAF980-6370-488D-A8D8-7B17FA8DBCF8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{7ADFE28C-5C1F-46F2-9A28-D90CEB38A316}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{A3DB897E-4D94-4A07-8177-92CE1F3AF903}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{222E7604-7380-45ED-9322-64238EF72023}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{7AD0E036-0226-4FD9-98EB-2913AD76CA83}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{3BE26C79-6809-4B3C-91EB-7048927D3339}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{454BEA0C-1BAC-469C-8B59-09D428EC8742}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{973C1E16-B2D6-4D1E-8305-E69341F2688E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{1422A4A9-5B64-4662-82E5-EA0396565B5A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{0D8B6231-D8CB-4136-BF35-0552FA8C0A68}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{B68BFDB9-54AB-4EC6-91BA-FBEF718947C8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{C41BDAAA-4B3C-409F-8BAB-28BB8617950E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{AA21AD32-08AE-44E1-AD92-3F84918AD561}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F7C51446-29DA-4871-BDB1-9E87366B5E9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{3AFDDD61-9B21-442B-A2E5-A9569B9756EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{28F3A9E8-5CB4-43E8-A420-F58A5E8E0215}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{6B2DB471-2705-4BEB-8726-0DE47F433BD0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{DD9EB22E-A092-44B1-8655-C06A17D07A07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{E3160591-0CDB-43CA-B789-8B18FD06FF2A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{AE2EDABE-1FC9-4337-B4AB-FE5F30AF07BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{5E3404AC-ADDC-4B94-8753-149D126B308A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{2629FCEA-6CEA-4B43-B105-4FCAA339FCAF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{29940186-D4F5-44B4-AF81-9D8B2B759F7D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{35B2994F-926A-414D-AB64-C7A9013A6D6E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{8EE992AD-2D64-416B-A11C-B21D601090E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{C4F877C6-CF47-4CF3-BB66-849D32736764}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{E7E5C226-AF28-4A19-A1A9-D3CC86741C6A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{65785401-F682-4656-97AF-6D1E77379270}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{D8BEA1C9-A641-463D-AB06-CC99858E9B6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{F29072B1-DB28-4F11-A7CB-270A2F550E72}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{E5C4DAFF-1E42-4221-A456-17EC2E08DAF2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{94910D5D-4577-4CAF-AB2C-2EB080370AE3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{A12DA46A-421D-4961-A892-34798003BF52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{AFFC572B-8292-49AB-A966-A3A06344639C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{BC6E663D-A81A-477C-96DD-1C882B293857}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{4D74C129-09FD-49AA-B48B-B819358F9F5E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{36112616-2F62-4359-80B5-34952595A745}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{3F8F845A-577D-46E4-BCD8-54BB17E249CB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D18699DD-3663-48C4-8287-15D0A6FE2D21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{D166B5B9-A4BF-4068-947C-DBCC59783F4A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{62953C40-27B7-438B-BA1F-CDAFADD7BE81}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{48CD7CA4-0304-4691-B686-14BF64D2BF5B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{75095B6C-667E-49E4-91B2-73592D1ACE62}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{3025CB00-E332-46E2-9248-5B0632AA2458}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{24FD90F4-BF41-4927-912B-71E98DC19DC4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{D0A6EC14-C086-443A-B7F5-50A894FC2EC8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{9B0C4577-A348-43D0-8409-4DFEB1DFAE3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{6703587B-DDAD-46DF-8DD6-D1FED933D052}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{8515CE51-BDC8-4996-A4BB-768E5E6C5659}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{B9C070FC-B903-402E-8DB4-2FD986E4718A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{BBBE0D6E-946B-4A21-81B4-A6443D729A8D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{5B715575-CA69-4A17-9F59-A7A196599600}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{85E12E7F-37FF-4CC2-9ADF-3865E303F363}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{B5C3E6EA-918E-4F2A-A7E0-DB6A522BA951}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{E866851B-4352-4F59-81C4-6438151BB509}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{A3AFF576-D01E-44C7-BB3F-6C9D31F562D0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{4CFC1407-9AF8-4FE7-86A1-49F33F2BB07F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{EDC9DC78-295F-4CBB-B2E2-1ACFFDD729D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{1787E7A8-2279-4268-AB2D-F8098D46C544}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{26A39019-CBB5-478A-A6BE-122A36FC018B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{CD4D109A-C561-45EC-B94C-349BC9DAE8DB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{7A976567-874D-4412-8DAA-8D6C0284CA83}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{2B53B25B-4762-486C-9430-5B7A7450444E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{1DDBF75D-43B4-4A1A-AA30-9A181D90B05C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{4A8C81AA-FD97-4C07-85EF-3ACA05CE5691}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{D295F48C-16A2-4647-9245-5B817F4ACE15}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F9493F86-ACB9-453E-89D4-470168F5573C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{193DBAAC-A44C-48FB-A243-05660F8E5E30}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{DFC4811F-8044-4ADD-8DA6-5F2A47F1D871}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A12D27BE-1348-4DCC-8B62-837FA7E6CE1D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{17BB815E-338C-4518-8A5E-720D7E577817}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{E575AB30-9F18-4BCF-870B-DCDA16962D7B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{8A14BFB7-AEA0-48E2-BD72-7604675FC02C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{692D4DCE-F9A8-43DD-A66D-B5CEC589309F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{88E9FC39-00D1-404A-A0F3-AA8BA90C438D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{2571D842-A014-406E-A20B-256F482631B9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{4903107A-61A1-4916-82F6-962FCAD7AE2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{F8B79A87-1813-4A77-BB19-A05FAC3007BD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{F4723629-809F-42EB-8676-C8FCA8082C38}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{03687CAA-26F8-454C-846E-EB87CBDEF554}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{CDD4FD86-5B1B-4805-BFE1-4C34D0CF46EC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{7D96C65A-19E6-4B65-BBE9-FFF7E2BFC9FF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{B534C0BE-9719-468B-94F4-EBAC0849B3C7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{5C87CE16-1B9A-46C9-9082-C2C2B44BE54D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{2CAD68CE-0024-4E6D-9A84-95BA3C65CAFE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{3F1F39BD-6F42-4137-B0EC-42A3E62FC3E0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{5D607F7A-6B19-472C-AF51-3BC959512E8A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{1CD3ABE9-B6D6-4742-B22F-669CE1192DE7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{74D85154-2A03-4121-B752-08B480A174FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{4DF37154-D997-4A05-9B64-DD1BF9A1C8A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{8BD0774E-477A-474A-9B6B-2C74B7A6AF35}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{5310066A-AEE3-4CFF-97FE-A27F829C4ED4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{410031EB-900A-426E-BFE4-A51DD7E218BE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{5C90C829-D035-4FB2-9C35-8F560A22737E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{23FB6F20-8E80-4274-B2CE-5310A4543D7E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{CB3E27CB-7567-440E-A224-2F5F55F180FA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{D577FBC1-ACD1-4D2C-BBB7-BC9753C0725E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" + +;075. ViveTool Manipulation + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\105243275] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1084486795] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1105025673] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1111440523] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1140553355] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1167405706] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1254311563] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1286552203] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\129315978] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1323362443] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\133772938] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1431914635] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1497709195] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\151073418] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\152522890] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1570325131] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1593135754] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1604982409] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1707173514] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1711504522] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1740062347] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1826306186] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1879800970] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2061326475] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2080885386] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2098554507] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\210965642] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2122649227] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2141004426] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2159103626] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\221325962] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\230377099] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2475784331] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2528327818] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2536843915] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2553628810] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\261698187] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2628859531] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2674077835] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\269563531] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2736994955] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2778935433] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2845256331] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2866624651] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2888518282] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2891254923] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2940954250] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2954081930] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\296246922] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3054451851] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3073583755] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3135060107] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3298293899] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\345723018] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3535874698] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3543217290] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3655416971] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3665657483] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3784116360] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3793829003] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3928046731] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3928239754] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\395859593] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4045366411] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4095660171] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4122855562] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4134351499] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4145095306] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\463973000] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\469712011] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\479401098] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\523318411] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\525560971] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\553726602] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\581515914] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\589803146] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\641901194] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\644487817] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\653733002] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\65394315] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\783108235] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\814945418] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\892417163] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\957700746] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +;076. Service Removal + diff --git a/Melody 12.01 (Script for Windows 10)/ma.ps1 b/Melody 12.01 (Script for Windows 10)/ma.ps1 new file mode 100644 index 0000000..6112035 --- /dev/null +++ b/Melody 12.01 (Script for Windows 10)/ma.ps1 @@ -0,0 +1,38 @@ +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "WOL & Shutdown Link Speed" -DisplayValue "Not Speed Down" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Power Saving Mode" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "NS Offload" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Jumbo Frame" -DisplayValue "9014 bytes" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Green Ethernet" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Gigabit Lite" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Energy-Efficient Ethernet" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Flow Control" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Interrupt Moderation" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Interrupt Moderation Rate" -DisplayValue "Off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Enable PME" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Maximum Number of RSS Queues" -DisplayValue "4 Queues" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Transmit Buffers" -DisplayValue "128" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Receive Buffers" -DisplayValue "512" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Large Send Offload V2 (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Large Send Offload V2 (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "TCP Checksum Offload (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "TCP Checksum Offload (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "UDP Checksum Offload (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "UDP Checksum Offload (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "IPv4 Checksum Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Speed & Duplex" -DisplayValue "1.0 Gbps Full Duplex" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Gigabit Master Slave Mode" -DisplayValue "Force Slave Mode" For two NICs +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Maximum Number of RSS Processors" -DisplayValue "4 Processors" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "RSS load balancing profile" -DisplayValue "NUMAScaling" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Protocol ARP Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Protocol NS Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Ultra Low Power Mode" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Jumbo Packet" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Magic Packet" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Pattern Match" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Link Settings" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wait for Link" -DisplayValue "off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Energy Efficient Ethernet" -DisplayValue "Off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Reduce Speed On Power Down" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "System Idle Power Saver" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Log Link State Event" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Packet Priority & VLAN" -DisplayValue "Packet Priority & VLAN Disabled" \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows 10)/nircmd.exe b/Melody 12.01 (Script for Windows 10)/nircmd.exe new file mode 100644 index 0000000..e606a83 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/nircmd.exe differ diff --git a/Melody 12.01 (Script for Windows 10)/nircmdc.exe b/Melody 12.01 (Script for Windows 10)/nircmdc.exe new file mode 100644 index 0000000..6e7fe18 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/nircmdc.exe differ diff --git a/Melody 12.01 (Script for Windows 10)/secdrv.sys b/Melody 12.01 (Script for Windows 10)/secdrv.sys new file mode 100644 index 0000000..fd2fe65 Binary files /dev/null and b/Melody 12.01 (Script for Windows 10)/secdrv.sys differ diff --git a/Melody 12.01 (Script for Windows 11)/Blank.ico b/Melody 12.01 (Script for Windows 11)/Blank.ico new file mode 100644 index 0000000..f6748fa Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/Blank.ico differ diff --git a/Melody 12.01 (Script for Windows 11)/PowerRun.exe b/Melody 12.01 (Script for Windows 11)/PowerRun.exe new file mode 100644 index 0000000..524816b Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/PowerRun.exe differ diff --git a/Melody 12.01 (Script for Windows 11)/SDL.dll b/Melody 12.01 (Script for Windows 11)/SDL.dll new file mode 100644 index 0000000..a7981ff Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/SDL.dll differ diff --git a/Melody 12.01 (Script for Windows 11)/Toggle Camera in menu.bat b/Melody 12.01 (Script for Windows 11)/Toggle Camera in menu.bat new file mode 100644 index 0000000..d134b74 --- /dev/null +++ b/Melody 12.01 (Script for Windows 11)/Toggle Camera in menu.bat @@ -0,0 +1,172 @@ + + + +:: **************************************************************************************** +@echo off & title Turn on or off the camera. & mode con cols=80 lines=13 & color 17 +:: **************************************************************************************** +Set "【Item】=Toggle Camera On or Off" +Set "【Name】=Camera_on_off" +Set "【Path】=wscript.exe" +If not exist "%ProgramData%\Fidelity\" (mkdir "%ProgramData%\Fidelity\") +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%\Command" /VE /D "schtasks /run /tn ""Apps\%【Name】%""" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Icon" /T REG_SZ /D "%WinDir%\System32\DDORes.dll,86" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Position" /T REG_SZ /D "Bottom" /F) +Cls +If errorlevel 1 (echo. +echo ==================================================================== +echo. +echo The script has failed to perform the operations. +echo Press any key to exit. +echo. +echo ==================================================================== +pause > nul & EXIT) +echo. +echo The script is creating an elevated task with highest privileges. +echo Please wait for a while. +echo. +:: **************************************************************************************** +Set "Folder=%ProgramData%\Fidelity\Turn_on_or_off_the_camera" +If not exist "%Folder%" (MkDir "%Folder%") + +Set "Script=%Folder%\+Turn_on_or_off_the_camera.cmd" +If exist "%Script%" (del "%Script%") +( +echo :: **************************************************************************************** +echo @echo off ^& title Turn on or off the camera. ^& mode con cols=68 lines=6 ^& color 17 +echo :: **************************************************************************************** + +echo cd /d "%%~dp0" +echo For /f "tokens=3" %%%%# in ^('REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V "Value"'^) Do ^(Set ✱=%%%%#^) +echo If "%%✱%%"=="Allow" ^(goto Turn_off_the_camera^) ^& Exit +echo :: **************************************************************************************** +echo :Turn_on_the_camera +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V Value /T REG_SZ /D "Allow" /F^) +echo ^(Start "" "Enabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +echo :Turn_off_the_camera +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V Value /T REG_SZ /D "Deny" /F^) +echo ^(Start "" "Disabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +)> "%Script%" + +:: **************************************************************************************** +Set "【VBS】=%Folder%\+Run_the_CMD_script.vbs" +If exist "%【VBS】%" (del "%【VBS】%") +( +echo Path = split^(wscript.scriptFullName, wscript.scriptname^)^(0^) +echo Item = Path ^& "+Turn_on_or_off_the_camera.cmd" +echo CreateObject^("wscript.shell"^).run^("""" ^& Item ^& ""^),0 +echo WScript.Quit +)> "%【VBS】%" +:: **************************************************************************************** +Set "Enabled=%Folder%\Enabled.ps1" +If exist "%Enabled%" (del "%Enabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Camera enabled. Press the Windows + M keys for it to take effect if the camera cannot be used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Enabled%" +:: **************************************************************************************** +Set "Enabled✱=%Folder%\Enabled.vbs" +If exist "%Enabled✱%" (del "%Enabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Enabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Enabled✱%" +:: **************************************************************************************** +Set "Disabled=%Folder%\Disabled.ps1" +If exist "%Disabled%" (del "%Disabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Camera Disabled. Press the Windows + M keys for it to take effect if the camera is being used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Disabled%" +:: **************************************************************************************** +Set "Disabled✱=%Folder%\Disabled.vbs" +If exist "%Disabled✱%" (del "%Disabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Disabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Disabled✱%" +:: **************************************************************************************** +For /f "tokens=*" %%I in ('WhoAmI /user') Do (for %%A in (%%~I) Do (set "【SID】=%%A")) +IF EXIST "%temp%\%【Name】%.xml" (DEL "%temp%\%【Name】%.xml") +IF EXIST "%temp%\Task.vbs" (DEL "%temp%\Task.vbs") + +echo Set X=CreateObject("Scripting.FileSystemObject") >> "%temp%\Task.vbs" +echo Set Z=X.CreateTextFile("%temp%\%【Name】%.xml",True,True)>> "%temp%\Task.vbs" +Set "W=echo Z.writeline " +( +%W%"" +%W%"" +%W%"" +%W%"To run the application/CMD script as an administrator with no UAC prompt." +%W%"" +%W%"" +%W%"" +%W%"" +%W%"%【SID】%" +%W%"InteractiveToken" +%W%"HighestAvailable" +%W%"" +%W%"" +%W%"" +%W%"IgnoreNew" +%W%"false" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"" +%W%"true" +%W%"false" +%W%"" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"false" +%W%"true" +%W%"false" +%W%"PT72H" +%W%"7" +%W%"" +%W%"" +%W%"" +%W%"""%【Path】%""" +%W%"""%【VBS】%""" +%W%"" +%W%"" +%W%"" +)>> "%temp%\Task.vbs" +echo Z.Close >> "%temp%\Task.vbs" +"%temp%\Task.vbs" +Del "%temp%\Task.vbs" +schtasks /create /xml "%temp%\%【Name】%.xml" /tn "Apps\%【Name】%" + +If %errorlevel%==1 (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The script has failed to create the task "%【Name】%". +echo The task might already exist in "Task Scheduler Library"--^>"Apps". +echo Press any key to close this message. +echo ============================================================================ +pause > nul) else (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The item "%【Item】%" has been added into the desktop context +echo menu ^(right-click menu^). +echo The scheduled task is in "Task Scheduler Library"--^>"Apps". +echo Please press any key to close this message. +echo ============================================================================ +pause > nul ) \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows 11)/Toggle Microphone in menu.bat b/Melody 12.01 (Script for Windows 11)/Toggle Microphone in menu.bat new file mode 100644 index 0000000..8b5d9fc --- /dev/null +++ b/Melody 12.01 (Script for Windows 11)/Toggle Microphone in menu.bat @@ -0,0 +1,169 @@ +:: **************************************************************************************** +@echo off & title Turn on or off the microphone. & mode con cols=80 lines=13 & color 17 +:: **************************************************************************************** +Set "【Item】=Toggle Microphone On or Off" +Set "【Name】=Microphone_on_off" +Set "【Path】=wscript.exe" +If not exist "%ProgramData%\Fidelity\" (mkdir "%ProgramData%\Fidelity\") +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%\Command" /VE /D "schtasks /run /tn ""Apps\%【Name】%""" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Icon" /T REG_SZ /D "%WinDir%\System32\DDORes.dll,86" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Position" /T REG_SZ /D "Bottom" /F) +Cls +If errorlevel 1 (echo. +echo ==================================================================== +echo. +echo The script has failed to perform the operations. +echo Press any key to exit. +echo. +echo ==================================================================== +pause > nul & EXIT) +echo. +echo The script is creating an elevated task with highest privileges. +echo Please wait for a while. +echo. +:: **************************************************************************************** +Set "Folder=%ProgramData%\Fidelity\Turn_on_or_off_the_microphone" +If not exist "%Folder%" (MkDir "%Folder%") + +Set "Script=%Folder%\+Turn_on_or_off_the_microphone.cmd" +If exist "%Script%" (del "%Script%") +( +echo :: **************************************************************************************** +echo @echo off ^& title Turn on or off the microphone. ^& mode con cols=68 lines=6 ^& color 17 +echo :: **************************************************************************************** + +echo cd /d "%%~dp0" +echo For /f "tokens=3" %%%%# in ^('REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V "Value"'^) Do ^(Set ✱=%%%%#^) +echo If "%%✱%%"=="Allow" ^(goto Turn_off_the_microphone^) ^& Exit +echo :: **************************************************************************************** +echo :Turn_on_the_microphone +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V Value /T REG_SZ /D "Allow" /F^) +echo ^(Start "" "Enabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +echo :Turn_off_the_microphone +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V Value /T REG_SZ /D "Deny" /F^) +echo ^(Start "" "Disabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +)> "%Script%" + +:: **************************************************************************************** +Set "【VBS】=%Folder%\+Run_the_CMD_script.vbs" +If exist "%【VBS】%" (del "%【VBS】%") +( +echo Path = split^(wscript.scriptFullName, wscript.scriptname^)^(0^) +echo Item = Path ^& "+Turn_on_or_off_the_microphone.cmd" +echo CreateObject^("wscript.shell"^).run^("""" ^& Item ^& ""^),0 +echo WScript.Quit +)> "%【VBS】%" +:: **************************************************************************************** +Set "Enabled=%Folder%\Enabled.ps1" +If exist "%Enabled%" (del "%Enabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Microphone enabled. Press the Windows + M keys for it to take effect if the microphone cannot be used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Enabled%" +:: **************************************************************************************** +Set "Enabled✱=%Folder%\Enabled.vbs" +If exist "%Enabled✱%" (del "%Enabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Enabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Enabled✱%" +:: **************************************************************************************** +Set "Disabled=%Folder%\Disabled.ps1" +If exist "%Disabled%" (del "%Disabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Microphone Disabled. Press the Windows + M keys for it to take effect if the microphone is being used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Disabled%" +:: **************************************************************************************** +Set "Disabled✱=%Folder%\Disabled.vbs" +If exist "%Disabled✱%" (del "%Disabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Disabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Disabled✱%" +:: **************************************************************************************** +For /f "tokens=*" %%I in ('WhoAmI /user') Do (for %%A in (%%~I) Do (set "【SID】=%%A")) +IF EXIST "%temp%\%【Name】%.xml" (DEL "%temp%\%【Name】%.xml") +IF EXIST "%temp%\Task.vbs" (DEL "%temp%\Task.vbs") + +echo Set X=CreateObject("Scripting.FileSystemObject") >> "%temp%\Task.vbs" +echo Set Z=X.CreateTextFile("%temp%\%【Name】%.xml",True,True)>> "%temp%\Task.vbs" +Set "W=echo Z.writeline " +( +%W%"" +%W%"" +%W%"" +%W%"To run the application/CMD script as an administrator with no UAC prompt." +%W%"" +%W%"" +%W%"" +%W%"" +%W%"%【SID】%" +%W%"InteractiveToken" +%W%"HighestAvailable" +%W%"" +%W%"" +%W%"" +%W%"IgnoreNew" +%W%"false" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"" +%W%"true" +%W%"false" +%W%"" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"false" +%W%"true" +%W%"false" +%W%"PT72H" +%W%"7" +%W%"" +%W%"" +%W%"" +%W%"""%【Path】%""" +%W%"""%【VBS】%""" +%W%"" +%W%"" +%W%"" +)>> "%temp%\Task.vbs" +echo Z.Close >> "%temp%\Task.vbs" +"%temp%\Task.vbs" +Del "%temp%\Task.vbs" +schtasks /create /xml "%temp%\%【Name】%.xml" /tn "Apps\%【Name】%" + +If %errorlevel%==1 (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The script has failed to create the task "%【Name】%". +echo The task might already exist in "Task Scheduler Library"--^>"Apps". +echo Press any key to close this message. +echo ============================================================================ +pause > nul & Exit) else (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The item "%【Item】%" has been added into the desktop context +echo menu ^(right-click menu^). +echo The scheduled task is in "Task Scheduler Library"--^>"Apps". +echo Please press any key to close this message. +echo ============================================================================ +pause > nul & Exit) \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows 11)/certificates/MicRooCerAut2011_2011_03_22.crt b/Melody 12.01 (Script for Windows 11)/certificates/MicRooCerAut2011_2011_03_22.crt new file mode 100644 index 0000000..1ae4740 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/MicRooCerAut2011_2011_03_22.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/MicRooCerAut_2010-06-23.crl b/Melody 12.01 (Script for Windows 11)/certificates/MicRooCerAut_2010-06-23.crl new file mode 100644 index 0000000..8166d95 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/MicRooCerAut_2010-06-23.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl new file mode 100644 index 0000000..174c487 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt new file mode 100644 index 0000000..3eb2c12 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Root Certificate Authority 2017.crl new file mode 100644 index 0000000..9ca82c0 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Root Certificate Authority 2017.crt new file mode 100644 index 0000000..86658ae Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl new file mode 100644 index 0000000..77a7065 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt new file mode 100644 index 0000000..d29764b Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl new file mode 100644 index 0000000..257bc74 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt new file mode 100644 index 0000000..90a7a79 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl new file mode 100644 index 0000000..0deac11 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt new file mode 100644 index 0000000..8835c44 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft RSA Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft RSA Root Certificate Authority 2017.crl new file mode 100644 index 0000000..0bcbf32 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft RSA Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft RSA Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft RSA Root Certificate Authority 2017.crt new file mode 100644 index 0000000..7031f88 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft RSA Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl new file mode 100644 index 0000000..8ab0e74 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl differ diff --git a/Melody 12.01 (Script for Windows 11)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt new file mode 100644 index 0000000..8a7a17f Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt differ diff --git a/Melody 12.01 (Script for Windows 11)/command2.bat b/Melody 12.01 (Script for Windows 11)/command2.bat new file mode 100644 index 0000000..f65e8e8 --- /dev/null +++ b/Melody 12.01 (Script for Windows 11)/command2.bat @@ -0,0 +1,881 @@ +:: Start with setting the location + +pushd "%CD%" +CD /D "%~dp0" + +:: Starting +reg.exe add "HKCU\Software\Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32" /f /ve +PowerRun "Toggle Camera in menu.bat" +PowerRun "Toggle Microphone in menu.bat" +PowerRun.exe Regedit.exe /S fidelityreg_reg11.reg +Regedit.exe /S fidelityreg_reg11.reg +:: Enable DirectPlay + +"powershell.exe" Enable-WindowsOptionalFeature -Online -FeatureName LegacyComponents -all -NoRestart +"powershell.exe" Enable-WindowsOptionalFeature -Online -FeatureName DirectPlay -all -NoRestart + +:: Installing Microsoft's Certs (because they removed sometime)... + +echo Now installing Root certs +for /f "delims=" %%f in ('dir /b "%~dp0\certificates\*"') do ( + echo Installing %%f... + certutil -f -addstore Root "%~dp0\certificates\%%f" +) + +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fidelity" /v DisplayName /t reg_sz /d "Melody 12.0 (EAS, partially applied)" /f + +:: Removal of Components + + +::Handwriting + +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~af-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~bs-LATN-BA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ca-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~cy-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~eu-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ga-IE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~gd-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~gl-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~hi-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~id-ID~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~lb-LU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~mi-NZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ms-BN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ms-MY~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nn-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nso-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~rm-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~rw-RW~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sq-AL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sr-CYRL-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sr-LATN-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sw-KE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~tn-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~wo-SN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~xh-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-TW~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zu-ZA~0.0.1.0 /NoRestart + + +::OCR + +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ar-SA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~bg-BG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~bs-LATN-BA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~hu-HU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sr-CYRL-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sr-LATN-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-TW~0.0.1.0 /NoRestart + +::Speech Recongnition + +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-AU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-TW~0.0.1.0 /NoRestart + + +::TTS Packs + +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ar-EG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ar-SA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~bg-BG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ca-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-AT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-AU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-IE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~he-IL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hi-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hu-HU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~id-ID~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ms-MY~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nl-BE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ta-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~th-TH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~vi-VN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-TW~0.0.1.0 /NoRestart + +::Network Drivers +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Intel.E1i68x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Intel.E2f68~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Vmware.Vmxnet3~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Realtek.Rtcx21x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmpciedhd63~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmwl63al~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmwl63a~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwbw02~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwew00~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwew01~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwlv64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwns64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwsw00~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw02~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw04~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw06~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw08~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw10~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Marvel.Mrvlpcie8897~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Athw8x~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Athwnx~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Qcamain10x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Ralink.Netr28x~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl8187se~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl8192se~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl819xp~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl85n64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane01~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane13~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane~~~~0.0.1.0 /NoRestart + +::Windows Tools +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.IoTDeviceUpdateCenter~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.PowerShell.ISE~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.WordPad~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OneCoreUAP.OneSync~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Client~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OneCoreUAP.OneSync~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Print.Fax.Scan~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:MathRecognizer~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Media.WindowsMediaPlayer~~~~0.0.12.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Accessibility.Braille~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Analog.Holographic.Desktop~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.StepsRecorder~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.Support.QuickAssist~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.WirelessDisplay.Connect~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Browser.InternetExplorer~~~~0.0.11.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Hello.Face.20134~~~~0.0.1.0 /NoRestart +:: Applying Network Settings + +netsh int tcp set heuristics disabled +netsh int tcp set supp internet congestionprovider=ctcp +netsh int tcp set global rss=enabled +netsh int tcp set global chimney=disabled +netsh int tcp set global ecncapability=enabled +netsh int tcp set global timestamps=disabled +netsh int tcp set global initialRto=3000 +netsh int tcp set global timestamps=disabled +netsh int tcp set global rsc=disabled +netsh int tcp set global nonsackttresiliency=disabled +netsh int tcp set global MaxSynRetransmissions=2 +netsh int tcp set global fastopen=enabled +netsh int tcp set global fastopenfallback=enabled +netsh int tcp set global pacingprofile=off +netsh int tcp set global hystart=disabled +netsh int tcp set heuristics disabled +netsh int tcp set global dca=enabled +netsh int tcp set global netdma=enabled +netsh int 6to4 set state state=enabled +netsh int udp set global uro=enabled +netsh winsock set autotuning on +netsh int tcp set supplemental template=custom icw=10 +netsh interface teredo set state enterprise +netsh int tcp set security mpp=disabled +netsh int tcp set security profiles=disabled +netsh interface ipv4 set subinterface "Wi-Fi" mtu=1500 store=persistent +netsh interface ipv6 set subinterface "Ethernet" mtu=1500 store=persistent +netsh interface ipv6 set subinterface "Ethernet" mtu=1500 store=persistent +netsh interface ipv4 set subinterface "Wi-Fi" mtu=1500 store=persistent +netsh int tcp set global autotuning=experimental +netsh advfirewall firewall set rule group="Remote Assistance" new enable=no + +for /f "tokens=3*" %%s in ('Reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards" /f "ServiceName" /s^|findstr /i /l "ServiceName"') do ( + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Psched\Parameters\Adapters\%%s" /v "NonBestEffortLimit" /t Reg_DWORD /d "0" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "DeadGWDetectDefault" /t Reg_DWORD /d "1" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "PerformRouterDiscovery" /t Reg_DWORD /d "1" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpInitialRTT" /t Reg_DWORD /d "0" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TCPNoDelay" /t Reg_DWORD /d "1" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpAckFrequency" /t Reg_DWORD /d "1" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpDelAckTicks" /t Reg_DWORD /d "0" /f >nul + ) + + +for %%i in (svchost explorer edge steam steamclient operagx Fornite-Win64-Shipping EA explorer chrome notepad++ steamwebviewer winword powerpnt excel mysummercar metin2 csgo VALORANT-Win64-Shipping javaw FortniteClient-Win64-Shipping ModernWarfare r5apex) do ( + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Application Name" /t Reg_SZ /d "%%i.exe" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Version" /t Reg_SZ /d "1.0" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Protocol" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local Port" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local IP" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local IP Prefix Length" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote Port" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote IP" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote IP Prefix Length" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "DSCP Value" /t Reg_SZ /d "46" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Throttle Rate" /t Reg_SZ /d "-1" /f +) + +for /f %%r in ('Reg query "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}" /f "PCI\VEN_" /d /s^|Findstr HKEY_') do ( +Reg add %%r /v "AutoDisableGigabit" /t Reg_SZ /d "0" /f +Reg add %%r /v "EnableGreenEthernet" /t Reg_SZ /d "0" /f +Reg add %%r /v "GigaLite" /t Reg_SZ /d "0" /f +Reg add %%r /v "PowerSavingMode" /t Reg_SZ /d "0" /f +) + +reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPerServer /t REG_DWORD /d 8 /f +reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPer1_0Server /t REG_DWORD /d 8 /f +reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPerServer /t REG_DWORD /d 8 /f +reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPer1_0Server /t REG_DWORD /d 8 /f + +for /f %%a in ('Reg query HKLM /v "*WakeOnMagicPacket" /s ^| findstr "HKEY"') do ( +for /f %%i in ('Reg query "%%a" /v "*EEE" ^| findstr "HKEY"') do (Reg add "%%i" /v "*EEE" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "*FlowControl" ^| findstr "HKEY"') do (Reg add "%%i" /v "*FlowControl" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableSavePowerNow" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableSavePowerNow" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnablePowerManagement" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnablePowerManagement" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableDynamicPowerGating" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableDynamicPowerGating" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableConnectedPowerGating" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableConnectedPowerGating" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "AutoPowerSaveModeEnabled" ^| findstr "HKEY"') do (Reg add "%%i" /v "AutoPowerSaveModeEnabled" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "AdvancedEEE" ^| findstr "HKEY"') do (Reg add "%%i" /v "AdvancedEEE" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "ULPMode" ^| findstr "HKEY"') do (Reg add "%%i" /v "ULPMode" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "ReduceSpeedOnPowerDown" ^| findstr "HKEY"') do (Reg add "%%i" /v "ReduceSpeedOnPowerDown" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnablePME" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnablePME" /t Reg_SZ /d "0" /f) +) + +PowerShell -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell -ArgumentList '-NoProfile -ExecutionPolicy Bypass -File ""%~dp0.\ma.ps1""' -Verb RunAs}" + +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001" /v "*RSSProfile" /t REG_SZ /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "ParamDesc" /t REG_SZ /d "RSS load balancing profile" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "default" /t REG_SZ /d "1" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "type" /t REG_SZ /d "enum" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "1" /t REG_SZ /d "ClosestProcessor" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "2" /t REG_SZ /d "ClosestProcessorStatic" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "3" /t REG_SZ /d "NUMAScaling" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "4" /t REG_SZ /d "NUMAScalingStatic" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "5" /t REG_SZ /d "ConservativeScaling" /f + +powershell -Command "Disable-NetAdapterChecksumOffload -Name * -IpIPv4 -TcpIPv4 -TcpIPv6 -UdpIPv4 -UdpIPv6" + +:: Services Part + +sc config MsKeyboardFilter start= disabled +sc config GraphicsPerfSvc start= disabled +sc config DiagTrack start= disabled +sc config TroubleshootingSvc start= disabled +sc config RemoteRegistry start= disabled +sc config shpamsvc start= disabled +sc config UevAgentService start= disabled +sc config MSiSCSI start= disabled +sc config NetTcpPortSharing start= disabled +sc config diagnosticshub.standardcollector.service start= disabled +sc config diagsvc start= disabled +sc config dmwappushservice start= disabled +sc config edgeupdate start= disabled + +::Search + +sc config WSearch start= disabled + +::Remote Desktop Native + +sc config tsusbflt start= disabled +sc config tsusbhub start= disabled +sc config TsUsbGD start= disabled +sc config TermService start= disabled +sc config SessionEnv start= disabled + +::Networking Services + +sc config PNRPsvc start= disabled +sc config p2psvc start= disabled +sc config p2pimsvc start= disabled +sc config PeerDistSvc start= disabled +sc config PerfHost start= disabled +sc config PNRPAutoReg start= disabled +sc config ALG start= disabled +sc config Fax start= disabled +sc config SNMPTrap start= disabled +sc config autotimesvc start= disabled +sc config LanmanWorkstation start= disabled +sc config LanmanServer start= disabled +sc config webthreatdefsvc start= disabled +sc config webthreatdefusersvc_63b8d start= disabled +sc config InventorySvc start= disabled +sc config MapsBroker start= disabled +sc config pla start= disabled + +::VR Services + +sc config perceptionsimulation start= disabled +sc config SharedRealitySvc start= disabled +sc config spectrum start= disabled +sc config MixedRealityOpenXRSvc start= disabled + +::Retail Demo + +sc config RetailDemo start= disabled + +::Virtual Machine + +sc config HvHost start= disabled +sc config vmickvpexchange start= disabled +sc config vmicguestinterface start= disabled +sc config vmicshutdown start= disabled +sc config vmicheartbeat start= disabled +sc config vmicvmsession start= disabled +sc config vmicrdv start= disabled +sc config vmictimesync start= disabled +sc config vmicvss start= disabled +sc config VMAuthdService start=demand +sc config VMnetDHCP start= demand +sc config VMware NAT Service start= demand +sc config VMUSBArbService start= demand +sc config VMwareHostd start= demand +sc config wcncsvc start= disabled +reg add "HKLM\SYSTEM\CurrentControlSet\Services\MessagingService" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKCU\Control Panel\Sound" /v "Beep" /t REG_SZ /d "no" /f + +::Blotware + + +sc config lfsvc start= disabled +sc config GoogleChromeBetaElevationService start= demand +sc config gupdate start= demand +sc config gupdatem start= demand +sc config GamingServices start= demand +sc config sppsvc start= demand +sc config DoSvc start= demand +sc config CDPSvc start= demand +sc config ClickToRunSvc start= demand +sc config DtsApo4Service start= demand +sc config TrkWks start= demand +sc config VacSvc start= disabled +sc config VSStandardCollectorService150 +sc config ss_conn_service start= demand +sc config ss_conn_service2 start= demand +sc config AudioEndpointBuilder start= demand +sc config RpcLocator start= disabled +sc config Sense start= disabled +sc config TapiSrv start= disabled +sc config KtmRm start= disabled +sc config SEMgrSvc start= disabled +sc config SCardSvr start= disabled +sc config ScDeviceEnum start= disabled +sc config AppVClient start= disabled +sc config SysMain start= disabled +sc config SSDPSRV start= disabled +sc config IKEEXT start= demand +sc config FontCache3.0.0.0 start= disabled +sc config WinRM start= disabled +sc config AxInstSV start= disabled +sc config WpcMonSvc start= disabled +sc config pla start= disabled +sc config COMSysApp start= disabled +sc config AGMService start= disabled +sc config AGSService start= disabled +sc stop TroubleshootingSvc +sc config TroubleshootingSvc start=disabled +sc stop MapsBroker +sc config MapsBroker start=disabled +sc stop SysMain +sc config SysMain start=disabled +sc config DusmSvc start= disabled +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpcMonSvc" /v "Start" /t REG_DWORD /d "4" /f + +:: Driver Service 2 +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\rdbss" /v "Start" /t REG_DWORD /d "1" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\pcmcia" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\lltdio" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\hwpolicy" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\vdrvroot" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\tcpipreg" /v "Start" /t REG_DWORD /d "2" / +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\TrustedInstaller" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\srvnet" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\rspndr" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\Schedule" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\ControlSet001\Services\TrkWks" /v "Start" /t REG_DWORD /d "3" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GoogleChromeElevationService" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BcastDVRUserService" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PhoneSvc" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fax" /v "Start" /t REG_DWORD /d "4" /f + +::TabletPC + +sc config SensorDataService start= disabled +sc config SensrSvc start= disabled +sc config SensorService start= disabled +sc config SmsRouter start= disabled +sc config PhoneSvc start= disabled +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DEFRAGSVC" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MessagingService_1c6e8" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\webthreatdefusersvc_77ac1" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MessagingService" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc" /v "Start" /t REG_DWORD /d "2" /f +REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\irmon" /v Start /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AxInstSV" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRM" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\luafv" /v "Start" /t REG_DWORD /d "4" /f + +::Task Disabler +::.net + +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical" /disable + +::ad tms management + +schtasks /Change /TN "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)" /disable +schtasks /Change /TN "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)" /disable + +::Mentenanta + +schtasks /Change /TN "\Microsoft\Windows\Chkdsk\ProactiveScan" /disable +schtasks /Change /TN "\Microsoft\Windows\Chkdsk\SyspartRepair" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery" /disable +schtasks /Change /TN "\Microsoft\Windows\Defrag\ScheduledDefrag" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskCleanup\SilentCleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\FileHistory\File History (maintenance mode)" /disable +schtasks /Change /TN "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE" /disable +schtasks /Change /TN "\Microsoft\Windows\Registry\RegIdleBackup" /disable + +:: telemetry +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\BthSQM" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Consolidator" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" /disable +schtasks /change /TN "\Microsoft\Windows\Autochk\Proxy" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\AitAgent" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\PcaPatchDbTask" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\ProgramDataUpdater" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\StartupAppTask" /disable +schtasks /Change /TN "Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /disable +schtasks /Change /TN "Microsoft\Windows\DiskFootprint\Diagnostics" /disable +schtasks /Change /TN "Microsoft\Windows\Windows Error Reporting\QueueReporting" /disable +schtasks /Change /TN "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem" /disable +schtasks /Change /TN "\Microsoft\Windows\NetTrace\GatherNetworkInfo" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClient" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\Scheduled" /disable +schtasks /Change /TN "\Microsoft\Windows\Application Experience\PcaPatchDbTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Device information\Device" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Setup\Metadata Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" /disable +schtasks /Change /TN "\Microsoft\Windows\Location\Notifications" /disable +schtasks /Change /TN "\Microsoft\Windows\Speech\SpeechModelDownloadTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Maintenance\WinSAT" /disable +schtasks /Change /TN "\Microsoft\Windows\PI\Sqm-Tasks" /disable +del /F /Q "C:\Windows\System32\Tasks\Microsoft\Windows\SettingSync\*" +schtasks /Change /TN "\Microsoft\Windows\AppListBackup\Backup" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Information\Device" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Information\Device User" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Setup\Metadata Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\Scheduled" /disable +schtasks /Change /TN "\Microsoft\Windows\DirectX\DXGIAdapterCache" /disable +schtasks /Change /TN "\Microsoft\Windows\DirectX\DirectXDatabaseUpdater" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskFootprint\Diagnostics" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskFootprint\StorageSense" /disable +schtasks /Change /TN "\Microsoft\Windows\DUSM\dusmtask" /disable +schtasks /Change /TN "\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClient" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\LocalUserSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\MouseSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\PenSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\TouchpadSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\International\Synchronize Language Settings" /disable +schtasks /Change /TN "\Microsoft\Windows\Kernel\La57Cleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\Location\WindowsActionDialog" /disable +schtasks /Change /TN "\Microsoft\Windows\Management\Provisioning\Logon" /disable +schtasks /Change /TN "\Microsoft\Windows\Management\Provisioning\Cellular" /disable +schtasks /Change /TN "\Microsoft\Windows\Maps\MapsToastTask" /disable +schtasks /Change /TN "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents" /disable +schtasks /Change /TN "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic" /disable +schtasks /Change /TN "\Microsoft\Windows\NlaSvc\WiFiTask" /disable +schtasks /Change /TN "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask" /disable +schtasks /Change /TN "\Microsoft\Windows\RetailDemo\CleanupOfflineContent" /disable +schtasks /Change /TN "\Microsoft\Windows\Servicing\StartComponentCleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\Shell\FamilySafetyRefreshTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Shell\FamilySafetyMonitor" /disable +schtasks /Change /TN "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Sysmain\ResPriStaticDbSync" /disable +schtasks /Change /TN "\Microsoft\Windows\SystemRestore\SR" /disable +schtasks /Change /TN "\Microsoft\Windows\TPM\Tpm-HASCertRetr" /disable +schtasks /Change /TN "\Microsoft\Windows\TPM\Tpm-Maintenance" /disable +schtasks /Change /TN "\Microsoft\Windows\UPnP\UPnPHostConfig" /disable +schtasks /Change /TN "\Microsoft\Windows\WlanSvc\CDSSync" /disable +schtasks /Change /TN "\Microsoft\Windows\WwanSvc\NotificationTask" /disable +schtasks /Change /TN "\Microsoft\Windows\WwanSvc\OobeDiscovery" /disable + + +::automatic App Update Windows +schtasks /Change /TN "Microsoft\Windows\WindowsUpdate\Automatic Update" /disable + +:: Office Telemetry Disable + +schtasks /Change /TN "\Microsoft\Office\OfficeTelemetryAgentFallBack2016" /disable +schtasks /Change /TN "\Microsoft\Office\OfficeTelemetryAgentLogOn2016" /disable + + +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange" /disable + +:: Remove Telemetry + +takeown /f C:\Windows\System32\smartscreen.exe +cacls C:\Windows\System32\smartscreen.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\smartscreen.exe" +takeown /f C:\Windows\System32\smartscreenps.dll +cacls C:\Windows\System32\smartscreenps.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\smartscreenps.dll" +takeown /f C:\Windows\System32\DeviceCensus.exe +cacls C:\Windows\System32\DeviceCensus.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\DeviceCensus.exe" +takeown /f C:\Windows\System32\CompatTelRunner.exe +cacls C:\Windows\System32\CompatTelRunner.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\CompatTelRunner.exe" +takeown /f C:\Windows\System32\dmclient.exe +cacls C:\Windows\System32\dmclient.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\dmclient.exe" +takeown /f C:\Windows\hh.exe +cacls C:\Windows\hh.exe /E /P %username%:F +del /F /Q "C:\Windows\hh.exe" +takeown /f C:\Windows\HelpPane.exe +cacls C:\Windows\HelpPane.exe /E /P %username%:F +del /F /Q "C:\Windows\HelpPane.exe" + + +:: Boot Parameters +bcdedit /set allowedinmemorysettings 0 +bcdedit /set hypervisorlaunchtype Off +bcdedit /set tscsyncpolicy Enhanced +bcdedit /set debug No +bcdedit /set isolatedcontext No +bcdedit /set bootmenupolicy Legacy +bcdedit /set usefirmwarepcisettings No +bcdedit /set sos Yes +bcdedit /set x2apicpolicy Enable +bcdedit /set vsmlaunchtype Off +bcdedit /set usephysicaldestination No +bcdedit /set ems No +bcdedit /set firstmegabytepolicy UseAll +bcdedit /set configaccesspolicy Default +bcdedit /set linearaddress57 optin +bcdedit /set noumex Yes +bcdedit /set bootems No +bcdedit /set graphicsmodedisabled No +bcdedit /set extendedinput Yes +bcdedit /set highestmode Yes +bcdedit /set forcefipscrypto No +bcdedit /set perfmem 0 +bcdedit /set clustermodeaddressing 1 +bcdedit /set usefirmwarepcisettings No +bcdedit /set uselegacyapicmode No +bcdedit /set onecpu No +bcdedit /set halbreakpoint No +bcdedit /set forcelegacyplatform No +bcdedit /set tpmbootentropy ForceDisable +bcdedit /timeout 0 +bcdedit /set allowedinmemorysettings 0x0 +bcdedit /set isolatedcontext No +bcdedit /set configaccesspolicy Default +bcdedit /set MSI Default +bcdedit /set usephysicaldestination No +bcdedit /set usefirmwarepcisettings No +bcdedit /set linearaddress57 OptOut +bcdedit /set increaseuserva 268435328 +bcdedit /set firstmegabytepolicy UseAll +bcdedit /set avoidlowmemory 0x8000000 +bcdedit /set nolowmem Yes +bcdedit /set allowedinmemorysettings 0x0 +bcdedit /set vm No +bcdedit /set pae ForceEnable +bcdedit /set useplatformclock No +bcdedit /set {current} recoveryenabled no +bcdedit /create {0cb3b571-2f2e-4343-a879-d86a476d7215} /d +bcdedit /set {bootmgr} bootsequence {0cb3b571-2f2e-4343-a879-d86a476d7215} +bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO,,DISABLE-VBS +bcdedit /set {current} disableelamdrivers yes +bcdedit /set vsmlaunchtype off +bcdedit /set recoveryenabled NO +bcdedit -set NOINTEGRITYCHECKS OFF +bcdedit -set TESTSIGNING OFF +bcdedit /set tscsyncpolicy legacy +bcdedit /set x2apicpolicy enable +bcdedit /set disabledynamictick yes +bcdedit /deletevalue useplatformclock +bcdedit /set useplatformtick yes +bcdedit /set nx AlwaysOff +bcdedit /set bootmenupolicy Legacy + + +:: Copy Files to Windows Folder +xcopy secdrv.sys ""C:\Windows\system32\drivers" /Y +xcopy "*.ico" "C:\Windows" /Y + +:: Mitigation Stuff + +powershell "ForEach($v in (Get-Command -Name \"Set-ProcessMitigation\").Parameters[\"Disable\"].Attributes.ValidValues){Set-ProcessMitigation -System -Disable $v.ToString().Replace(\" \", \"\").Replace(\"`n\", \"\") -ErrorAction SilentlyContinue}" +powershell "Set-ProcessMitigation -System -Enable CFG" +powershell "Set-ProcessMitigation -Name vgc.exe -Enable AuditDynamicCode" +powershell "Set-ProcessMitigation -Name vgc.exe -Enable CFG" +powershell "Set-ProcessMitigation -Name csgo.exe -Disable CFG" +powershell "Set-ProcessMitigation -Name FarCry6.exe -Disable CFG" + +echo Security Tweaks + +Reg add "HKLM\System\CurrentControlSet\Control\Class{4d36e96c-e325-11ce-bfc1-08002be10318}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{4d36e967-e325-11ce-bfc1-08002be10318}" /v "LowerFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{6bdd1fc6-810f-11d0-bec7-08002be2092f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{71a27cdd-812a-11d0-bec7-08002be2092f}" /v "LowerFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{71a27cdd-812a-11d0-bec7-08002be2092f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{ca3e7ab9-b4c3-4ae6-8251-579ef933890f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f + +xcopy "*.exe" "C:\Windows\System32" /Y + + +:: File Remover +takeown /f C:\Windows\System32\GamePanel.exe +cacls C:\Windows\System32\GamePanel.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanel.exe" +takeown /f C:\Windows\System32\wermgr.exe +cacls C:\Windows\System32\wermgr.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\wermgr.exe" +takeown /f C:\Windows\System32\wersvc.dll +cacls C:\Windows\System32\wersvc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\wersvc.dll" +takeown /f C:\Windows\System32\werui.dll +cacls C:\Windows\System32\werui.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werui.dll" +takeown /f C:\Windows\System32\WerEnc.dll +cacls C:\Windows\System32\WerEnc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\WerEnc.dll" +takeown /f C:\Windows\System32\WerFault.exe +cacls C:\Windows\System32\WerFault.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\WerFault.exe" +takeown /f C:\Windows\System32\wercplsupport.dll +cacls C:\Windows\System32\wercplsupport.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\wercplsupport.dll" +takeown /f C:\Windows\System32\werdiagcontroller.dll +cacls C:\Windows\System32\werdiagcontroller.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werdiagcontroller.dll" +takeown /f C:\Windows\System32\lfsvc.dll +cacls C:\Windows\System32\lfsvc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\lfsvc.dll" +takeown /f C:\Windows\System32\WerEnc.dll +cacls C:\Windows\System32\WerEnc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\WerEnc.dll" +takeown /f C:\Windows\System32\werui.dll +cacls C:\Windows\System32\werui.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werui.dll" +takeown /f C:\Windows\System32\WerFaultSecure.exe +cacls C:\Windows\System32\WerFaultSecure.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\WerFaultSecure.exe" +takeown /f C:\Windows\System32\gameux.dll +cacls C:\Windows\System32\gameux.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\gameux.dll" +takeown /f C:\Windows\System32\GamePanelExternalHook.dll +cacls C:\Windows\System32\GamePanelExternalHook.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanelExternalHook.dll" +takeown /f C:\Windows\System32\GamePanel.exe +cacls C:\Windows\System32\GamePanel.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanel.exe" +takeown /f C:\Windows\System32\gamemode.dll +cacls C:\Windows\System32\gamemode.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\gamemode.dll" +takeown /f C:\Windows\System32\GameBarPresenceWriter.exe +cacls C:\Windows\System32\GameBarPresenceWriter.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GameBarPresenceWriter.exe" +takeown /f C:\Windows\System32\zipcontainer.dll +cacls C:\Windows\System32\zipcontainer.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\zipcontainer.dll" +takeown /f C:\Windows\System32\msfeeds.dll +cacls C:\Windows\System32\msfeeds.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\msfeeds.dll" +takeown /f C:\Windows\System32\MsSpellCheckingHost.exe +cacls C:\Windows\System32\MsSpellCheckingHost.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\MsSpellCheckingHost.exe" +takeown /f C:\Windows\System32\ieapfltr.dll +cacls C:\Windows\System32\ieapfltr.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\ieapfltr.dll" +takeown /f C:\Windows\System32\MsSpellCheckingFacility.dll +cacls C:\Windows\System32\MsSpellCheckingFacility.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\MsSpellCheckingFacility.dll" +takeown /f C:\Windows\System32\LocationNotificationWindows.exe +cacls C:\Windows\System32\LocationNotificationWindows.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\LocationNotificationWindows.exe" +takeown /f C:\Windows\System32\msfeedssync.exe +cacls C:\Windows\System32\msfeedssync.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\msfeedssync.exe" +takeown /f C:\Windows\winhlp32.exe +cacls C:\Windows\winhlp32.exe /E /P %username%:F +del /F /Q "C:\Windows\winhlp32.exe" +takeown /f C:\Windows\System32\WpcMon.exe +cacls "C:\Windows\System32\WpcMon.exe" /E /P %username%:F +del /F /Q "C:\Windows\System32\WpcMon.exe" +takeown /f C:\Windows\System32\atieclxx.exe +cacls "C:\Windows\System32\atieclxx.exe" /E /P %username%:F +del /F /Q "C:\Windows\System32\atieclxx.exe" + +:: Windows Error Reporting +Reg.exe add "HKLM\Software\Microsoft\Windows\Windows Error Reporting\Assert Filtering Policy" /v "ReportAndContinue" /t REG_DWORD /d "0" /f +sc delete WerSvc +sc delete wercplsupport + +:: Disable Windows Update Driver Search + +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching" /v "SearchOrderConfig" /t REG_DWORD /d "3" /f +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverMetadata" /v "PreventDeviceMetadataFromNetwork" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\Update" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\Update" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" /v "DontSearchWindowsUpdate" REG_DWORD /d "1" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" /v "DontPromptForWindowsUpdate" REG_DWORD /d "1" /f + +:: Copying SDL in System 32... + +copy "%~dp0\SDL.dll" "C:\Windows\System32\SDL.dll" /Y +copy "%~dp0\SDL.dll" "C:\Windows\SysWOW64\SDL.dll" /Y + +:: Windows Defender Configuration + +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System" /v "EnableSmartScreen" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter" /v "EnabledV9" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender" /v "DisableRoutinelyTakingAction" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\SmartScreen" /v "ConfigureAppInstallControlEnabled" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "1" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "2" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "4" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "5" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\UX Configuration" /v "Notification_Suppress" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v DontReportInfectionInformation /t REG_DWORD /d 1 /f + +netsh Advfirewall set allprofiles state on + + +:: Another Tweaks +for /f %%i in ('Reg query "HKLM\SYSTEM\CurrentControlSet\Services" /s /f DmaRemappingCompatible ^| find /i "Services\" ') do ( +Reg add "%%i" /v "DmaRemappingCompatible" /t Reg_DWORD /d "0" /f ) +reg add "HKU\!USER_SID!\Control Panel\Mouse" /v "SmoothMouseXCurve" /t REG_BINARY /d "0000000000000000c0cc0c0000000000809919000000000040662600000000000033330000000000" /f +reg add "HKU\!USER_SID!\Control Panel\Mouse" /v "SmoothMouseYCurve" /t REG_BINARY /d "0000000000000000000038000000000000007000000000000000a800000000000000e00000000000" /f +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fidelity" /v DisplayName /t reg_sz /d "Melody 12.0 (EAS)" /f +shutdown /r /f /t 0 + + + diff --git a/Melody 12.01 (Script for Windows 11)/fidelityreg_reg11.reg b/Melody 12.01 (Script for Windows 11)/fidelityreg_reg11.reg new file mode 100644 index 0000000..d00b611 --- /dev/null +++ b/Melody 12.01 (Script for Windows 11)/fidelityreg_reg11.reg @@ -0,0 +1,7437 @@ +Windows Registry Editor Version 5.00 + +;001.Optimize GPU Usage (set system and productivity Apps to iGPU) + +[HKEY_CURRENT_USER\Software\Microsoft\DirectX\UserGpuPreferences] +"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"="AutoHDREnable=1;GpuPreference=1;" +"C:\Windows\System32\rundll32.exe"="AutoHDREnable=1;GpuPreference=1;" +"C:\\Windows\\System32\\bdeunlock.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bdechangepin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipDLS.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ScriptRunner.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplySettingsTemplateCatalog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Microsoft.Uev.CscUnpinTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UevAppMonitor.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Microsoft.Uev.SyncController.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chgport.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chgusr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\query.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\logoff.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qappsrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qprocess.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\reset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rwinsta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tscon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tsdiscon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tskill.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\quser.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qwinsta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\baaupdate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\logagent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mfpmp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PackageInspector.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\manage-bde.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PresentationSettings.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AgentService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\repair-bde.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipRenew.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CustomShellHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AssignedAccessGuard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mavinject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BitLockerDeviceEncryption.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpshell.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AppVClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BdeHdCfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CameraSettingsUIHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RemoteAppLifetimeManager.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpsign.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fveprompt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iotstartup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fvenotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WPDShextAutoplay.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BdeUISrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbengine.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MsSpellCheckingHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bootim.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinBioDataModelOOBE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UevAppMonitor.exe.config" +"C:\\Windows\\System32\\AppV\\AppVStreamingUX.exe.config" +"C:\\Windows\\System32\\PresentationHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rstrui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\srdelayed.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SrTasks.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SpaceAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\provlaunch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EduPrintProv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UNPUXHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UNPUXLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UpdateNotificationMgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Spectrum.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SIHClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\xwizard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\takeown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vssadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\where.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cacls.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eventcreate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsavailux.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ftp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\grpconv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runas.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systeminfo.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\taskkill.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tasklist.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\timeout.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\waitfor.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\whoami.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mstsc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TSTheme.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wkspbroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TSWbPrxy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSa.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSaProxy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSaUacHelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sessionmsg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TieringEngineService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpclip.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpinput.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TapiUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dialer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tcmsetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MultiDigiMon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tabcal.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\FsIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dvdplay.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\calc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\charmap.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\credwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\certreq.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\certutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\klist.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ksetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nltest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regini.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regsvr32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setspn.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regedt32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ResetEngine.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SysResetErr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systemreset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemResetPlatform\\SystemResetPlatform.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\migwiz\\mighost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pwlauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fodhelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Fondue.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\OptionalFeatures.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CheckNetIsolation.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msiexec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mblctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msconfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LocationNotificationWindows.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mmc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsActionDialog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cliconfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\odbcad32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\odbcconf.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iscsicpl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iscsicli.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\IESettingSync.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ie4uinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ie4ushowIE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\F12\\IEChooser.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ieUnatt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iexpress.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wextract.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mshta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wiaacmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wiawow64.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bridgeunattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eventvwr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpresult.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpupdate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\esentutl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eudcedit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wecutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\easinvoker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EhStorAuthn.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DpiScaling.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dxpserver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceProperties.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DisplaySwitch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsRemoveDevice.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SyncHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DevicePairingWizard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ComputerDefaults.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DataExchangeHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompMgmtLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\convert.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\find.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ktmutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\label.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\openfiles.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\replace.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Robocopy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\stordiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\choice.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\clip.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\doskey.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\forfiles.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\print.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\subst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cttune.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cttunesvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\help.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msdtc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CastSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserDataSource.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\curl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tar.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spaceman.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spaceutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EDPCleanup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MDMAppInstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ARP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\finger.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\HOSTNAME.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MRINFO.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NETSTAT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ROUTE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sort.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TCPSVCS.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\xcopy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\auditpol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mountvol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\net.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\net1.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netsh.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PATHPING.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PING.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\reg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TRACERT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\attrib.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipUp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskusage.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\findstr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\icacls.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ipconfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CIDiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\comp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\recover.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sdclt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PerceptionSimulation\\PerceptionSimulationService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tcblaunch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\securekernel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SgrmBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SgrmLpac.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\upnpcont.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BioIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NgcIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dusmtask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinBioPlugIns\\FaceFodUninstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GamePanel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GameBarPresenceWriter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\oobeldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\windeploy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\audit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\AuditShD.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MBR2GPT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\Setup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\poqexec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PkgMgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dism\\DismHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmdkey.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dpapimig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LsaIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RmClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecEdit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\icsunattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NetHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmmon32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmstp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmdl32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasautou.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasdial.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasphone.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ntprint.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\printui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceEject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\powercfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sigverif.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\drvinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\hdwwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pnputil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wowreg32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\InfDefault-"="GpuPreference=1;" +"C:\\Windows\\System32\\ndadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\newdev.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\driverquery.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PnPUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\FirstLogonAnim.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\msoobe.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\UserOOBEBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netbtugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netiougc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nbtstat.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NetCfgNotifyObjectHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\djoin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\getmac.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\shrpubw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesAdvanced.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesComputerName.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesDataExecutionPrevention.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesHardware.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesPerformance.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesProtection.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesRemote.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sxstrace.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Sysprep\\sysprep.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSCollect.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSReset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\changepk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LicensingUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\phoneactivate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UpgradeResultsUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GenValObj.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\slui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SppExtComObj.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sppsvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech\\SpeechUX\\SpeechUXWiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\snmptrap.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\immersivetpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rmttpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tpmvscmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\OpenWith.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ThumbnailExtractionHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verclsid.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WallpaperHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\prevhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rundll32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mcbuilder.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MSchedExe.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WUDFCompanionHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WUDFHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AxInstUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\consent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LanguageComponentsInstallerComHandler.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LockAppHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\la57setup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lpk-"="GpuPreference=1;" +"C:\\Windows\\System32\\lpksetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lpremove.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DsmUserTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netcfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runonce.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\secinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\colorcpl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dccw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dism.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\proquota.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserAccountControlSettings.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\shutdown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\efsui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cipher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\edpnotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeCP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rekeywiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dnscacheugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nslookup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lodctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\unlodctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ddodiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\omadmclient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\omadmprc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DmOmaCpMo.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\coredpussvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceEnroller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmcertinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmcfghost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CredentialUIBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SensorDataService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\prproc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Windows.Media.BackgroundPlayback.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sfc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wusa.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\wbemtest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\scrcons.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplyTrustOffline.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CustomInstallExec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\deploymentcsphelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\expand.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ReAgentc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RelPost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MuiUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dxdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fontdrvhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winlogon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DiagSvcs\\DiagnosticsHub.StandardCollector.Service.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\drivers\\ExecutionContext.sys" +"C:\\Windows\\System32\\ucsvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fltMC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lsass.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ntoskrnl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\services.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\smss.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\csrss.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Boot\\winload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AggregatorHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dtdump.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runexehelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdrleakdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wpr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pacjsworker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\userinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wininit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceCensus.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dllhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\conhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\extrac32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\makecab.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\svchost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\compact.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dwm.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dcomcnfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Locator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Com\\MigRegDB.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RpcPing.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mtstocom.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Com\\comrepl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dllhst3g.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setupcl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setupugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wimserv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chkdsk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chkntfs.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wsqmcons.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\autochk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\browser_broker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\browserexport.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Boot\\winresume.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winresume.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bthudtask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsquirt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bitsadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\refsutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidcertstorecheck.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidpolicyconverter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SndVol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidtel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompatTelRunner.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sdbinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pcalua.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\aitstatic.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LaunchTM.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pcaui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Taskmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Utilman.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EaseOfAccessDialog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Narrator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\osk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sethc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AtBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Magnify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EoAExperiences.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CloudExperienceHostBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplicationFrameHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthSystray.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ShellAppRuntime.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\desktopimgdownldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsAdminFlows.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\VSSVC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\convertvhd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wuauclt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotifyIcon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsUpdateElevatedInstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotification.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotificationUx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MoNotificationUx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UsoClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech_OneCore\\common\\SpeechModelDownload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech_OneCore\\common\\SpeechRuntime.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceCredentialDeployment.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LegacyNetUXHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wevtutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dasHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DiskSnapshot.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verifier.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Register-CimProvider.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WinMgmt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WmiPrvSE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winrs.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winrshost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WMIC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSManHTTPConfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wsmprovhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LogonUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mpnotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wlrmdr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskpart.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskraid.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vds.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vdsldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fixmapi.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Netplwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PasswordOnWakeSettingFlyout.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserAccountBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LaunchWinApp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verifiergui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tzsync.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wksprt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\InputSwitchToastHandler.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UIMgrBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ctfmon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\taskhostw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\at.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\schtasks.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MdmDiagnosticsTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\alg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PackagedCWALauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mmgaserver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AuthHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\backgroundTaskHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\VaultCmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\licensingdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CertEnrollCtrl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RuntimeBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BackgroundTransferHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ByteCodeGenerator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WWAHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WaaSMedicAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\upfc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wuapihost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ttdinject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tttracer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sihost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pospaymentsworker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RemotePosWorker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LicenseManagerShellext.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ISM.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchFilterHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchIndexer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchProtocolHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\directxdatabaseupdater.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dispdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Windows.WARP.JITService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dxgiadaptercache.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeSH.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TokenBrokerCookies.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AppHostRegistrationVerifier.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dstokenclean.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinRTNetMUAHostServer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PickerHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\execmodelproxy.dll" +"C:\\Windows\\System32\\ExecModelClient.dll" +"C:\\Windows\\System32\\SystemUWPLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DataStoreCacheDumpTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CredentialEnrollmentManager.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wlanext.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LockScreenContentServer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SlideToShutDown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systray.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RunLegacyCPLElevated.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\control.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fontview.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wifitask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tzutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\w32tm.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmclient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dsregcmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UtcDecoderHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TpmTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\HealthAttestationClientAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TpmInit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CloudNotifications.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\mofcomp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\unsecapp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WMIADAP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WmiApSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_isv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_ssp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_ssp_isv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\printfilterpipelinesvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\provtool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PrintIsolationHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spoolsv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PinEnrollmentBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WpcTok.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WpcMon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApproveChildRequest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ofdeploy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DmNotificationBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MDMAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeBCHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Eap3Host.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bcdboot.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bcdedit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bootsect.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\audiodg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SpatialAudioLicenseSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompPkgSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\agentactivationruntimestarter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\IcsEntitlementHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ShellUpdateAgentTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\XblGameSaveTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\en-US\\notepad.exe.mui" +"C:\\Windows\\System32\\notepad.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TsWpfWrp.exe"="GpuPreference=1;" + +; 002. IRQ Priority + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouclass\Parameters] +"ThreadPriority"=dword:0000001f + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\mouhid\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DXGKrnl\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\USBXHCI\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\USBHUB3\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\amdkmdap\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvlddmkm\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\amd_sata\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BTUSB\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BthLEEnum\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BthHFEnum\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\umbus_A1614B8FA282BCE3\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RTWlanE\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RtkBtManServ\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RtkBtFilter\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\rtump64x64\Parameters] +"ThreadPriority"=dword:0000001f + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl] +"IRQ4294967253Priority"=dword:00000001 +"IRQ4294967254Priority"=dword:00000001 +"IRQ4294967259Priority"=dword:00000001 +"IRQ4294967256Priority"=dword:00000001 +"IRQ4294967257Priority"=dword:00000001 +"IRQ4294967258Priority"=dword:00000001 +"IRQ4294967260Priority"=dword:00000002 +"IRQ4294967261Priority"=dword:00000002 +"IRQ4294967262Priority"=dword:00000001 +"IRQ39Priority"=dword:00000001 +"IRQ1024Priority"=dword:00000001 +"IRQ4294967287Priority"=dword:00000001 +"IRQ4294967288Priority"=dword:00000001 +"IRQ4294967289Priority"=dword:00000001 +"IRQ4294967290Priority"=dword:00000001 +"IRQ4294967291Priority"=dword:00000001 +"IRQ4294967292Priority"=dword:00000001 +"IRQ4294967293Priority"=dword:00000001 +"IRQ4294967294Priority"=dword:00000001 +"IRQ1Priority"=dword:00000001 +"IRQ6Priority"=dword:00000001 +"IRQ7Priority"=dword:00000001 +"IRQ25Priority"=dword:00000001 +"IRQ36Priority"=dword:00000001 +"IRQ55Priority"=dword:00000001 +"IRQ57Priority"=dword:00000001 +"IRQ8Priority"=dword:00000001 +"Win32PrioritySeparation"=dword:00000038 + + +; 003. MMSSVC + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Audio] +"Affinity"=dword:00000007 +"Background Only"="True" +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000006 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Low Latency] +"Affinity"=dword:00000000 +"Background Only"="False" +"BackgroundPriority"=dword:00000000 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000002 +"Scheduling Category"="High" +"SFIO Priority"="High" +"Latency Sensitive"="True" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Audio] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000001 +"Priority"=dword:00000002 +"Scheduling Category"="High" +"SFIO Priority"="High" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Capture] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000005 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\DisplayPostProcessing] +"Affinity"=dword:00000000 +"Background Only"="True" +"BackgroundPriority"=dword:00000008 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000008 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Distribution] +"Affinity"=dword:00000000 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000004 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Playback] +"Affinity"=dword:00000007 +"Background Only"="False" +"BackgroundPriority"=dword:00000004 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000003 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Pro Audio] +"Affinity"=dword:00000007 +"Background Only"="False" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000001 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Window Manager] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000005 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\DisplayPostProcessing] +"Affinity"=dword:00000000 +"Background Only"="True" +"BackgroundPriority"=dword:00000018 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000012 +"Priority"=dword:00000008 +"Scheduling Category"="High" +"SFIO Priority"="High" +"Latency Sensitive"="True" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games] +"Affinity"=dword:00000000 +"Background Only"="False" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000006 +"Scheduling Category"="High" +"SFIO Priority"="High" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile] +"NoLazyMode"=dword:00000001 +"AlwaysOn"=dword:00000001 +"NetworkThrottlingIndex"=dword:ffffffff +"SystemResponsiveness"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider] +"RestoreConnection"=dword:00000001 +"WakeUp"=dword:00000000 + +; 004. Contextual Menu + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay] +"Icon"="display.dll,-1" +"MUIVerb"="Turn off display" +"Position"="Bottom" +"SubCommands"="" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\01menu] +"Icon"="powercpl.dll,-513" +"MUIVerb"="Turn off display" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\01menu\command] +@="nircmd.exe cmdwait 1000 monitor async_off" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\02menu] +"MUIVerb"="Lock computer and Turn off display" +"CommandFlags"=dword:00000020 +"Icon"="imageres.dll,-59" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\02menu\command] +@="cmd /c \"nircmd.exe cmdwait 1000 monitor async_off & rundll32.exe user32.dll, LockWorkStation\"" + + + +[HKEY_CLASSES_ROOT\exefile\shell\Priority] +"MUIVerb"="Run with priority" +"SubCommands"="" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\001flyout] +@="Realtime" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\001flyout\command] +@="cmd.exe /c start \"\" /Realtime \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\002flyout] +@="High" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\002flyout\command] +@="cmd.exe /c start \"\" /High \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\003flyout] +@="Above normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\003flyout\command] +@="cmd.exe /c start \"\" /AboveNormal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\004flyout] +@="Normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\004flyout\command] +@="cmd.exe /c start \"\" /Normal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\005flyout] +@="Below normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\005flyout\command] +@="cmd.exe /c start \"\" /BelowNormal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\006flyout] +@="Low" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\006flyout\command] +@="cmd.exe /c start \"\" /Low \"%1\"" + + + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shell\Windows.PermanentDelete] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E9571AB2-AD92-4ec6-8924-4E5AD33790F5}" +"Icon"="shell32.dll,-240" +"Position"="Bottom" + + + +[HKEY_CLASSES_ROOT\Msi.Package\shell\Extract\command] +@="msiexec.exe /a \"%1\" /qb TARGETDIR=\"%1 Contents\"" + + +[HKEY_CLASSES_ROOT\VBSFile\Shell\runas\command] +@="C:\\Windows\\System32\\WScript.exe \"%1\" %*" + + +[HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\batfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\cmdfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\docxfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\fonfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\htmlfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\inffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\inifile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\JSEFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\otffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\pfmfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\regfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\rtffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\ttcfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\ttffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\txtfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\VBEFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\VBSFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\WSFFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash] +"MUIVerb"="Hash" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\01SHA1] +"MUIVerb"="SHA1" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\01SHA1\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA1 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\02SHA256] +"MUIVerb"="SHA256" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\02SHA256\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA256 | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\03SHA384] +"MUIVerb"="SHA384" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\03SHA384\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA384 | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\04SHA512] +"MUIVerb"="SHA512" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\04SHA512\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA512 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\05MACTripleDES] +"MUIVerb"="MACTripleDES" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\05MACTripleDES\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm MACTripleDES | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\06MD5] +"MUIVerb"="MD5" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\06MD5\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm MD5 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\07RIPEMD160] +"MUIVerb"="RIPEMD160" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\07RIPEMD160\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm RIPEMD160 | format-list" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\UEV\Agent] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WorkFolders] +"AutoProvision"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRE] +"DisableSetup"=dword:00000001 + +[HKEY_CLASSES_ROOT\*\shell\TakeOwnership] +@="Take Ownership" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"NeverDefault"="" + +[HKEY_CLASSES_ROOT\*\shell\TakeOwnership\command] +@="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l' -Verb runAs\"" +"IsolatedCommand"= "powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\Directory\shell\TakeOwnership] +@="Take Ownership" +"AppliesTo"="NOT (System.ItemPathDisplay:=\"C:\\Users\" OR System.ItemPathDisplay:=\"C:\\ProgramData\" OR System.ItemPathDisplay:=\"C:\\Windows\" OR System.ItemPathDisplay:=\"C:\\Windows\\System32\" OR System.ItemPathDisplay:=\"C:\\Program Files\" OR System.ItemPathDisplay:=\"C:\\Program Files (x86)\")" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"Position"="middle" + +[HKEY_CLASSES_ROOT\Directory\shell\TakeOwnership\command] +@="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" /r /d y && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l /q' -Verb runAs\"" +"IsolatedCommand"="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" /r /d y && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l /q' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\Drive\shell\runas] +@="Take Ownership" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"Position"="middle" +"AppliesTo"="NOT (System.ItemPathDisplay:=\"C:\\\")" + +[HKEY_CLASSES_ROOT\Drive\shell\runas\command] +@="cmd.exe /c takeown /f \"%1\\\" /r /d y && icacls \"%1\\\" /grant *S-1-3-4:F /t /c" +"IsolatedCommand"="cmd.exe /c takeown /f \"%1\\\" /r /d y && icacls \"%1\\\" /grant *S-1-3-4:F /t /c" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart] +"Icon"="shell32.dll,-16739" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\001flyout] +"MUIVerb"="Force apps to close, and full shutdown and restart PC with no time-out or warning" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\001flyout\command] +@="shutdown /r /f /t 0" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\002flyout] +"MUIVerb"="Full shutdown and restart PC with warning" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\002flyout\command] +@="shutdown /r" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\003flyout] +"MUIVerb"="Full shutdown and restart PC. After rebooted, restart any opened registered apps." +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\003flyout\command] +@="shutdown /g /t 0" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\004flyout] +"MUIVerb"="Restart to Advanced Startup Options" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\004flyout\command] +@="shutdown /r /o /f /t 0" + + +[-HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs] + +[HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs] +@="Install" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs\Command] +@="cmd /k dism /online /add-package /packagepath:\"%1\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars] +"MUIVerb"="Environment variables" +"Icon"="sysdm.cpl,-1" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\01UserVars] +"MUIVerb"="User variables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\01UserVars\Command] +@="rundll32.exe sysdm.cpl,EditEnvironmentVariables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\02SystemVars] +"HasLUAShield"="" +"MUIVerb"="System variables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\02SystemVars\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process rundll32 -ArgumentList '/s,/c, sysdm.cpl,EditEnvironmentVariables' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\*\shell\Copy Content to Clipboard] +"MUIVerb"="Copy Content to Clipboard" +"Icon"="DxpTaskSync.dll,-52" +"Position"="Center" + +[HKEY_CLASSES_ROOT\*\shell\Copy Content to Clipboard\Command] +@="cmd /c clip < \"%1\"" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Safely Remove Hardware] +"MUIVerb"="Safely Remove Hardware" +"Icon"="hotplug.dll,-100" +"Position"="Center" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Safely Remove Hardware\Command] +@="C:\\Windows\\system32\\control.exe hotplug.dll" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall] +"MUIVerb"="Windows Firewall" +"Icon"="FirewallControlPanel.dll,-1" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command001] +"MUIVerb"="Windows Firewall" +"Icon"="FirewallControlPanel.dll,-1" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command001\Command] +@="RunDll32.exe shell32.dll,Control_RunDLL firewall.cpl" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command002] +"MUIVerb"="Windows Firewall with Advanced Security" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command002\Command] +@="mmc.exe /s wf.msc" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command003] +"MUIVerb"="Configure Allowed Apps" +"Icon"="FirewallControlPanel.dll,-1" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command003\Command] +@="explorer.exe shell:::{4026492F-2F69-46B8-B9BF-5654FC07E423} -Microsoft.WindowsFirewall\\pageConfigureApps" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command004] +"MUIVerb"="Turn On Windows Firewall" +"HasLUAShield"="" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command004\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall set allprofiles state on' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command005] +"MUIVerb"="Turn Off Windows Firewall" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command005\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall set allprofiles state off' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command006] +"MUIVerb"="Reset Windows Firewall" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command006\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall reset' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\KillNRTasks] +"icon"="taskmgr.exe,-30651" +"MUIverb"="Kill all not responding tasks" +"Position"="Top" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\KillNRTasks\command] +@="CMD.exe /C taskkill.exe /f /fi \"status eq Not Responding\" & Pause" + + +[HKEY_CURRENT_USER\Software\Classes\*\shellex\ContextMenuHandlers\PintoStartScreen] +@="{470C0EBD-5D73-4d58-9CED-E91E22E23282}" + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex\ContextMenuHandlers] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex\ContextMenuHandlers\PintoStartScreen] +@="{470C0EBD-5D73-4d58-9CED-E91E22E23282}" + + + +[-HKEY_CLASSES_ROOT\DesktopBackground\Shell\AdvancedBootOptions] + + +[HKEY_CLASSES_ROOT\*\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + +[HKEY_CLASSES_ROOT\Directory\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shell\windows.copyaspath] +"CanonicalName"="{707C7BC6-685A-4A4D-A275-3966A5A3EFAA}" +"CommandStateHandler"="{3B1599F9-E00A-4BBF-AD3E-B3F99FA87779}" +"CommandStateSync"="" +"Description"="@shell32.dll,-30336" +"Icon"="imageres.dll,-5302" +"InvokeCommandOnSelection"=dword:00000001 +"MUIVerb"="@shell32.dll,-30329" +"VerbHandler"="{f3d06e7c-1e45-4a26-847e-f9fcdee59be0}" +"VerbName"="copyaspath" + +[HKEY_CLASSES_ROOT\Drive\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + + +; 1.6. Restart File Explorer + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer] +"icon"="explorer.exe" +"Position"="Center" +"SubCommands"="" +"MUIVerb"="Restart/Pause File Explorer " + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\01menu] +"MUIVerb"="Restart File Explorer" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\01menu\command] +@="cmd.exe /c taskkill /f /im explorer.exe & start explorer.exe" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\02menu] +"MUIVerb"="Pause File Explorer" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\02menu\command] +@="cmd.exe /c @echo off & echo. & echo Stopping explorer.exe process . . . & echo. & taskkill /f /im explorer.exe & echo. & echo. & echo Waiting to start explorer.exe process when you are ready . . . & pause && start explorer.exe && exit" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\DismContextMenu] +"Icon"="WmiPrvSE.exe" +"MUIVerb"="Repair Windows Image" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\CheckHealth] +"HasLUAShield"="" +"MUIVerb"="Check Health of Windows Image" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\CheckHealth\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, Dism /Online /Cleanup-Image /CheckHealth' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\RestoreHealth] +"HasLUAShield"="" +"MUIVerb"="Repair Windows Image" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\RestoreHealth\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, Dism /Online /Cleanup-Image /RestoreHealth' -Verb runAs\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions] +"HasLUAShield"="" +"MUIVerb"="Check for Corruptions" + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, sfc.exe /scannow' -Verb runAs\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions_log] +"HasLUAShield"="" +"MUIVerb"="View Scan Logs" + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions_log\command] +@="PowerShell (Select-String [SR] $env:windir\\Logs\\CBS\\CBS.log -s).Line >\"$env:userprofile\\Desktop\\SFC_LOG.txt\"" + + + +;; 1.2.Windows Terminal + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked] +"{9F156763-7844-4DC4-B2B1-901F640F5155}"="" + +[HKEY_CLASSES_ROOT\Directory\shell\OpenWindowsTerminalProfiles] +"MUIVerb"="Open in Windows Terminal" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile] +"MUIVerb"="Default Profile" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile\command] +@="cmd.exe /c start wt.exe -d \"%1\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile] +"MUIVerb"="Command Prompt" +"Icon"="imageres.dll,-5323" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile\command] +@="cmd.exe /c start wt.exe -p \"Command Prompt\" -d \"%1\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile] +"MUIVerb"="PowerShell" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile\command] +@="cmd.exe /c start wt.exe -p \"Windows PowerShell\" -d \"%1\"" + +[HKEY_CLASSES_ROOT\Directory\Background\shell\OpenWindowsTerminalProfiles] +"MUIVerb"="Open in Windows Terminal" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile] +"MUIVerb"="Default Profile" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile\command] +@="cmd.exe /c start wt.exe -d \"%V\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile] +"MUIVerb"="Command Prompt" +"Icon"="imageres.dll,-5323" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile\command] +@="cmd.exe /c start wt.exe -p \"Command Prompt\" -d \"%V\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile] +"MUIVerb"="PowerShell" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile\command] +@="cmd.exe /c start wt.exe -p \"Windows PowerShell\" -d \"%V\"" + + +; 1.2.1 Windows Terminal for Directory + +[HKEY_CLASSES_ROOT\Directory\shell\WindowsTerminalAsAdmin] +"HasLUAShield"="" +"MUIVerb"="Open in Windows Terminal as Administrator" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile] +"MUIVerb"="Open in Windows Terminal as Administrator - Default Profile" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\02Cmd] +"MUIVerb"="Open in Windows Terminal as Administrator - Command Prompt" +"Icon"="imageres.dll,-5324" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\02Cmd\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Command Prompt\"\"\"','-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\03PS] +"MUIVerb"="Open in Windows Terminal as Administrator - PowerShell" +"HasLUAShield"="" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\03PS\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Windows PowerShell\"\"\"','-d','.')\"" + +; Directory\Background + +[HKEY_CLASSES_ROOT\Directory\Background\shell\WindowsTerminalAsAdmin] +"HasLUAShield"="" +"MUIVerb"="Open in Windows Terminal as Administrator" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile] +"MUIVerb"="Open in Windows Terminal as Administrator - Default Profile" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\02Cmd] +"MUIVerb"="Open in Windows Terminal as Administrator - Command Prompt" +"Icon"="imageres.dll,-5324" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\02Cmd\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Command Prompt\"\"\"','-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\03PS] +"MUIVerb"="Open in Windows Terminal as Administrator - PowerShell" +"HasLUAShield"="" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\03PS\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Windows PowerShell\"\"\"','-d','.')\"" + +;005. Removal of Components in Registry + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HomeFolderDesktop\NameSpace\DelegateFolders\{3134ef9c-6b18-4996-ad04-ed5912e00eb5}] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\HomeFolderDesktop\NameSpace\DelegateFolders\{3134ef9c-6b18-4996-ad04-ed5912e00eb5}] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Play] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Play] + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\Windows.IsoFile\shell\burn] + +[-HKEY_CLASSES_ROOT\MediaCenter.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.DVR-MSFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3G2\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3GP\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ADTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AIFF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AU\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AVI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.FLAC\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M2TS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.m3u\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M4A\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MIDI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MK3D\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MOV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP3\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP4\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MPEG\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.TTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WPL\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WVX\shell\Enqueue] + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpeg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpe\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.png\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.gif\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.tif\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.tiff\Shell\3D Edit] + +[-HKEY_CLASSES_ROOT\Directory\Background\shell\WSL] + +[-HKEY_CLASSES_ROOT\Directory\shell\WSL] + +[-HKEY_CLASSES_ROOT\Drive\shell\WSL] + +[-HKEY_CLASSES_ROOT\MediaCenter.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.DVR-MSFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3G2\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3GP\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ADTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AIFF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AU\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AVI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.FLAC\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M2TS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.m3u\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M4A\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MIDI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MK3D\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MOV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP3\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP4\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MPEG\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.TTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WPL\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WVX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\*\shell\UpdateEncryptionSettingsWork] + +[-HKEY_CLASSES_ROOT\Directory\shell\UpdateEncryptionSettings] + +[HKEY_CLASSES_ROOT\IE.AssocFile.URL\ShellEx\ContextMenuHandlers\{09799AFB-AD67-11d1-ABCD-00C04FC30936}] + +[-HKEY_CLASSES_ROOT\Drive\shell\Optimize using PerfectDisk] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\print] + +[-HKEY_CLASSES_ROOT\batfile\shell\print] + +[-HKEY_CLASSES_ROOT\cmdfile\shell\print] + +[-HKEY_CLASSES_ROOT\docxfile\shell\print] + +[-HKEY_CLASSES_ROOT\fonfile\shell\print] + +[-HKEY_CLASSES_ROOT\htmlfile\shell\print] + +[-HKEY_CLASSES_ROOT\inffile\shell\print] + +[-HKEY_CLASSES_ROOT\inifile\shell\print] + +[-HKEY_CLASSES_ROOT\JSEFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\otffile\shell\print] + +[-HKEY_CLASSES_ROOT\pfmfile\shell\print] + +[-HKEY_CLASSES_ROOT\regfile\shell\print] + +[-HKEY_CLASSES_ROOT\rtffile\shell\print] + +[-HKEY_CLASSES_ROOT\ttcfile\shell\print] + +[-HKEY_CLASSES_ROOT\ttffile\shell\print] + +[-HKEY_CLASSES_ROOT\txtfile\shell\print] + +[-HKEY_CLASSES_ROOT\VBEFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\VBSFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\WSFFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\Drive\shell\unlock-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\manage-bde] + + + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\SendTo] +@="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\*\shell\UpdateEncryptionSettingsWork] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\Directory\shell\UpdateEncryptionSettings] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked] +"{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}"="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\Folder\ShellEx\ContextMenuHandlers\Library Location] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Drive\shell\change-passphrase] + +[-HKEY_CLASSES_ROOT\Drive\shell\change-pin] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\Drive\shell\encrypt-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\encrypt-bde-elev] + +[-HKEY_CLASSES_ROOT\Drive\shell\manage-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\resume-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\resume-bde-elev] + +[-HKEY_CLASSES_ROOT\Drive\shell\unlock-bde] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ModernSharing] + +[-HKEY_CLASSES_ROOT\Directory\Background\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\PropertySheetHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\LibraryFolder\background\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\CLSID\{09A47860-11B0-4DA5-AFA5-26D86198A780}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\DesktopBackground\Shell\ControlledFolderAccess] + +[-HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications] +"Windows Photo Viewer"="-" + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Photo Viewer\Capabilities] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Bitmap] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.JFIF] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Jpeg] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Png] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Wdp] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\photoviewer.dll] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DiagnosticLogCSP] + + +;006. Add Files for NEW Menu + + +[HKEY_CLASSES_ROOT\.cpp\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.c\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.py\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.js\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.code\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.aup\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.php\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.cmd\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.ini\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.ini\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.reg\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.txt\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.bat\ShellNew] +"NullFile"="" +"ItemName"=hex(2):40,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ + 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ + 00,61,00,63,00,70,00,70,00,61,00,67,00,65,00,2e,00,64,00,6c,00,6c,00,2c,00,\ + 2d,00,36,00,30,00,30,00,32,00,00,00 + +[HKEY_CLASSES_ROOT\.html\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.vbs\ShellNew] +"NullFile"="" +"ItemName"=hex(2):40,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\ + 73,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,73,\ + 00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,34,00,38,00,\ + 30,00,32,00,00,00 + + +; 007. App Priority + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acrobat.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acrobat.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acrotray.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acrotray.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Among Us.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Among Us.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\audiodg.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\audiodg.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BananaBugs.exe] +"MaxLoaderThreads"=dword:00000002 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BananaBugs.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bitwarden.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bitwarden.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BlueMail.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BlueMail.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bookworm.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bookworm.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\candycrushsaga.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\candycrushsaga.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe] +"MaxLoaderThreads"=dword:00000004 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Chuzzle.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Chuzzle.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CIU.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CIU.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\converter.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\converter.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csgo.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csgo.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrss.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrss.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cyberpunk2077.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cyberpunk2077.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discord.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discord.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ditto.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ditto.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DoomEternalx64vk.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DoomEternalx64vk.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DragonCity.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DragonCity.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwm.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwm.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EABackgroundService.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EABackgroundService.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EarTrumpet.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EarTrumpet.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eurotrucks2.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eurotrucks2.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ext2Srv.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FarCry6.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fontdrvhost.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FortniteClient-Win64-Shipping.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FortniteClient-Win64-Shipping.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon3.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon3.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon4.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon4.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon5.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon5.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\game] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\game\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GameOverlayUI.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GameOverlayUI.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GeometryDash.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GeometryDash.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyCtrl.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyCtrl.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyHelp32.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyHelp64.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc32.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc32.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc64.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc64.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-iii.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-iii.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-lc.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-lc.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-sa.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-sa.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-vc.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-vc.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GTAV.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GTAV.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IDMan.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IDMan.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iScrRec.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iScrRec.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lghub_updater.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lghub_updater.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightroom.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightroom.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightshot.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightshot.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ludo King.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ludo King.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MegaRun-WinStore.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MegaRun-WinStore.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\metin2client.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\metin2client.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly_Plus.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly_Plus.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpc-hc64.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe] +"MaxLoaderThreads"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Muck.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Muck.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysummercar.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysummercar.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Notepad++.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Notepad++.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NVDisplay.Container.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfficeClickToRun.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfficeClickToRun.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe] +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\operagx.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\operagx.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photoshop.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photoshop.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PizzaFrenzy.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PizzaFrenzy.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlantsVsZombies.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlantsVsZombies.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlayGtaV.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlayGtaV.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rambox.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rambox.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVCpl64.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re6.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re6.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re7.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re7.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re8.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re8.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Resolve.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Resolve.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RuntimeBroker.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RuntimeBroker.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ShellExperienceHost.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SnowRunner.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SnowRunner.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SonicMania.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SonicMania.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Spotify.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Spotify.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SpotifyStartupTask.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SpotifyStartupTask.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11Srv.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11Srv.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11_64.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11_64.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Steam.exe] +"MaxLoaderThreads"=dword:00000001 +"mpc-hc64.exe"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Steam.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steamwebhelper.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steamwebhelper.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Teams.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Teams.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Terraria.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Terraria.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2_BE.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2_BE.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Update.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Update.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vgc.exe] +"MitigationOptions"=hex:00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VideoEditorPlus.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VideoEditorPlus.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WheresMyWater2.WindowsStore.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WheresMyWater2.WindowsStore.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinBM.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinBM.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WmiPrvSE.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WmiPrvSE.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zoom.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zoom.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + + +; 008. Connections + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] +"explorer.exe"=dword:00000002 +"sllauncher.exe"=dword:00000006 +"winword.exe"=dword:0000000d +"mspub.exe"=dword:0000000d +"powerpnt.exe"=dword:0000000d +"outlook.exe"=dword:0000000d +"onenote.exe"=dword:0000000d +"excel.exe"=dword:0000000d +"msaccess.exe"=dword:0000000d +"csgo.exe"=dword:0000000d +"jaraw.exe"=dword:0000000d +"chrome.exe"=dword:0000000d +"msedge.exe"=dword:0000000d +"edge.exe"=dword:0000000d +"opera.exe"=dword:0000000d +"firefox.exe"=dword:0000000d + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] +"explorer.exe"=dword:00000002 +"sllauncher.exe"=dword:00000006 +"winword.exe"=dword:0000000d +"mspub.exe"=dword:0000000d +"powerpnt.exe"=dword:0000000d +"outlook.exe"=dword:0000000d +"onenote.exe"=dword:0000000d +"excel.exe"=dword:0000000d +"msaccess.exe"=dword:0000000d +"csgo.exe"=dword:0000000d +"jaraw.exe"=dword:0000000d +"chrome.exe"=dword:0000000d +"msedge.exe"=dword:0000000d +"edge.exe"=dword:0000000d +"opera.exe"=dword:0000000d +"firefox.exe"=dword:0000000d + + +;009. +20GB Disk Space + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power] +"HibernateEnabled"=dword:00000000 +"HiberbootEnabled"=dword:00000000 +"ExitLatency "=dword:00000001 +"DisableVsyncLatencyUpdate"=dword:00000001 +"DisableSensorWatchdog"=dword:00000001 +"ExitLatencyCheckEnabled"=dword:00000001 +"Latency"=dword:00000001 +"LatencyToleranceDefault"=dword:00000000 +"LatencyToleranceFSVP"=dword:00000000 +"LatencyToleranceIdleResiliency"=dword:00000000 +"LatencyTolerancePerfOverride"=dword:00000000 +"LatencyToleranceScreenOffIR"=dword:00000000 +"LatencyToleranceVSyncEnabled"=dword:00000000 +"RtlCapabilityCheckLatency "=dword:00000001 +"MfBufferingThreshold"=dword:00000000 +"CoalescingTimerInterval"=dword:00000000 +"CsEnabled"=dword:00000000 +"EnergyEstimationEnabled"=dword:00000000 +"PerfCalculateActualUtilization"=dword:00000000 +"SleepReliabilityDetailedDiagnostics"=dword:00000000 +"EventProcessorEnabled"=dword:00000000 +"QosManagesIdleProcessors"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management] +"PagingFiles"=hex(7):00,00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager] +"ShippedWithReserves"=dword:00000000 +"PassedPolicy"=dword:00000000 + + +;010. Realtek HDA Tweaks + +[HKEY_CURRENT_USER\Software\Realtek\Audio\RtkNGUI64\General] +"JDPopup"=dword:00000001 +"CplExecuted_104386C7_104386C7"=dword:00000001 +"LastFixDefaultTime"=hex:e2,07,0c,00,02,00,04,00,00,00,20,00,33,00,fd,00 +"RenderDefaultFixed"=dword:00000001 +"CaptureDefaultFixed"=dword:00000001 +"Language"=dword:00000000 +"CplExecuted_103C830C_103C830C"=dword:00000001 +"AutoSelectChannelByJackConf"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Realtek\Audio\RtkNGUI64\PowerMgnt] +"Enabled"=dword:00000001 +"DelayTime"=dword:00000003 +"OnlyBattery"=dword:00000000 +"PowerState"=dword:00000000 + +;011. Disable System Restore + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] +"DisableSR"=dword:00000001 + +;012. Add Open With.. for URL Files + + +[HKEY_CLASSES_ROOT\IE.AssocFile.URL\ShellEx\ContextMenuHandlers\{09799AFB-AD67-11d1-ABCD-00C04FC30936}] + +;013. Prefetch Disable + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters] +"EnablePrefetcher"=dword:00000000 +"EnableSuperfetch"=dword:00000000 +"BootId"=- +"BaseTime"=- + +;014. Disable Keyboard shortcuts with Accesibility + + +[HKEY_CURRENT_USER\Control Panel\Accessibility\HighContrast] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\Keyboard Response] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\MouseKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\SoundSentry] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\StickyKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\TimeOut] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\ToggleKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\SlateLaunch] +"ATapp"=- + +[HKEY_CURRENT_USER\Control Panel\Accessibility\TimeOut] +"Flags"="0" + + +;015. Disable Animation and Transparency + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects] +"VisualFxSetting"=dword:00000003 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"DITest"=dword:00000000 + +[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\DWM] +"CompositionPolicy"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\DWM] +"CompositionPolicy"=dword:00000000 + + +[HKEY_USERS\.DEFAULT\Control Panel\Desktop] +"ForegroundLockTimeout"=dword:00000000 +"MenuShowDelay"="0" +"MouseWheelRouting"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] +"DesktopHeapLogging"=dword:00000000 +"DwmInputUsesIoCompletionPort"=dword:00000000 +"EnableDwmInputProcessing"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Dwm] +"AnimationAttributionEnabled"=dword:00000000 +"AnimationAttributionHashingEnabled"=dword:00000000 +"OneCoreNoBootDWM"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Dwm] +"ForceEffectMode"=- + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DWM] +"DWMWA_TRANSITIONS_FORCEDISABLED"=dword:00000001 +"DisallowFlip3d"=dword:00000001 +"DisallowColorizationColorChanges"=dword:00000001 +"DisallowAnimations"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\DWM] +"Composition"=dword:00000000 +"EnableAeroPeek"=dword:00000000 +"AlwaysHibernateThumbnails"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\International] +"s1159"="AM" +"s2359"="PM" +"sCurrency"="$" +"sDate"="." +"sDecimal"="," +"sGrouping"="3;0" +"sList"="." +"sLongDate"="dddd, dd.MM.yyyy" +"sMonDecimalSep"="." +"sMonGrouping"="3;0" +"sMonThousandSep"="," +"sNativeDigits"="0123456789" +"sNegativeSign"="-" +"sPositiveSign"="" +"sShortDate"="dd.MM.yyyy" +"sThousand"="." +"sTime"=":" +"sTimeFormat"="HH:mm:ss" +"sShortTime"="HH:mm" +"iFirstDayOfWeek"="0" +"iLZero"="1" +"iMeasure"="0" +"iNegCurr"="0" + +[HKEY_CURRENT_USER\Control Panel\Desktop] +"DragFullWindows"="1" +"FontSmoothing"="2" +"FontSmoothingType"=dword:00000002 +"MenuShowDelay"="0" +"UserPreferencesMask"=hex:90,12,01,80,10 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize] +"EnableTransparency"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager] +"ThemeActive"="0" + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MultitaskingView\AllUpView] +"AllUpView"=dword:00000000 +"Remove TaskView"=dword:00000001 + + +[HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics] +"PaddedBorderWidth"="0" + +[HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics] +"MinAnimate"="0" +"MaxAnimate"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE] +"DisableExternalDMAUnderLock"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability] +"TimeStampInterval"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"DisableThumbnails"=- + +[HKEY_CLASSES_ROOT\*] +"DefaultDropEffect"=dword:00000001 + +[HKEY_CLASSES_ROOT\AllFilesystemObjects] +"DefaultDropEffect"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] +"ThumbnailQuality"=dword:00000032 +"SmartScreenEnabled"="Off" +"NoPreviousVersionsPage"=dword:00000001 +"HubMode"=dword:00000001 +"Max Cached Icons"="4096" +"EnableAutoTray"=dword:00000001 +"DesktopProcess"=dword:00000001 +"ShowRecent"=dword:00000000 +"ShowFrequent"=dword:00000000 + +;016. DirectX API Optimization + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000000 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +;018. Microsoft Windows's Keylogger Disable + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AppModel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Cellcore] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Circular Kernel Context Logger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\CloudExperienceHostOobe] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DataMarket] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DiagLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\HolographicDevice] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\iclsClient] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\iclsProxy] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\LwtNetLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Mellanox-Kernel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Microsoft-Windows-AssignedAccess-Trace] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Microsoft-Windows-Setup] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\NBSMBLOGGER] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\PEAuthLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\RdrLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\ReadyBoot] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SetupPlatform] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SetupPlatformTel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SocketHeciServer] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SpoolerLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SQMLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TCPIPLOGGER] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TileStore] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Tpm] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TPMProvisioningService] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\UBPM] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WFP-IPsec Trace] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiDriverIHVSession] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiDriverIHVSessionRepro] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiSession] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WinPhoneCritical] +"Start"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\PwdlessAggregator] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\PwdlessAggregator\{fb3cd94d-95ef-5a73-b35c-6c78451095ef}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{025d2741-697b-5e0e-7e77-9a36140251f7}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{2504bc27-0e8b-5fed-7a9f-d86972086285}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{46b13027-2dfd-46e1-832d-e41e2810e6e5}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{59dd67cc-7ce1-52f8-cf74-fe8a257a2b6b}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{a8b932c2-51ec-5c22-63fc-0115fd79b9e0}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{cee50f59-e321-4691-9bb7-9b75494f6aab}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{d48679eb-8aa3-4138-be24-f1648C874e49}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{025d2741-697b-5e0e-7e77-9a36140251f7}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{59dd67cc-7ce1-52f8-cf74-fe8a257a2b6b}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{a8b932c2-51ec-5c22-63fc-0115fd79b9e0}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{e77a560c-3696-4ac0-911c-545ceca6be3c}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{18D6CBEB-1E21-500A-27E2-8BA2BEAC7C00}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{3D6120A6-0986-51C4-213A-E2975903051D}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{59DD67CC-7CE1-52F8-CF74-FE8A257A2B6B}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{8BE48F34-1F58-4180-8C12-DBE6E6E71A81}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{AC8D9176-9E0-5047-9B60-1AABC45281B8}] +"Enabled"=dword:00000000 +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{B39B8CEA-EAAA-5A74-5794-4948E222C663}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{BBC9A2C9-EEED-58D4-9483-6C87118F9EC6}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{CEE50F59-E321-4691-9BB7-9B75494F6AAB}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{D059A021-6947-44FB-976A-B18C9B73D1D8}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{1377561d-9312-452c-ad13-c4a1c9c906e0}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{1a1dfad0-6d37-5521-1d72-1f87dd20423c}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{3E0D88DE-AE5C-438A-BB1C-C2E627F8AECB}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{76AD4308-DF7C-5F43-E668-FCEA4FA1179D}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{b6acef34-fab6-5909-6b6b-b1c2cc84057f}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{D1094A14-063E-7A21-A301-F2FE3BA23F62}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{EC4BA041-1DFE-5F76-EF6D-0251DA19D178}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Host] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Host\0] +"Status"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\PwdlessAggregator] +"HbStart"=dword:00000000 +"HbStop"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdateHeartbeatScan] + +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdatePolicyScenarioReliabilityAggregator] +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdateReboot] +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UusFailover] +"HbStart"=dword:00000000 + + +;019. Disable Telemetry + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppV\CEIP] +"CEIPEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\FirewallAPI] +"Active"=dword:00000000 +"ControlFlags"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\PlugPlay\SETUPAPI] +"Active"=dword:00000000 +"ControlFlags"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\SCM\Regular] +"TracingDisabled"=dword:00000001 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\AsimovUploader] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventMonitors] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling] +"PowerThrottlingOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\EnergyEstimation\TaggedEnergy] +"DisableTaggedEnergyLogging"=dword:00000001 +"TelemetryMaxApplication"=dword:00000000 +"TelemetryMaxTagPerApplication"=dword:00000000 + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection] +"AllowTelemetry"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CloudContent] +"DisableWindowsConsumerFeatures"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Narrator\NoRoam] +"WinEnterLaunchEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorPort] +"TelemetryPerformanceEnabled"=dword:00000000 +"TelemetryErrorDataEnabled"=dword:00000000 +"Tele­metry­DeviceHealthEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub\hubg] +"DisableOnSoftRemove"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction] +"Enable"="N" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl] +"AutoReboot"=dword:00000000 +"CrashDumpEnabled"=dword:00000000 +"DumpFile"=hex(2):70,00,75,00,6c,00,61,00,00,00 +"DumpLogLevel"=dword:00000000 +"EnableLogFile"=dword:00000000 +"LogEvent"=dword:00000000 +"MinidumpDir"=hex(2):70,00,75,00,6c,00,61,00,00,00 +"MinidumpsCount"=dword:00000000 +"Overwrite"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard] +"ExitOnMSICW"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection] +"DisableDiagnosticDataViewer"=dword:00000001 +"DisableOneSettingsDownloads"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 +"DisableTelemetryOptInChangeNotification"=dword:00000000 +"DisableTelemetryOptInSettingsUx"=dword:00000000 +"AllowCommercialDataPipeline"=dword:00000000 +"AllowDesktopAnalyticsProcessing"=dword:00000000 +"AllowDeviceNameInTelemetry"=dword:00000000 +"AllowTelemetry"=dword:00000000 +"AllowUpdateComplianceProcessing"=dword:00000000 +"AllowWUfBCloudProcessing"=dword:00000000 +"DisableDeviceDelete"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000000 +"LimitDumpCollection"=dword:00000001 +"LimitEnhancedDiagnosticDataWindowsAnalytics"=dword:00000001 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection] +"AllowTelemetry"=dword:00000000 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 +"DisableDiagnosticDataViewer"=dword:00000001 +"DisableOneSettingsDownloads"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 +"DisableTelemetryOptInChangeNotification"=dword:00000000 +"DisableTelemetryOptInSettingsUx"=dword:00000000 +"AllowCommercialDataPipeline"=dword:00000000 +"AllowDesktopAnalyticsProcessing"=dword:00000000 +"AllowDeviceNameInTelemetry"=dword:00000000 +"AllowUpdateComplianceProcessing"=dword:00000000 +"AllowWUfBCloudProcessing"=dword:00000000 +"DisableDeviceDelete"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000000 +"LimitDumpCollection"=dword:00000001 +"LimitEnhancedDiagnosticDataWindowsAnalytics"=dword:00000001 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] +"TargetGroup"="Workstations" +"TargetGroupEnabled"=dword:00000000 +"WUServer"="http://x.x.x.x:8530" +"WUStatusServer"="http://x.x.x.x:8530" +"DeferUpgrade"=dword:00000001 +"DisableOSUpgrade"=dword:00000001 +"SetActiveHoursMaxRange"=dword:00000001 +"ActiveHoursMaxRange"=dword:00000012 +"AllowAutoWindowsUpdateDownloadOverMeteredNetwork"=dword:00000001 +"NoAutoRebootWithLoggedOnUsers"=dword:00000001 +"NoAUShutdownOption"=dword:00000001 +"NoAUAsDefaultShutdownOption"=dword:00000001 +"AlwaysAutoRebootAtScheduledTime"=dword:00000001 +"AlwaysAutoRebootAtScheduledTimeMinutes"=dword:0000000f +"EnableFeaturedSoftware"=dword:00000000 +"DisableWindowsUpdateAccess"=dword:00000001 +"SetAutoRestartNotificationDisable"=dword:00000001 +"SetActiveHours"=dword:00000001 +"ActiveHoursStart"=dword:00000007 +"ActiveHoursEnd"=dword:00000016 +"SetPolicyDrivenUpdateSourceForFeatureUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForQualityUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForDriverUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForOtherUpdates"=dword:00000000 +"DoNotConnectToWindowsUpdateInternetLocations"=dword:00000001 +"DisableDualScan"=dword:00000001 +"SetUpdateNotificationLevel"=dword:00000001 +"UpdateNotificationLevel"=dword:00000001 +"AcceptTrustedPublisherCerts"=dword:00000001 +"ElevateNonAdmins"=dword:00000001 +"ManagePreviewBuildsPolicyValue"=dword:00000002 +"BranchReadinessLevel"=dword:00000002 +"TargetReleaseVersion"=dword:00000000 +"DisableWUfBSafeguards"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\TraceManager] +"MiniTraceSlotContentPermitted"=dword:00000000 +"MiniTraceSlotEnabled"=dword:00000000 +"alternativeTraceScenarioId"="" +"alternativeTraceStartTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceStopTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceHasStopTime"=dword:00000000 +"alternativeTracePriority"=dword:00000000 +"alternativeTraceIsExclusive"=dword:00000000 +"alternativeTraceIsAutoLogger"=dword:00000000 +"alternativeTraceProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceIsThrottled"=dword:00000000 +"alternativeTraceRequiredBufferSpace"=dword:00000000 +"alternativeTraceThrottleState"=dword:00000000 +"aotScenarioId"="" +"aotStartTime"=hex(b):00,00,00,00,00,00,00,00 +"aotSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"aotStopTime"=hex(b):00,00,00,00,00,00,00,00 +"aotMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"aotHasStopTime"=dword:00000000 +"aotPriority"=dword:00000000 +"aotIsExclusive"=dword:00000000 +"aotIsAutoLogger"=dword:00000000 +"aotProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"aotIsThrottled"=dword:00000000 +"aotRequiredBufferSpace"=dword:00000000 +"aotThrottleState"=dword:00000000 +"miniTraceScenarioId"="" +"miniTraceStartTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceStopTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceHasStopTime"=dword:00000000 +"miniTracePriority"=dword:00000000 +"miniTraceIsExclusive"=dword:00000000 +"miniTraceIsAutoLogger"=dword:00000000 +"miniTraceProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceIsThrottled"=dword:00000000 +"miniTraceRequiredBufferSpace"=dword:00000000 +"miniTraceThrottleState"=dword:00000000 +"diagScenarioId"="" +"diagStartTime"=hex(b):00,00,00,00,00,00,00,00 +"diagSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"diagStopTime"=hex(b):00,00,00,00,00,00,00,00 +"diagMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"diagHasStopTime"=dword:00000000 +"diagPriority"=dword:00000000 +"diagIsExclusive"=dword:00000000 +"diagIsAutoLogger"=- +"diagProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"diagIsThrottled"=dword:00000000 +"diagRequiredBufferSpace"=dword:00000000 +"diagThrottleState"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack] +"DiagTrackStatus"=dword:00000002 +"DiagTrackAuthorization"=dword:00000375 +"ConnectivityNoNetworkTime"=dword:00000000 +"ConnectivityRestrictedNetworkTime"=dword:00000000 +"UploadPermissionReceived"=dword:00000000 +"ShowedToastAtLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters] +"DisableParallelAandAAAA"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient] +"DisableSmartNameResolution"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Wacom\Analytics] +"Analytics_On"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\ProviderControl] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SettingsRequests\] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Tenants] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\TriggerListener] +"MatchEngineBufferSize"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventTranscriptKey] +"EnableEventTranscript"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\OmittedIds] +"w:B04E2543-63EB-D3C6-4722-FBFE64FA31C0"=dword:00000000 +"w:5B08FD5C-0859-F5E6-7503-0D19552D498E"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Features] +"EventTagDropUserIds"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InputPersonalization] +"RestrictImplicitInkCollection"=dword:00000001 +"RestrictImplicitTextCollection"=dword:00000001 +"Installed"=dword:00000000 +"Shutdown"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SpeechGestures] +"RDCPolicyCollectionLevel"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy] +"HasAccepted"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP] +"RestartTimer"=dword:00000000 +"ForceEncryptedData"=dword:00000001 +"ForceEncryptedPassword"=dword:00000002 +"SecureVPN"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LLTD] +"EnableLLTDIO"=dword:00000000 +"AllowLLTDIOOnDomain"=dword:00000000 +"AllowLLTDIOOnPublicNet"=dword:00000000 +"ProhibitLLTDIOOnPrivateNet"=dword:00000001 +"EnableRspndr"=dword:00000000 +"AllowRspndrOnDomain"=dword:00000000 +"AllowRspndrOnPublicNet"=dword:00000000 +"ProhibitRspndrOnPrivateNet"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager] +"FeatureManagementEnabled"=dword:00000000 +"SlideshowEnabled"=dword:00000000 +"OemPreInstalledAppsEnabled"=dword:00000000 +"PreInstalledAppsEnabled"=dword:00000000 +"RotatingLockScreenEnabled"=dword:00000000 +"RotatingLockScreenOverlayEnabled"=dword:00000000 +"SilentInstalledAppsEnabled"=dword:00000000 +"SoftLandingEnabled"=dword:00000000 +"SystemPaneSuggestionsEnabled"=dword:00000000 +"SubscribedContent-338389Enabled"=dword:00000000 +"SubscribedContent-338388Enabled"=dword:00000000 +"PreInstalledAppsEverEnabled"=dword:00000000 +"SubscribedContent-88000326Enabled"=dword:00000000 +"SubscribedContent-338393Enabled"=dword:00000000 +"SubscribedContent-353694Enabled"=dword:00000000 +"SubscribedContent-353696Enabled"=dword:00000000 +"SubscribedContent-353698Enabled"=dword:00000000 +"SubscribedContentEnabled"=dword:00000000 +"RemediationRequired"=dword:00000000 +"ShowSyncProviderNotifications"=dword:00000000 +"SubscribedContent-310093Enabled"=dword:00000000 +"SubscribedContent-314563Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AdvertisingInfo] +"DisabledByGroupPolicy"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\StorageTelemetry] +"DeviceDumpEnabled"=dword:00000000 +"StorageTCCode_0"=dword:00000000 +"StorageTCCode_1"=dword:00000000 +"StorageTCCode_2"=dword:00000000 +"StorageTCCode_3"=dword:00000000 +"StorageTCCode_4"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\LiveKernelReports] +"DeleteLiveMiniDumps"=dword:00000000 + + +;020. Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"NoInstrumentation"=dword:00000001 +"NoRecentDocsMenu"=dword:00000001 +"MemCheckBoxInRunDlg"=dword:00000001 +"NoSMConfigurePrograms"=dword:0000000 +"NoRemoteRecursiveEvents"=dword:00000001 +"NoLowDiskSpaceChecks"=dword:00000001 +"LinkResolveIgnoreLinkInfo"=dword:00000001 +"NoResolveSearch"=dword:00000001 +"NoResolveTrack"=dword:00000001 +"NoInternetOpenWith"=dword:00000001 +"DisableSearchBoxSuggestions"=dword:00000001 +"NoLowDiskSpaceChecks"=dword:00000001 +"ConfirmFileDelete"=dword:00000000 +"HideSCAMeetNow"=dword:00000001 +"NoRecentDocsNetHood"=dword:00000001 +"NoNetConnectDisconnect"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\QuietHours] +"Enable"=dword:00000000 +"AllowCalls"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel] +"AllItemsIconView"=dword:00000002 +"StartupPage"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Serialize] +"StartupDelayInMSec"=dword:00000000 + + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LocationAndSensors] +"DisableLocation"=dword:00000001 +"DisableLocationScripting"=dword:00000001 +"DisableWindowsLocationProvider"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Siuf\Rules] +"NumberOfSIUFInPeriod"=dword:00000000 +"PeriodInNanoSeconds"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"SeparateProcess"=dword:00000001 +"HideFileExt"=dword:00000000 +"DontPrettyPath"=dword:00000001 +"ShowInfoTip"=dword:00000001 +"MapNetDrvBtn"=dword:00000000 +"WebView"=dword:00000000 +"ShowSuperHidden"=dword:00000001 +"MMTaskbarGlomLevel"=dword:00000000 +"Start_ShowRun"=dword:00000001 +"ExtendedUIHoverTime"=dword:00000001 +"ListviewShadow"=dword:00000000 +"TaskbarAnimations"=dword:00000000 +"ListviewAlphaSelect"=dword:00000000 +"ListviewWatermark"=dword:00000000 +"StartShownOnUpgrade"=dword:00000001 +"TaskbarDa"=dword:00000000 +"LaunchTo"=dword:00000001 +"TaskbarMn"=dword:00000000 +"Start_NotifyNewApps"=dword:00000000 +"ShowSecondsInSystemClock"=dword:00000001 +"ShowSyncProviderNotifications"=dword:00000000 +"NavPaneShowAllFolders"=dword:00000000 +"NoNetCrawling"=dword:00000001 +"TaskbarSi"=dword:00000001 +"JointResize"=dword:00000000 +"SnapAssist"=dword:00000000 +"SnapFill"=dword:00000000 +"LastActiveClick"=dword:00000001 +"TaskbarSizeMove"=dword:00000001 +"ShowStatusBar"=dword:00000001 +"HideSCAMeetNow"=dword:00000001 +"NoRecentDocsNetHood"=dword:00000001 +"IconsOnly"=dword:00000000 +"Start_TrackProgs"=dword:00000000 +"Start_TrackDocs"=dword:00000000 + + + +;021. AutoPlay + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\ShowPicturesOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\WPD] + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\WPD\ImageSource] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\CameraAlternate] + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\CameraAlternate\ShowPicturesOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\StorageOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers\StorageOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers] +"DisableAutoplay"=dword:00000000 + + +;022. Internet Optimization + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ServiceProvider] +"DnsPriority"=dword:00000006 +"LocalPriority"=dword:00000004 +"NetbtPriority"=dword:00000007 +"HostPriority"=dword:00000005 +"HostsPriority"=dword:00000005 +"Class"=dword:00000008 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters] +"EnableWsd"=dword:00000000 +"DisableDynamicDiscovery"=dword:00000001 +"EnablePMTUDiscovery"=dword:00000000 +"EnablePMTUBDetect"=dword:00000000 +"EnableICMPRedirect"=dword:00000001 +"DisableTaskOffload"=dword:00000000 +"TcpMaxDupAcks"=dword:00000002 +"Tcp1323Opts"=dword:00000001 +"TcpTimedWaitDelay"=dword:00000002 +"MaxFreeTcbs"=dword:00010000 +"TCPCongestionControl"=dword:00000001 +"SackOpts"=dword:00000000 +"DefaultTTL"=dword:00000040 +"CongestionAlgorithm"=dword:00000001 +"MultihopSets"=dword:0000000f +"FastCopyReceiveThreshold"=dword:00004000 +"FastSendDatagramThreshold"=dword:00004000 +"DelayedAckFrequency"=dword:00000000 +"DelayedAckTicks"=dword:00000000 +"UseDomainNameDevolution"=dword:00000000 +"IGMPLevel"=dword:00000000 +"GlobalMaxTcpWindowSize"=dword:00256960 +"TcpWindowSize"=dword:00256960 +"MaxConnectionsPer1_0Server"=dword:00000016 +"MaxConnectionsPerServer"=dword:00000016 +"MaxUserPort"=dword:00065534 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\Standard TCP/IP Port\Ports] +"LprAckTimeout"=dword:00000002 +"StatusUpdateEnabled"=dword:00000001 +"StatusUpdateInterval"=dword:0000000a + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\QoS] +"Do not use NLA"=dword:00000001 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Winsock] +"UseDelayedAcceptance"=dword:00000000 +"MaxSockAddrLength"=dword:00000010 +"MinSockAddrLength"=dword:00000010 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard] +"ExitOnMSICW"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkConnectivityStatusIndicator] +@="" +"NoActiveProbe"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender] +"DisableRoutinelyTakingAction"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender] +"DisableRoutinelyTakingAction"=dword:00000001 + +[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\QoS] +"Do not use NLA"="1" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSMQ\Parameters] +"TCPNoDelay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces] +"TcpAckFrequency"=dword:00000001 +"TCPNoDelay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TCPIP\v6Transition] +"Teredo_ClientPort"=dword:00000000 +"Teredo_DefaultQualified"="Enabled" +"Teredo_RefreshRate"=dword:0000001e +"Teredo_ServerName"="win10.ipv6.microsoft.com" +"Teredo_State"="Enterprise Client" + +;023. Disable Sound at Startup + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootControl] +"BootProgressAnimation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Boot] +"DisableStartupSound"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet] +"ActiveDnsProbeContent"="208.67.222.222" +"ActiveDnsProbeContentV6"="2620:119:35::35" +"ActiveDnsProbeHost"="resolver1.opendns.com" +"ActiveDnsProbeHostV6"="resolver1.opendns.com" +"ActiveWebProbeContent"="success" +"ActiveWebProbeContentV6"="success" +"ActiveWebProbeHost"="detectportal.firefox.com" +"ActiveWebProbeHostV6"="detectportal.firefox.com" +"ActiveWebProbePath"="success.txt" +"ActiveWebProbePathV6"="success.txt" + +[HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\WiFi\AllowAutoConnectToWiFiSenseHotspots] +"value"=dword:00000000 + +;024. Region Part + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CodePage] +"1250"="c_1251.nls" +"1251"="c_1251.nls" +"1252"="c_1251.nls" +"1253"="c_1251.nls" +"1254"="c_1251.nls" +"1255"="c_1251.nls" + +;025. GPU-n Driver Optimization + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"PlatformSupportMiracast"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\NVIDIA Corporation\Global\NVTweak\Devices\509901423-0\Color] +"NvCplUseColorCorrection"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] +"Optional"="" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\FTS] +"EnableRID61684"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\Global\NVTweak] +"DisplayPowerSaving"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Scheduler] +"EnablePreemption"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0000] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"TdrLevel"=dword:00000000 +"UseGpuTimer"=dword:00000001 +"RmGpsPsEnablePerCpuCoreDpc"=dword:00000001 +"PowerSavingTweaks"=dword:00000000 +"DisableWriteCombining"=dword:00000001 +"EnableRuntimePowerManagement"=dword:00000000 +"PrimaryPushBufferSize"=dword:00000001 +"FlTransitionLatency"=dword:00000000 +"D3PCLatency"=dword:00000000 +"RMDeepLlEntryLatencyUsec"=dword:00000000 +"PciLatencyTimerControl"=dword:00000020 +"Node3DLowLatency"=dword:00000001 +"LOWLATENCY"=dword:00000001 +"RmDisableRegistryCaching"=dword:00000001 +"RMDisablePostL2Compression"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Power] +"UseGpuTimer"=dword:00000001 +"RmGpsPsEnablePerCpuCoreDpc"=dword:00000001 +"PowerSavingTweaks"=dword:00000000 +"DisableWriteCombining"=dword:00000001 +"EnableRuntimePowerManagement"=dword:00000000 +"PrimaryPushBufferSize"=dword:00000001 +"FlTransitionLatency"=dword:00000000 +"D3PCLatency"=dword:00000000 +"RMDeepLlEntryLatencyUsec"=dword:00000000 +"PciLatencyTimerControl"=dword:00000020 +"Node3DLowLatency"=dword:00000001 +"LOWLATENCY"=dword:00000001 +"RmDisableRegistryCaching"=dword:00000001 +"RMDisablePostL2Compression"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceNoContext"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceMonitorOff"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceActivelyUsed"=dword:00000001 +"DefaultLatencyToleranceTimerPeriod "=dword:00000001 +"DefaultLatencyToleranceOther"=dword:00000001 +"DefaultLatencyToleranceNoContextMonitorOff"=dword:00000001 +"DefaultLatencyToleranceNoContext"=dword:00000001 +"DefaultLatencyToleranceMemory"=dword:00000001 +"DefaultLatencyToleranceIdle1MonitorOff"=dword:00000001 +"DefaultLatencyToleranceIdle1"=dword:00000001 +"DefaultLatencyToleranceIdle0MonitorOff"=dword:00000001 +"DefaultLatencyToleranceIdle0"=dword:00000001 +"DefaultD3TransitionLatencyIdleVeryLongTime"=dword:00000001 +"DefaultD3TransitionLatencyIdleShortTime"=dword:00000001 +"DefaultD3TransitionLatencyIdleNoContext"=dword:00000001 +"DefaultD3TransitionLatencyIdleMonitorOff"=dword:00000001 +"DefaultD3TransitionLatencyIdleLongTime"=dword:00000001 +"DefaultD3TransitionLatencyActivelyUsed"=dword:00000001 +"Latency"=dword:00000001 +"DefaultD3TransitionLatencyActivelyUsed"=dword:00000001 +"TransitionLatency"=dword:00000001 +"MonitorRefreshLatencyTolerance"=dword:00000001 +"MonitorLatencyTolerance"=dword:00000001 +"MiracastPerfTrackGraphicsLatency"=dword:00000001 +"MaxIAverageGraphicsLatencyInOneBucket"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"DpiMapIommuContiguous"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0001] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0002] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0000] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0001] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0002] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0003] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0001] +"LTRSnoopL1Latency"=dword:00000001 +"LTRSnoopL0Latency"=dword:00000001 +"LTRNoSnoopL1Latency"=dword:00000001 +"LTRMaxNoSnoopLatency"=dword:00000001 +"KMD_RpmComputeLatency"=dword:00000001 +"DalUrgentLatencyNs"=dword:00000001 +"memClockSwitchLatency"=dword:00000001 +"PP_RTPMComputeF1Latency"=dword:00000001 +"PP_DGBMMMaxTransitionLatencyUvd"=dword:00000001 +"PP_DGBPMMaxTransitionLatencyGfx"=dword:00000001 +"DalNBLatencyForUnderFlow"=dword:00000001 +"DalDramClockChangeLatencyNs"=dword:00000001 +"BGM_LTRSnoopL1Latency"=dword:00000001 +"BGM_LTRSnoopL0Latency"=dword:00000001 +"BGM_LTRNoSnoopL1Latency"=dword:00000001 +"BGM_LTRNoSnoopL0Latency"=dword:00000001 +"BGM_LTRMaxSnoopLatencyValue"=dword:00000001 +"BGM_LTRMaxNoSnoopLatencyValue"=dword:00000001 +"EnableVceSwClockGating"=dword:00000001 +"EnableUvdClockGating"=dword:00000001 +"DisableVCEPowerGating"=dword:00000000 +"DisableUVDPowerGatingDynamic"=dword:00000000 +"DisablePowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisableFBCForFullScreenApp"="0" +"DisableFBCSupport"=dword:00000000 +"DisableEarlySamuInit"=dword:00000001 +"PP_GPUPowerDownEnabled"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_SclkDeepSleepDisable"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000001 +"PP_ActivityTarget"=dword:0000001e +"PP_ODNFeatureEnable"=dword:00000001 +"EnableUlps"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"PP_AllGraphicLevel_DownHyst"=dword:00000014 +"PP_AllGraphicLevel_UpHyst"=dword:00000000 +"KMD_FRTEnabled"=dword:00000000 +"DisableDMACopy"=dword:00000001 +"DisableBlockWrite"=dword:00000000 +"PP_ODNFeatureEnable"=dword:00000001 +"KMD_MaxUVDSessions"=dword:00000020 +"DalAllowDirectMemoryAccessTrig"=dword:00000001 +"DalAllowDPrefSwitchingForGLSync"=dword:00000000 +"WmAgpMaxIdleClk"=dword:00000020 +"StutterMode"=dword:00000000 +"TVEnableOverscan"=dword:00000000 +"PowerMizerEnable"=dword:00000001 +"PowerMizerLevel"=dword:00000001 +"PowerMizerLevelAC"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000] +"LTRSnoopL1Latency"=dword:00000001 +"LTRSnoopL0Latency"=dword:00000001 +"LTRNoSnoopL1Latency"=dword:00000001 +"LTRMaxNoSnoopLatency"=dword:00000001 +"KMD_RpmComputeLatency"=dword:00000001 +"DalUrgentLatencyNs"=dword:00000001 +"memClockSwitchLatency"=dword:00000001 +"PP_RTPMComputeF1Latency"=dword:00000001 +"PP_DGBMMMaxTransitionLatencyUvd"=dword:00000001 +"PP_DGBPMMaxTransitionLatencyGfx"=dword:00000001 +"DalNBLatencyForUnderFlow"=dword:00000001 +"DalDramClockChangeLatencyNs"=dword:00000001 +"BGM_LTRSnoopL1Latency"=dword:00000001 +"BGM_LTRSnoopL0Latency"=dword:00000001 +"BGM_LTRNoSnoopL1Latency"=dword:00000001 +"BGM_LTRNoSnoopL0Latency"=dword:00000001 +"BGM_LTRMaxSnoopLatencyValue"=dword:00000001 +"BGM_LTRMaxNoSnoopLatencyValue"=dword:00000001 +"EnableVceSwClockGating"=dword:00000001 +"EnableUvdClockGating"=dword:00000001 +"DisableVCEPowerGating"=dword:00000000 +"DisableUVDPowerGatingDynamic"=dword:00000000 +"DisablePowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisableFBCForFullScreenApp"="0" +"DisableFBCSupport"=dword:00000000 +"DisableEarlySamuInit"=dword:00000001 +"PP_GPUPowerDownEnabled"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_SclkDeepSleepDisable"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000001 +"PP_ActivityTarget"=dword:0000001e +"PP_ODNFeatureEnable"=dword:00000001 +"EnableUlps"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"PP_AllGraphicLevel_DownHyst"=dword:00000014 +"PP_AllGraphicLevel_UpHyst"=dword:00000000 +"KMD_FRTEnabled"=dword:00000000 +"DisableDMACopy"=dword:00000001 +"DisableBlockWrite"=dword:00000000 +"PP_ODNFeatureEnable"=dword:00000001 +"KMD_MaxUVDSessions"=dword:00000020 +"DalAllowDirectMemoryAccessTrig"=dword:00000001 +"DalAllowDPrefSwitchingForGLSync"=dword:00000000 +"WmAgpMaxIdleClk"=dword:00000020 +"StutterMode"=dword:00000000 +"TVEnableOverscan"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm] +"NVFBCEnable"=dword:00000001 +"DisablePreemption"=dword:00000001 +"DisableCudaContextPreemption"=dword:00000001 +"DisableWriteCombining"=dword:00000001 +"EnableTiledDisplay"=dword:00000000 +"ComputePreemption"=dword:00000000 +"DisablePreemptionOnS3S4"=dword:00000001 +"EnableCEPreemption"=dword:00000000 + +[HKLM\SYSTEM\CurrentControlSet\Services\DXGKrnl] +"MonitorLatencyTolerance"=dword:00000001 + +[HKLM\SYSTEM\CurrentControlSet\Services\DXGKrnl] +"MonitorRefreshLatencyTolerance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid\Parameters] +"TreatAbsolutePointerAsAbsolute"=dword:00000001 +"TreatAbsoluteAsRelative"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\CDP] +"CdpSessionUserAuthzPolicy"=dword:00000000 +"RomeSdkChannelUserAuthzPolicy"=dword:00000000 + +;026. Session Manager Configuration (Meltown and Spectre) + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"DisablePagingExecutive"=dword:00000001 +"LargeSystemCache"=dword:00000001 +"NonPagedPoolSize"=dword:000000c0 +"PagedPoolSize"=dword:000000c0 +"FeatureSettings"=dword:00000001 +"FeatureSettingsOverride"=dword:00000003 +"FeatureSettingsOverrideMask"=dword:00000003 +"PoolUsageMaximum"=dword:000000c0 +"EnableCfg"=dword:00000000 +"IoPageLockLimit"=dword:ffffffff +"ProtectionMode"=dword:00000000 +"ThirdLevelDataCache"=dword:00008192 +"MoveImages"=dword:00000000 +"PhysicalAddressExtension"=dword:00000001 +"SecondLevelDataCache"=dword:00003072 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel] +"DpcWatchdogProfileOffset"=dword:00000000 +"DpcTimeout"=dword:00000000 +"DpcWatchdogPeriod"=dword:00000000 +"DisableExceptionChainValidation"=dword:00000001 +"KernelSEHOPEnabled"=dword:00000000 +"DpcWatchdogProfileOffset"=dword:00000000 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,20,02,00,00,00,20,00,00 +"MitigationAuditOptions"=hex:20,00,00,20,20,20,22,22,00,00,00,00,00,00,00,00 +"DisableExceptionChainValidation"=dword:00000001 +"MaximumSharedReadyQueueSize"=dword:00000001 +"DisableAutoBoost"=dword:00000001 +"DistributeTimers"=dword:00000001 +"IdealDpcRate"=dword:00000001 +"MaximumDpcQueueDepth"=dword:00000001 +"MinimumDpcRate"=dword:00000001 +"ThreadDpcEnable"=dword:00000001 +"AdjustDpcThreshold"=dword:00000000 +[HKEY_LOCAL_MACHINE\SYSTEM] +"MinimumWorkingSet"=hex(b):00,00,00,00,00,10,00,00 +"MinimumFileCacheSize"=hex(b):00,00,00,00,00,10,00,00 +"increaseuserva"=dword:0fffff80 +"InterruptSteeringDisabled"=dword:00000001 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 +"OverlayTestMode"=dword:00000005 +"UseLargePages"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsMitigation] +"UserPreference"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"MinimumWorkingSet"=hex(b):00,00,00,00,00,10,00,00 +"MinimumFileCacheSize"=hex(b):00,00,00,00,00,10,00,00 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 +"OverlayTestMode"=dword:00000005 +"UseLargePages"=dword:00000001 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xusb22\Parameters] +"IoQueueWorkItem"=dword:0000000a + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters] +"DisabledComponents"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseSensitivity"="10" + + +;027.SecDrv + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SecDrv] +"Type"=dword:00000001 +"Start"=dword:00000003 +"ErrorControl"=dword:00000001 +"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ + 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,00,69,\ + 00,76,00,65,00,72,00,73,00,5c,00,53,00,45,00,43,00,44,00,52,00,56,00,2e,00,\ + 53,00,59,00,53,00,00,00 +"DisplayName"="SecDrv" +"WOW64"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SecDrv\Security] +"Security"=hex:01,00,14,80,8c,00,00,00,98,00,00,00,14,00,00,00,30,00,00,00,02,\ + 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ + 00,00,02,00,5c,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ + 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ + 20,02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\ + 00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,\ + 00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 + +;028.Resource Management + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\I/O System] +"PassiveIntRealTimeWorkerPriority"=dword:00000018 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\KernelVelocity] +"DisableFGBoostDecay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\HardCap0] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\Paused] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapFull] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapFullAboveNormal] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapLow] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapLowBackgroundBegin] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\UnmanagedAboveNormal] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\BackgroundDefault] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Frozen] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenDNCS] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenDNK] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenPPLE] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Paused] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\PausedDNK] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Pausing] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\PrelaunchForeground] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\ThrottleGPUInterference] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Critical] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\CriticalNoUi] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\EmptyHostPPLE] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\High] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Low] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Lowest] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Medium] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\MediumHigh] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\StartHost] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\VeryHigh] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\VeryLow] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\IO\NoCap] +"IOBandwidth"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Memory\NoCap] +"CommitLimit"=dword:ffffffff +"CommitTarget"=dword:ffffffff + +;029. Services + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GpuEnergyDrv] +"Start"=dword:00000004 + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\AMDLOG] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus_25D3A396F7F029EE] +"Start"=dword:00000004 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell] +"ConvertibleSlateModePromptPreference"=dword:00000000 +"TabletMode"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\perceptionsimulation] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PenService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edgeupdate] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edgeupdatem] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GoogleChromeElevationService] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Credssp] +"DebugLogLevel"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.devicemetadata-ms] + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter] +"EnabledV9"=dword:00000000 + + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hvcmon] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DiagTrack] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmwappushservice] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\diagsvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DPS] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\diagnosticshub.standardcollector.service] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiServiceHost] + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WacomPen] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PktMon] +"Start"=dword:00000004 +"Type"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVEdrv] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep] +"Start"=dword:00000004 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysMain] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WSearch] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AMD External Events Utility] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSLinkNear] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSLinkRemote] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSSystemAnalysis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSSystemDiagnosis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BcastDVRUserService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdate] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdatem] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdatem] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisVirtualBus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vid] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\umbus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpbus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndu] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisCap] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemUsageReportSvc_QUEENCREEK] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Intel(R) SUR QC SAM] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMS] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEIx64] +"Start"=dword:00000004 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GraphicsPerfSvc] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dam] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Audiosrv] +"ErrorControl"=dword:00000002 + + +;030. File System Efficency + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem] +"DisableDeleteNotification"=dword:00000001 +"RefsDisableLastAccessUpdate"=dword:00000001 +"Win31FileSystem"=dword:00000000 +"Win95TruncatedExtensions"=dword:00000000 +"LongPathsEnabled"=dword:00000001 +"NtfsDisableLastAccessUpdate"=dword:00000001 +"NtfsMemoryUsage"=dword:00000000 +"NtfsMftZoneReservation"=dword:00000004 +"NtfsDisableSpotCorruptionHandling"=dword:00000001 +"RefsDisableLastAccessUpdate"=dword:00000001 +"NtfsBugcheckOnCorrupt"=dword:00000000 +"LongPathsEnabled"=dword:00000001 +"NTFSDisable8dot3NameCreation"=dword:00000001 +"LongPathsEnabled"=dword:00000001 + + +;031. Delay & Timeout + +[HKEY_CURRENT_USER\Control Panel\Desktop] +"AutoEndTasks"="1" +"MenuShowDelay"="0" +"AutoEndTasks"="1" +"ScreenSaveTimeOut"=- +"SCRNSAVE.EXE"=- +"ForegroundLockTimeout"=dword:00000000 +"MouseWheelRouting"=dword:00000000 +"WaitToKillAppTimeout"="1" +"WaitToKillServiceTimeout"=dword:00000002 +"HungAppTimeout"="2000" +"LowLevelHooksTimeout"=dword:00000005 +"Win8DpiScaling"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\ModernSleep] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control] +"CoalescingTimerInterval"=dword:00000000 +"WaitToKillServiceTimeout"="1" +"DisableRemoteScmEndpoints"dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control] +"WaitToKillServiceTimeout"="1" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PnP] +"PollBootPartitionTimeout"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfNet\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfOS\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfDisk\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfProc\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BackgroundModel\BackgroundAudioPolicy] +"AllowHeadlessExecution"=dword:00000001 +"AllowMultipleBackgroundTasks"=dword:00000001 +"InactivityTimeoutMs"=dword:FFFFFFFF + +;032. Google Chrome + +[HEKY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome] +"TranslateEnabled"=dword:00000001 +"TaskManagerEndProcessEnabled"=dword:00000001 +"UserFeedbackAllowed"=dword:00000000 +"SpellCheckServiceEnabled"=dword:00000000 +"SpellcheckEnabled"=dword:00000000 +"MediaRouterCastAllowAllIPs"=dword:00000001 +"AllowDinosaurEasterEgg"=dword:00000001 +"DefaultGeolocationSetting"=dword:00000002 +"DefaultCookiesSetting"=dword:00000001 +"DefaultFileHandlingGuardSetting"=dword:00000003 +"DefaultFileSystemReadGuardSetting"=dword:00000003 +"DefaultFileSystemWriteGuardSetting"=dword:00000003 +"DefaultPopupsSetting"=dword:00000002 +"DefaultSensorsSetting"=dword:00000002 +"DefaultSerialGuardSetting"=dword:00000002 +"DefaultWebBluetoothGuardSetting"=dword:00000002 +"DefaultWebUsbGuardSetting"=dword:00000002 +"EnableMediaRouter"=dword:00000001 +"ShowCastIconInToolbar"=dword:00000001 +"CloudPrintProxyEnabled"=dword:00000000 +"PrintRasterizationMode"=dword:00000000 +"PrintingEnabled"=dword:00000001 +"DefaultPluginsSetting"=dword:00000001 +"SafeBrowsingProtectionLevel"=dword:00000000 +"SafeBrowsingExtendedReportingEnabled"=dword:00000000 +"HomepageIsNewTabPage"=dword:00000000 +"HomepageLocation"="google.com" +"NewTabPageLocation"="google.com" +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 +"ChromeCleanupEnabled"=dword:00000000 +"ChromeCleanupReportingEnabled"=dword:00000000 +"DefaultSearchProviderName"="sGoogle Encrypted" +"DefaultSearchProviderSearchURL"="https://www.google.com/#q={searchTerms}" +"DefaultSearchProviderEnabled"=dword:01000000 +"AllowCrossOriginAuthPrompt"=dword:00000000 +"AlwaysOpenPdfExternally"=dword:00000001 +"AmbientAuthenticationInPrivateModesEnabled"=dword:00000000 +"AudioCaptureAllowed"=dword:00000001 +"AudioSandboxEnabled"=dword:00000000 +"DnsOverHttpsMode"="off" +"ScreenCaptureAllowed"=dword:00000001 +"SitePerProcess"=dword:00000001 +"TLS13HardeningForLocalAnchorsEnabled"=dword:00000001 +"VideoCaptureAllowed"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome] +"TranslateEnabled"=dword:00000001 +"TaskManagerEndProcessEnabled"=dword:00000001 +"UserFeedbackAllowed"=dword:00000000 +"SpellCheckServiceEnabled"=dword:00000000 +"SpellcheckEnabled"=dword:00000000 +"MediaRouterCastAllowAllIPs"=dword:00000001 +"AllowDinosaurEasterEgg"=dword:00000001 +"DefaultGeolocationSetting"=dword:00000002 +"DefaultCookiesSetting"=dword:00000001 +"DefaultFileHandlingGuardSetting"=dword:00000003 +"DefaultFileSystemReadGuardSetting"=dword:00000003 +"DefaultFileSystemWriteGuardSetting"=dword:00000003 +"DefaultPopupsSetting"=dword:00000002 +"DefaultSensorsSetting"=dword:00000002 +"DefaultSerialGuardSetting"=dword:00000002 +"DefaultWebBluetoothGuardSetting"=dword:00000002 +"DefaultWebUsbGuardSetting"=dword:00000002 +"EnableMediaRouter"=dword:00000001 +"ShowCastIconInToolbar"=dword:00000001 +"CloudPrintProxyEnabled"=dword:00000000 +"PrintRasterizationMode"=dword:00000000 +"PrintingEnabled"=dword:00000001 +"DefaultPluginsSetting"=dword:00000001 +"SafeBrowsingProtectionLevel"=dword:00000000 +"SafeBrowsingExtendedReportingEnabled"=dword:00000000 +"HomepageIsNewTabPage"=dword:00000000 +"HomepageLocation"="google.com" +"NewTabPageLocation"="google.com" +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 +"ChromeCleanupEnabled"=dword:00000000 +"ChromeCleanupReportingEnabled"=dword:00000000 +"DefaultSearchProviderName"="sGoogle Encrypted" +"DefaultSearchProviderSearchURL"="https://www.google.com/#q={searchTerms}" +"DefaultSearchProviderEnabled"=dword:01000000 +"AllowCrossOriginAuthPrompt"=dword:00000000 +"AlwaysOpenPdfExternally"=dword:00000001 +"AmbientAuthenticationInPrivateModesEnabled"=dword:00000000 +"AudioCaptureAllowed"=dword:00000001 +"AudioSandboxEnabled"=dword:00000000 +"DnsOverHttpsMode"="off" +"ScreenCaptureAllowed"=dword:00000001 +"SitePerProcess"=dword:00000001 +"TLS13HardeningForLocalAnchorsEnabled"=dword:00000001 +"VideoCaptureAllowed"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\Extensions\djflhoibgkdhkhhcedjiklpkjnoahfmg\policy\OtherSettings] +"send_errors"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist] +"1"="cjpalhdlnbpafiamejdnhcphjbkeiagm" +"2"="fihnjjcciajhdojfnbdddfaoknhalnja" +"3"="bnomihfieiccainjcjblhegjgglakjdd" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\Recommended] +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\URLBlacklist] +"1"="javascript://*" + + + +;033. Virtualization + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard] +"DeployConfigCIPolicy"=dword:00000000 +"EnableVirtualizationBasedSecurity"=dword:00000000 +"HVCIMATRequired"=dword:00000000 +"RequirePlatformSecurityFeature"=dword:00000000 +"CachedDrtmAuthIndex"=dword:00000000 +"RequireMicrosoftSignedBootChain"=dword:00000000 +"RequirePlatformSecurityFeatures"=dword:00000000 +"Locked"=dword:00000000 + +;034. Input Tweaks + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\TabletTip\1.7] +"HideIPTIPTarget"=dword:00000001 +"HideIPTIPTouchTarget"=dword:00000001 +"IncludeRareChar"=dword:00000000 +"DisableEdgeTarget"=dword:00000001 +"DisableACIntegration"=dword:00000001 +"EnableAutocorrection"=dword:00000000 +"EnableSpellchecking"=dword:00000000 +"EnableTextPrediction"=dword:00000000 +"EnablePredictionSpaceInsertion"=dword:00000000 +"EnableDoubleTapSpace"=dword:00000000 +"EnableInkingWithTouch"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TabletTip\1.7] +"HideIPTIPTarget"=dword:00000001 +"HideIPTIPTouchTarget"=dword:00000001 +"IncludeRareChar"=dword:00000000 +"DisableEdgeTarget"=dword:00000001 +"DisableACIntegration"=dword:00000001 +"EnableAutocorrection"=dword:00000000 +"EnableSpellchecking"=dword:00000000 +"EnableTextPrediction"=dword:00000000 +"EnablePredictionSpaceInsertion"=dword:00000000 +"EnableDoubleTapSpace"=dword:00000000 +"EnableInkingWithTouch"=dword:00000000 + + + +[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings] +"EnableExpressiveInputShellHotkey"=dword:00000001 +"EnableExpressiveInputEmojiMultipleSelection"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\PenWorkspace] +"PenWorkspaceAppSuggestionsEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventTranscriptKey] +"EnableEventTranscript"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorSpeed] +"CursorSensitivity"=dword:00002710 +"CursorUpdateInterval"=dword:00000001 +"IRRemoteNavigationDelta"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorMagnetism] +"AttractionRectInsetInDIPS"=dword:00000005 +"DistanceThresholdInDIPS"=dword:00000028 +"MagnetismDelayInMilliseconds"=dword:00000002 +"MagnetismUpdateIntervalInMilliseconds"=dword:00000001 +"VelocityInDIPSPerSecond"=dword:00000168 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] +"EnableCursorSuppression"=dword:00000000 +"DelayedDesktopSwitchTimemout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\ChainEngine\Config] +"ChainRevAccumulativeUrlRetrievalTimeoutMilliseconds"=dword:0000000e +"ChainUrlRetrievalTimeoutMilliseconds"=dword:0000000e +"CrossCertDownloadIntervalHours"=dword:000000a8 +"Options"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings] +"AutoAccent"=dword:00000000 +"AutoApostrophe"=dword:00000000 +"AutoCap"=dword:00000000 +"AutoCapAllTokens"=dword:00000000 +"AutoCorrectFirstWord"=dword:00000000 +"AutoCorrection"=dword:00000000 +"AutoCorrectVisualDelay"=dword:00000000 +"AutoswitchAfterEmoji"=dword:00000000 +"ContactPenalty"=dword:00000000 +"DictationEnabled"=dword:00000001 +"DictationSupportedLanguages"="en-US;fr-FR;en-GB;de-DE;it-IT;zh-hans-CN;es-ES;en-IN;pt-BR;en-AU;en-CA;fr-CA;es-MX;ro-RO" +"DisablePersonalization"=dword:00000001 +"EmojiSuggestion"=dword:00000001 +"EmojiTranslation"=dword:00000001 +"EnableHwkbAutocorrection"=dword:00000000 +"EnableHwkbMode"=dword:00000000 +"EnableHwkbTextPrediction"=dword:00000000 +"HarvestContacts"=dword:00000000 +"HasTrailer"=dword:00000000 +"HTREnabled"=dword:00000000 +"HwkbAutocorrectionAlwaysOffList"=-" +"InsightsEnabled"=dword:00000000 +"IsVoiceTypingKeyEnabled"=dword:00000001 +"KeyboardMode"=dword:00000000 +"LMDataLoggerEnabled"=dword:00000000 +"MaxCorrections"=dword:00000000 +"MultilingualEnabled"=dword:00000000 +"NotActiveLanguagePenalty"=dword:00000000 +"NotPredictedLanguagePenalty"=dword:00000000 +"PeriodShortcut"=dword:00000000 +"Prediction"=dword:00000000 +"Private"=dword:00000000 +"ProofDataSources"=dword:00000000 +"SearchDataSources"=dword:00000000 +"Spellcheck"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore] +"HarvestContacts"=dword:00000000 +"InsightsEnabled"=dword:00000000 +"LMDataLoggerEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Speech] +"AllowSpeechModelUpdate"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Privacy] +"TailoredExperiencesWithDiagnosticDataEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MSDeploy\3] +"EnableTelemetry"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CPSS\UserPolicy\ImproveInkingAndTyping] +"DefaultValue"=dword:00000000 +"InheritsFromDevice"=dword:00000000 +"LegacyKeyName"="Enabled" +"LegacyKeyType"=dword:00000000 +"LegacyProjection"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Diagnostics\Performance] +"DisableDiagnosticTracing"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CPSS\UserPolicy\InkingAndTypingPersonalization] +"DefaultValue"=dword:00000000 +"InheritsFromDevice"=dword:00000000 +"LegacyKeyType"=dword:00000000 +"LegacyProjection"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings] +"EnableHwkbAutocorrection2"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TabletPC] +"PreventHandwritingDataSharing"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\HandwritingErrorReports] +"PreventHandwritingErrorReports"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PenTraining] +"DisablePenTraining"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace] +"AllowWindowsInkWorkspace"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorSpeed] +"CursorUpdateInterval"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouclass\Parameters] +"MouseDataQueueSize"=dword:00000032 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdclass\Parameters] +"KeyboardDataQueueSize"=dword:00000032 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS] +"Start"=dword:00000004 + +[HKEY_USERS\.DEFAULT\Control Panel\Mouse] +"MouseSpeed"="0" +"MouseThreshold1"="0" +"MouseThreshold2"="0" + + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseSpeed"="0" +"MouseThreshold1"="0" +"MouseThreshold2"="0" + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"Beep"="No" +"ExtendedSounds"="No" + +[HKEY_USERS\.DEFAULT\Control Panel\Sound] +"Beep"="no" +"ExtendedSounds"="no" + +[HKEY_CURRENT_USER\Control Panel\Sound] +"Beep"="no" +"ExtendedSounds"="no" + +[HKEY_CURRENT_USER\Control Panel\Keyboard] +"KeyboardDelay"="0" +"KeyboardSpeed"="10" +"InitialKeyboardIndicators"="2" + +[HKEY_USERS\.DEFAULT\Control Panel\Keyboard] +"InitialKeyboardIndicators"="2" +"KeyboardDelay"="0" +"KeyboardSpeed"="10" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters] +"DefaultReceiveWindow"=dword:00004000 +"DefaultSendWindow"=dword:00004000 +"FastCopyReceiveThreshold"=dword:00004000 +"FastSendDatagramThreshold"=dword:00004000 +"DynamicSendBufferDisable"=dword:00000000 +"IgnorePushBitOnReceives"=dword:00000001 +"NonBlockingSendSpecialBuffering"=dword:00000001 +"DisableRawSecurity"=dword:00000001 +"DoNotHoldNicBuffers"=dword:00000001 +"DisableAddressSharing"=dword:00000001 + +;035. Office Tweaks + + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Lync] +"disableautomaticsendtracking"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common] +"QMEnable"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\Feedback] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\15.0\osm] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry] +"MotherboardUUID"="-" +"DisableTelemetry"=dword:00000001 +"VerboseLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common] +"sentcostumerdata"=dword:00000000 +"qmenable"=dword:00000000 +"updaterealiabilitydata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Feedback] +"enabled"=dword:00000000 +"includescreenshot"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Office\17.0\osm] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\OSM] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\Calendar] +"EnableCalendarLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Security] +"InitEncrypt"=dword:00000002 +"InitSign"=dword:00000002 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Graphics] +"DisableAnimations"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common] +"sendcustomerdata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Feedback] +"enabled"=dword:00000000 +"includescreenshot"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common] +"qmenable"=dword:00000000 +"updatereliabilitydata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\General] +"shownfirstrunoptin"=dword:00000000 +"skydrivesigninoption"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ptwatson] +"ptwoptin"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Firstrun] +"disablemovie"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\OSM] +"Enablelogging"=dword:00000000 +"EnableUpload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Options\Calendar] +"EnableCalendarLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Options\Mail] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options] +"EnableLogging"=dword:00000000 +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options\WordMail] +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options] +"EnableLogging"=dword:00000000 +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\WordMail] +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common] +"sendcustomerdata"=dword:00000000 +"SendCustomerDataOptInReason"=dword:00000000 +"SendCustomerDataOptIn"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\Mail] +"BlockExtContent"=dword:00000000 +"UnblockSpecificSenders"=dword:00000000 +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common] +"QMEnable"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\International\User Profile] +"HttpAcceptLanguageOptOut"=dword:00000001 + + +;036. Google Update + +:: Google Update + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Update] +"Install{8A69D345-D564-463C-AFF1-A69D9E530F96}"=dword:00000005 +"TargetChannel{8A69D345-D564-463C-AFF1-A69D9E530F96}"="stable" +"Update{8A69D345-D564-463C-AFF1-A69D9E530F96}"=dword:00000003 +"Install{4CCED17F-7852-4AFC-9E9E-C89D8795BDD2}"=dword:00000000 +"AutoUpdateCheckPeriodMinutes"=dword:0000a8c0 +"DownloadPreference"="cacheable" +"UpdatesSuppressedStartHour"=dword:00000017 +"UpdatesSuppressedStartMin"=dword:00000030 +"UpdatesSuppressedDurationMin"=dword:00000037 + + + +;037. Windows Update + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] +"BranchReadinessLevel"=dword:00000010 +"DeferFeatureUpdates"=dword:00000001 +"DeferFeatureUpdatesPeriodInDays"=dword:00000000 +"PauseFeatureUpdatesStartTime"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] +"DetectionFrequency"=dword:00000014 +"DetectionFrequencyEnabled"=dword:00000001 +"EnableFeaturedSoftware"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\PolicyState] +"DeferQualityUpdates"=dword:00000001 +"DeferFeatureUpdates"=dword:00000001 +"BranchReadinessLevel"="CB" +"IsDeferralIsActive"=dword:00000001 +"IsWUfBConfigured"=dword:00000000 +"IsWUfBDualScanActive"=dword:00000000 +"FeatureUpdatesDeferralInDays"=dword:00000000 +"ExcludeWUDrivers"=dword:00000001 +"PolicySources"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE] +"DisableExternalDMAUnderLock"=dword:00000001 + +;038. XBOX + +[-HKEY_CURRENT_USER\System\GameConfigStore\Children] + +[-HKEY_CURRENT_USER\System\GameConfigStore\Parents] + +[HKEY_USERS\.DEFAULT\Software\Microsoft\GameBar] +"AutoGameModeEnabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\GameBar] +"AutoGameModeEnabled"=dword:00000000 + + +[HKEY_CURRENT_USER\Software\Microsoft\Games] +"EnableXBGM"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\GameDVR] +"KGLRevision"=- +"KGLToGCSUpdatedRevision"=- +"LastGameActivity"=- +"AppCaptureEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\GameDVR] +"AllowgameDVR"=dword:00000000 + +[HKEY_CURRENT_USER\System\GameConfigStore] +"GameDVR_FSEBehavior"=dword:00000002 + +[HKEY_CURRENT_USER\Software\Microsoft\GameBar] +"AllowAutoGameMode"=dword:00000000 +"AutoGameModeEnabled"=dword:00000000 +"ShowStartupPanel"=dword:00000000 +"ShowGameModeNotifications"=dword:00000000 + +[HKEY_CURRENT_USER\System\GameConfigStore] +"GameDVR_Enabled"=dword:00000000 +"GameDVR_FSEBehaviorMode"=dword:00000002 +"Win32_AutoGameModeDefaultProfile"=- +"Win32_GameModeRelatedProcesses"=- +"GameDVR_HonorUserFSEBehaviorMode"=dword:00000001 +"GameDVR_DXGIHonorFSEWindowsCompatible"=dword:00000001 +"GameDVR_EFSEFeatureFlags"=dword:00000000 +"GameDVR_FSEBehavior"=dword:00000002 + +[-HKEY_CURRENT_USER\System\GameConfigStore\Children] + +[-HKEY_CURRENT_USER\System\GameConfigStore\Parents] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TWinUI\FilePicker\LastVisitedPidlMRU] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Diagnostics] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Census] + +[-HKEY_CURRENT_USER\Briefcase\ShellNew] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameBar] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameChatOverlay] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameChatOverlayMessageSource] +"ActivationType"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{FC96B68C-09EF-4251-A598-19E4BE1B76A9}] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\ApplicationManagement\AllowGameDVR] +"value"=dword:00000000 + +;039. Power Tweaks + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\2a737441-1930-4402-8d77-b2bebba308a3\d4e98f31-5ffe-4ce1-be31-1b38b384c009] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\d639518a-e56d-4345-8af2-b9f32fb26109] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\dab60367-53fe-4fbc-825e-521d069d2456] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\0b2d69d7-a2a1-449c-9680-f91c70521c60] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\12a0ab44-fe28-4fa9-b3bd-4b64f44960a6] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\6b013a00-f775-4d61-9036-a62f7e7a6a5b] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"AcPolicy"=hex:01,00,00,00,00,00,00,00,03,00,00,00,10,00,00,00,02,00,00,00,03,\ + 00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,1a,88,\ + 41,7e,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,32,00,00,00,02,00,00,\ + 00,02,00,00,00,02,00,00,00,01,00,00,00,96,88,41,7e,00,00,00,00,03,00,00,00,\ + 01,00,00,00,03,00,00,00,03,00,00,00,04,00,00,c0,01,00,00,00,05,00,00,00,01,\ + 00,00,00,0a,00,00,00,00,00,00,00,03,00,00,00,01,00,01,00,01,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,00,00,00,\ + 00,d0,09,00,08,00,00,00,3c,13,00,00,30,31,09,00,00,00,00,00,01,64,64,00,02,\ + 00,00,00,04,00,00,c0,00,00,00,00 +"DcPolicy"=hex:01,00,00,00,00,00,00,00,03,00,00,00,10,00,00,00,02,00,00,00,03,\ + 00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,0d,00,\ + 00,00,02,00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,03,09,00,02,00,00,\ + 00,02,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,84,03,00,00,03,00,00,00,\ + 01,00,00,00,03,00,00,00,03,00,00,00,04,00,00,c0,01,00,00,00,05,00,00,00,01,\ + 00,00,00,0a,00,00,00,00,00,00,00,03,00,00,00,01,00,01,00,01,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,2c,01,00,00,\ + 01,88,41,7e,99,01,00,00,d0,7f,54,00,e4,7f,54,00,58,02,00,00,01,64,64,00,02,\ + 00,00,00,04,00,00,c0,00,00,00,00 + +[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\0] +"Policies"=hex:01,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,32,00,03,02,00,00,00,02,00,\ + 00,00,00,00,3d,77,2e,f2,07,00,00,00,00,00,2c,01,00,00,00,00,00,00,58,02,00,\ + 00,01,01,64,64,64,64,91,7c + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling] +"PowerThrottlingOff"=dword:00000001 + + +;040. Control Panel Items (only Windows 10) + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Account Manager" +"InfoTip"="Opens Account Manager" +"System.ControlPanel.Category"="9" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\DefaultIcon] +@="%SystemRoot%\\System32\\netplwiz.exe" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\Shell\Open\command] +@="netplwiz.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Add Advanced User Accounts to Control Panel" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@=" Account Manager" +"InfoTip"="Opens Account Manager" +"System.ControlPanel.Category"="9" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\DefaultIcon] +@="%SystemRoot%\\System32\\netplwiz.exe" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\Shell\Open\command] +@="netplwiz.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Add Advanced User Accounts to Control Panel" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}] +@="WinColor" +"InfoTip"="Change the color of your taskbar, window borders, and Start menu" +"System.ApplicationName"="Microsoft.Personalization" +"System.ControlPanel.Category"=dword:00000001 +"System.Software.TasksFileUrl"="Internal" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}\DefaultIcon] +@="%SystemRoot%\\System32\\imageres.dll,-197" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}\Shell\Open\command] +@="explorer shell:::{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921} -Microsoft.Personalization\\pageColorization" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{106ee807-9e5d-451b-a9c5-74908630cefb}] +@="Color and Appearance" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}] +@=" Disk Manager" +"InfoTip"="Create and format hard disk partitions" +"System.ControlPanel.Category"="2" +"System.ControlPanel.EnableInSafeMode"="3" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}\DefaultIcon] +@="%WinDir%\\System32\\dmdskres.dll,-344" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}\Shell\Open\command] + @="mmc.exe diskmgmt.msc" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{403ac161-c813-4819-b37f-3aacf0e12e0e}] +@="Disk Management" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}] +@="GOD Module" +"InfoTip"="All Control Panel items in a single view" +"System.ControlPanel.Category"="5" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}\DefaultIcon] +@="%SystemRoot%\\System32\\imageres.dll,-27" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}\Shell\Open\Command] +@="explorer.exe shell:::{ED7BA470-8E54-465E-825C-99712043E01C}" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{E91B00A7-97F2-4934-B06A-101C194D2333}] +@="All Tasks" + + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}] +@="GroupPolicy" +"InfoTip"="Starts the Local Group Policy Editor" +"System.ControlPanel.Category"="5" + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}\DefaultIcon] +@="%SYSTEMROOT%\\System32\\gpedit.dll" + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}\Shell\Open\Command] +@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\ + 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,6d,00,\ + 63,00,2e,00,65,00,78,00,65,00,20,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,\ + 00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,\ + 33,00,32,00,5c,00,67,00,70,00,65,00,64,00,69,00,74,00,2e,00,6d,00,73,00,63,\ + 00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{1695E87D-8BC9-4803-A701-D812E7C55223}] +@="Local Group Policy Editor" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}] +@="System Configuration" +"InfoTip"="Perform advanced troubleshooting and system configuration" +"System.ControlPanel.Category"="5" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}\DefaultIcon] +@="msconfig.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}\Shell\Open\Command] +@="msconfig.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}] +@="System Configuration" + +;041. Windows Error Reporting + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"DoReport"=dword:00000000 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 +"OobeCompleted"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"DoReport"=dword:00000000 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 +"OobeCompleted"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\PCHealth\ErrorReporting] +"ShowUI"=dword:00000000 +"DoReport"=dword:00000000 + + + +;042. AppCompat + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat] +"VDMDisallowed"=dword:00000001 +"DisableEngine"=dword:00000001 +"AITEnable"=dword:00000000 +"DisableInventory"=dword:00000001 +"DisablePCA"=dword:00000001 +"DisableUAR"=dword:00000001 +"SbEnable"=dword:00000000 +"AllowTelemetry"=dword:00000000 + +;043. Codecs + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows Media Foundation] +"EnableFrameServerMode"=dword:00000000 + +;044. More Optimization + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppHost] +"EnableWebContentEvaluation"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + + +[HKEY_CURRENT_USER\Control Panel\PowerCfg] +"CurrentPowerPolicy"="4" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters] +"IRPStackSize"=dword:00000032 +"AutoShareWks"=dword:00000000 +"DisableCompression"=dword:00000001 +"EnableAuthenticateUserSharing"=dword:00000000 +"ServiceDllUnloadOnStop"=dword:00000001 +"autodisconnect"=dword:0000000f +"enablesecuritysignature"=dword:00000000 +"requiresecuritysignature"=dword:00000000 +"restrictnullsessaccess"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main] +"AllowPrelaunch"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\0] +"0200"=hex:00,00,00,00,01,00,00,07,00,00,00,00,00,00,00,00,1e,00,00,00,00,00,\ + 00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,ff,\ + 00,ff,00,ff,ff,00,00,00,00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,\ + ff,ff,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 +"1700"=hex:00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,ff,00,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + ff,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB] +"AllowIdleIrpInD3"=dword:00000000 +"EnhancedPowerManagementEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBXHCI\Parameters\Wdf] +"NoExtraBufferRoom"=dword:00000001 + + +;045. PSCHED + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched] +"TimerResolution"=dword:00000001 +"MaxOutstandingSends"=dword:00000000 +"NonBestEffortLimit"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\DiffservByteMappingConforming] +"ServiceTypeGuaranteed"=dword:0000002e +"ServiceTypeNetworkControl"=dword:00000038 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\DiffservByteMappingNonConforming] +"ServiceTypeGuaranteed"=dword:0000002e +"ServiceTypeNetworkControl"=dword:00000038 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\UserPriorityMapping] +"ServiceTypeGuaranteed"=dword:00000005 +"ServiceTypeNetworkControl"=dword:00000007 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"SleepStudyDisabled"=dword:00000001 + + + +;046. Notification Setting + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpnUserService] +"Start"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging] +"EnableModuleLogging"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging] +"EnableScriptBlockLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings] +"NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK"=dword:00000000 +"NOC_GLOBAL_SETTING_ALLOW_NOTIFICATION_SOUND"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.AutoPlay] +"Enabled"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.SecurityAndMaintenance] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.StartupApp] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications] +"NoToastApplicationNotification"=dword:00000000 +"NoToastApplicationNotificationOnLockScreen"=dword:00000001 + +;047. Search Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Search] +"CortanaEnabled"=dword:00000000 +"AnyAboveLockAppsActive"=dword:00000000 +"BingSearchEnabled"=dword:00000000 +"CortanaCapabilities"=dword:00000000 +"CortanaCapabilityFlags"=dword:00000000 +"CortanaConsent"=dword:00000000 +"CortanaInAmbientMode"=dword:00000000 +"DeviceHistoryEnabled"=dword:00000000 +"HasAboveLockTips"=dword:00000000 +"IsAssignedAccess"=dword:00000000 +"IsMicrophoneAvailable"=dword:00000000 +"IsWindowsHelloActive"=dword:00000000 +"Start_TrackDocs"=dword:00000000 +"Start_TrackProgs"=dword:00000000 +"CanCortanaBeEnabled"=dword:00000000 +"DisableSearchBoxSuggestions"=dword:00000001 +"SearchboxTaskbarMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search] +"PreventIndexOnBattery"=dword:00000001 +"PreventIndex"=dword:00000001 +"DisableRemovableDriveIndexing"=dword:00000001 +"DisableWebSearch"=dword:00000001 +"ConnectedSearchUseWeb"=dword:00000000 +"ConnectedSearchUseWebOverMeteredConnections"=dword:00000000 +"AllowCortana"=dword:00000000 +"BingSearchEnabled"=dword:00000000 +"AllowCloudSearch"=dword:00000000 +"BackgroundAppGlobalToggle"=dword:00000000 + +;048. Cloud Content.. + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CloudContent] +"ConfigureWindowsSpotlight"=dword:00000002 +"IncludeEnterpriseSpotlight"=dword:00000000 +"DisableWindowsSpotlightFeatures"=dword:00000001 +"DisableWindowsSpotlightWindowsWelcomeExperience"=dword:00000001 +"DisableWindowsSpotlightOnActionCenter"=dword:00000001 +"DisableWindowsSpotlightOnSettings"=dword:00000001 +"DisableThirdPartySuggestions"=dword:00000001 +"DisableTailoredExperiencesWithDiagnosticData"=dword:00000001 +"DisableWindowsConsumerFeatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications] +"NoCloudApplicationNotification"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History] +"DaysToKeep"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] +"LowRiskFileTypes"=".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.msu;.wav;" + +;049. Crash on Ctrl+Scroll + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt\Parameters] +"CrashOnCtrlScroll"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Parameters] +"CrashOnCtrlScroll"=dword:00000001 + +;050. Touch Latency + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TouchPrediction] +"Latency"=dword:00000001 +"SampleTime"=dword:00000001 +"UseHWTimeStamp"=dword:00000001 + + +;051. Windows Explorer + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Feeds] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DataSharing] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing] + + +[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"GreyMSIAds"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System] +"AllowCrossDeviceClipboard"=dword:00000000 +"DisableAcrylicBackgroundOnLogon"=dword:00000001 +"AllowClipboardHistory"=dword:00000000 +"EnableSmartScreen"=dword:00000000 +"EnableFontProviders"=dword:00000001 +"DisableHHDEP"=dword:00000001 +"DisableForceUnload"=dword:00000001 +"SlowLinkDetectEnabled"=dword:00000000 +"DeleteRoamingCache"=dword:00000001 +"CompatibleRUPSecurity"=dword:00000001 +"AllowBlockingAppsAtShutdown"=dword:00000001 +"AllowClipboardHistory"=dword:00000000 +"EnableActivityFeed"=dword:00000000 +"PublishUserActivities"=dword:00000000 +"UploadUserActivities"=dword:00000000 +"DisableLockScreenAppNotifications"=dword:00000001 +"RSoPLogging"=dword:00000000 +"DisableForceUnload"=dword:00000001 +"EnableSmartScreen"=dword:00000000 +"EnableMmx"=dword:00000000 +"EnableCdp"=dword:00000000 +"AllowBlockingAppsAtShutdown"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes] +"ThemeChangesMousePointers"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] +"NoAutoUpdate"=dword:00000001 +"EnableFeaturedSoftware"=dword:00000000 +"IncludeRecommendedUpdates"=dword:00000000 +"UseUpdateClassPolicySource"=dword:00000001 +"NoAUShutdownOption"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\Local] +"WCMPresent"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\GroupPolicy] +"fDisablePowerManagement"=dword:00000001 +"fSoftDisconnectConnections"=dword:00000000 +"fMinimizeConnections"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseHoverTime"="1" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FindMyDevice] +"AllowFindMyDevice"=dword:00000000 +"LocationSyncEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NvCache] +"OptimizeBootAndResume"=dword:00000000 +"EnablePowerModeState"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{0DA965DC-8FCF-4c0b-8EFE-8DD5E7BC959A}\{7E01ADEF-81E6-4e1b-8075-56F373584694}\{F6CC25DF-6E8F-4cf8-A242-B1343F565884}\{BDB3AF7A-F67E-4d1e-945D-E2790352BE0A}] +@="{db57eb61-1aa2-4906-9396-23e8b8024c32}" +"Operator"=dword:00000002 +"Type"=dword:0000103d +"Value"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{0DA965DC-8FCF-4c0b-8EFE-8DD5E7BC959A}\{7E01ADEF-81E6-4e1b-8075-56F373584694}\{F6CC25DF-6E8F-4cf8-A242-B1343F565884}\{CD9230EE-218E-44b9-8AE5-EE7AA5DAD08F}] +@="{db57eb61-1aa2-4906-9396-23e8b8024c32}" +"Operator"=dword:00000002 +"Type"=dword:0000100a +"Value"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\EdgeUI] +"DisableMFUTracking"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule] +"DisableRpcOverTcp"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client] +"ShowShutdownDialog"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WlanSvc\AnqpCache] +"OsuRegistrationStatus"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Control Panel\Desktop] +"ScreenSaveActive"="0" +"EnablePerProcessSystemDPI"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EnhancedStorageDevices] +"TCGSecurityActivationDisabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PreviousVersions] +"DisableLocalPage"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] +"SystemRestorePointCreationFrequency"=dword:00000000 + +[HKEY_CLASSES_ROOT\SystemFileAssociations\image] +"Treatment"=dword:00000000 + +[HKEY_CLASSES_ROOT\SystemFileAssociations\video] +"Treatment"=dword:00000000 + +;052. Windows Store Apps + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore] +"AutoDownload"=dword:00000002 + + +;053. IE + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Security] +"DisableSecuritySettingsCheck"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security] +"DisableSecuritySettingsCheck"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\SQM] +"DisableCustomerImprovementProgram"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions] +"NoHelpItemSendFeedback"=dword:00000001 +"NoHelpItemTipOfTheDay"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"HideNewEdgeButton"=dword:00000001 + + +;054. Realtek Bluetooth Latency + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\BTHLEDevice\{00001812-0000-1000-8000-00805f9b34fb}_Dev_VID&02046d_PID&b34f_REV&0021_ff773a4381ed\9&1d91d97b&0&0021\Device Parameters] +"RetainWWIrpWhenDeviceAbsent"=dword:00000001 +"HighDutyCycleScanWindow"=dword:00000012 +"HighDutyCycleScanInterval"=dword:00000024 +"LowDutyCycleScanWindow"=dword:00000012 +"LowDutyCycleScanInterval"=dword:00000400 +"LinkSupervisionTimeout"=dword:0000000c +"ConnectionLatency"=dword:00000001 +"ConnectionIntervalMin"=dword:00000001 +"ConnectionIntervalMax"=dword:00000001 + +;055. UAC + Virtualization 2 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] +"ConsentPromptBehaviorAdmin"=dword:00000000 +"ConsentPromptBehaviorUser"=dword:00000000 +"DSCAutomationHostEnabled"=dword:00000000 +"EnableCursorSuppression"=dword:00000000 +"EnableInstallerDetection"=dword:00000000 +"EnableLUA"=dword:00000000 +"EnableSecureUIAPaths"=dword:00000000 +"EnableUIADesktopToggle"=dword:00000000 +"EnableUwpStartupTasks"=dword:00000000 +"EnableVirtualization"=dword:00000000 +"PromptOnSecureDesktop"=dword:00000000 +"scforceoption"=dword:00000000 +"shutdownwithoutlogon"=dword:00000001 +"undockwithoutlogon"=dword:00000001 +"NoInternetOpenWith"=dword:00000001 +"EnableFirstLogonAnimation"=dword:00000000 + + +;056.Notepad Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Notepad] +"StatusBar"=dword:00000001 +"fWrap"=dword:00000001 +"fSavePageSettings"=dword:00000001 +"fSaveWindowPositions"=dword:00000001 +"fWindowsOnlyEOL"=dword:00000000 +"fPasteOriginalEOL"=dword:00000001 + +[HKEY_CLASSES_ROOT\*\shell\Open with Notepad] +"Icon"="notepad.exe,-2" + +[HKEY_CLASSES_ROOT\*\shell\Open with Notepad\command] +@="notepad.exe %1" + + +;057. MRT Tool + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MRT] +"DontOfferThroughWUAU"=dword:00000001 +"DontReportInfectionInformation"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 + + +;058. USB Flags + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\usbflags] +"fid_D1Latency"=dword:00000001 +"fid_D2Latency"=dword:00000001 +"fid_D3Latency"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"UseOLEDTaskbarTransparency"=- +"EncryptionContextMenu"=dword:00000000 +"HideFileExt"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer] +"HidePeopleBar"=dword:00000001 +"NoUseStoreOpenWith"=dword:00000001 +"DisableSearchBoxSuggestions"=dword:00000001 +"NoPinningStoreToTaskbar"=dword:00000000 +"NoWindowMinimizingShortcuts"=dword:00000001 +"NoDataExecutionPrevention"=dword:00000001 +"NoHeapTerminationOnCorruption"=dword:00000001 +"NoNewAppAlert"=dword:00000001 +"DisableContextMenusInStart"=dword:00000000 +"HideRecentlyAddedApps"=dword:00000001 +"ShowOrHideMostUsedApps"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\IPMI] +"BusyWaitPeriod"=dword:000000001 +"BusyWaitTimeoutPeriod"=dword:00000001 +"CommandWaitTimeoutPeriod"=dword:00000001 +"IpmbWaitTimeoutPeriod"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF] +"LogEnable"=dword:00000000 +"LogLevel"=dword:00000000 + +;059. Windows Installer Service in Safe Mode + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer] +@="Service" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] +@="Service" + +[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] +"SyncMode5"=dword:00000003 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] +"SyncMode5"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"DEPOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\QoS] +"Tcp Autotuning Level"="Experimental" +"Application DSCP Marking Request"="Allowed" + +;060.Icon Set + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Icons] +"29"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 +"77"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 +"179"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 + +;061. iSCSI Optimization + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\iSCSI] +"ChangeIQNName"=dword:00000001 +"RestrictAdditionalLogins"=dword:00000001 +"ChangeCHAPSecret"=dword:00000001 +"RequireIPSec"=dword:00000001 +"RequireMutualCHAP"=dword:00000001 +"RequireOneWayCHAP"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer] +"PreventCodecDownload"=dword:00000001 + +;062.File History + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\FileHistory] +"Disabled"=dword:00000001 + + +;063. End + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\MobilityCenter] +"NoMobilityCenter"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes] +"ThemeChangesMousePointers"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters\Config\VpnCostedNetworkSettings] +"NoRoamingNetwork"=dword:00000001 +"NoCostedNetwork"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Maintenance] +"MaintenanceDisabled"=dword:00000001 +"WakeUp"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\StorageHealth] +"AllowDiskHealthModelUpdates"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\StorageSense] +"AllowStorageSenseGlobal"=dword:00000000 +"AllowStorageSenseTemporaryFilesCleanup"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Maps] +"AutoDownloadAndUpdateMapData"=dword:00000000 +"AllowUntriggeredNetworkTrafficOnSettingsPage"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Messaging] +"AllowMessageSync"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetCache] +"SyncAtLogon"=dword:00000000 +"SyncAtLogoff"=dword:00000000 +"SyncEnabledForCostedNetwork"=dword:00000000 +"EconomicalAdminPinning"=dword:00000000 +"NoReminders"=dword:00000001 +"NoMakeAvailableOffline"=dword:00000001 +"NoCacheViewer"=dword:00000001 +"NoConfigCache"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Network Connections] +"NC_PersonalFirewallConfig"=dword:00000000 +"NC_DoNotShowLocalOnlyIcon"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NDIS\Parameters] +"TrackNblOwner"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer] +"DisableLoggingFromPackage"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate] +"DoNotUpdateToEdgeWithChromium"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\OOBE] +"DisablePrivacyExperience"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HomeGroup] +"DisableHomeGroup"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HotspotAuthentication] +"Enabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole] +"DefaultLaunchPermission"=- +"EnableDCOM"="N" +"LegacyImpersonationLevel"=dword:00000002 +"MachineAccessRestriction"=- +"MachineLaunchRestriction"=- + +;064. WCN Registrator + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WCN\UI] +"DisableWcnUi"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars] +"EnableRegistrars"=dword:00000000 +"DisableUPnPRegistrar"=dword:00000000 +"DisableInBand802DOT11Registrar"=dword:00000000 +"DisableFlashConfigRegistrar"=dword:00000000 +"DisableWPDRegistrar"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services] +"fAllowToGetHelp"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service] +"AllowUnencryptedTraffic"=dword:00000000 + +;065. Sandbox Tweaks + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Sandbox] +"AllowVideoInput"=dword:00000001 +"AllowVGPU"=dword:00000000 +"AllowPrinterRedirection"=dword:00000000 +"AllowNetworking"=dword:00000000 +"AllowClipboardRedirection"=dword:00000001 +"AllowAudioInput"=dword:00000001 + + +;066. Event log + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest] +"UseLogonCredential"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters] +"SupportedEncryptionTypes"=dword:7ffffff8 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EdgeUI] +"DisableMFUTracking"=dword:00000001 +"DisableHelpSticker"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EventLog\ProtectedEventLogging] +"EnableProtectedEventLogging"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EventLog\Setup] +"Enabled"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\fssProv] +"EncryptProtocol"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WDI\{affc81e2-612a-4f70-6fb2-916ff5c7e3f8}] +"ScenarioExecutionEnabled"=dword:00000000 +"EnabledScenarioExecutionLevel"=dword:00000000 + +;067. Your Phone API + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client] +"PreventAutoRun"=dword:00000001 +"CEIP"=dword:00000002 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\ms-phone-api] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\tbauth] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\windows.tbauth] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\windows.yourphone.api] + + +;068 ! (reveu 063, 065 si 067) + + +[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download] +"CheckExeSignatures"="no" +"RunInvalidSignatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MdmCommon\SettingValues] +"LocationSyncEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation] +"AllowOfflineFilesforCAShares"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\Maps] +"AutoUpdateEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge] +"TrackingPrevention"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScheduledDiagnostics] +"EnabledExecution"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub\hubg] +"DisableOnSoftRemove"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers] +"authenticodeenabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\SettingSync] +"DisableSettingSync"=dword:00000002 +"DisableSettingSyncUserOverride"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications] +"GlobalUserDisabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppPrivacy] +"LetAppsRunInBackground"=dword:00000002 + +;070. Delivery Optimization Disable + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\DeliveryOptimization] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"DEPOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NVDisplay.ContainerLocalSystem\LocalSystem\NvcDispCorePlugin] +"DisableLoad"=dword:00000001 +"LogFile"="-" +"LogLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Reliability Analysis\WMI] +"WMIEnable"=dword:00000000 + + +;070. Remove ControlPanel and Settings Applets + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"NoRemoteRecursiveEvents"=dword:00000001 +"DisableThumbnails"=- +"MemCheckBoxInRunDlg"=dword:00000001 +"NoInstrumentation"=dword:00000001 +"ConfirmFileDelete"=dword:00000000 +"AllowOnlineTips"=dword:00000000 +"NoRemoteRecursiveEvents"=dword:00000001 +"StartMenuFavorites"=dword:00000000 +"Start_ShowHelp"=dword:00000000 +"Start_ShowMyComputer"=dword:00000001 +"Start_ShowRun"=dword:00000001 +"SettingsPageVisibility"="hide:quiethours;tabletmode;multitasking;project;crossdevice;clipboard;remotedesktop;typing;pen;autoplay;;mobile-devices;network-dialup;network-directaccess;maps;appsforwebsites;videoplayback;startupapps;sync;speech;gaming-gamebar;gaming-gamedvr;gaming-broadcasting;gaming-gamemode;;search-permissions;cortana-windowssearch;search-moredetails;privacy;privacy-speech;privacy-speechtyping;privacy-feedback;privacy-activityhistory;privacy-location;privacy-voiceactivation;privacy-notifications;privacy-accountinfo;privacy-contacts;privacy-calendar;privacy-callhistory;privacy-email;privacy-eyetracker;privacy-tasks;privacy-messaging;privacy-radios;privacy-customdevices;privacy-backgroundapps;privacy-appdiagnostics;privacy-automaticfiledownloads;privacy-documents;privacy-pictures;privacy-documents;privacy-broadfilesystemaccess;delivery-optimization;windowsdefender;backup;troubleshoot;findmydevice;;holographic-audio;privacy-holographic-environment;holographic-headset;holographic-management;" + + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl] +"1"="Microsoft.ProgramsAndFeatures" +"2"="Microsoft.DefaultPrograms" +"3"="Microsoft.StorageSpaces" +"4"="Microsoft.FileHistory" +"5"="Microsoft.ActionCenter" +"6"="Microsoft.DateAndTime" +"7"="Microsoft.SpeechRecognition" +"8"="Microsoft.EaseOfAccessCenter" +"9"="Microsoft.DevicesAndPrinters" +"10"="Microsoft.PenAndTouch" +"11"="Microsoft.AutoPlay" +"12"="Microsoft.MobilityCenter" +"13"="Microsoft.Taskbar" +"14"="Microsoft.TextToSpeech" +"15"="Microsoft.Troubleshooting" +"16"="Microsoft.SyncCenter" +"17"="Microsoft.Keyboard" +"18"="Microsoft.Mouse" +"19"="Microsoft.Personalization" +"20"="Microsoft.TabletPCSettings" +"21"="Microsoft.System" +"22"="Microsoft.AdministrativeTools" +"23"="Microsoft.CredentialManager" +"24"="Microsoft.PhoneAndModem" +"25"="Microsoft.RemoteAppAndDesktopConnections" + +;071. Adobe Acrobat Reader + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown] +"bAcroSuppressUpsell"=dword:00000001 +"bDisablePDFHandlerSwitching"=dword:00000001 +"bDisableTrustedFolders"=dword:00000001 +"bDisableTrustedSites"=dword:00000001 +"bEnableFlash"=dword:00000000 +"bEnhancedSecurityInBrowser"=dword:00000001 +"bEnhancedSecurityStandalone"=dword:00000001 +"bProtectedMode"=dword:00000001 +"iFileAttachmentPerms"=dword:00000001 +"iProtectedView"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cCloud] +"bAdobeSendPluginToggle"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\DC\Installer] +"DisableMaintenance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms] +"iURLPerms"=dword:00000003 +"iUnknownURLPerms"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices] +"bToggleAdobeDocumentServices"=dword:00000001 +"bToggleAdobeSign"=dword:00000001 +"bTogglePrefsSync"=dword:00000001 +"bToggleWebConnectors"=dword:00000001 +"bUpdater"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Adobe\Acrobat Reader\DC\Installer] +"DisableMaintenance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cSharePoint] +"bDisableSharePointFeatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWebmailProfiles] +"bDisableWebmail"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWelcomeScreen] +"bShowWelcomeScreen"=dword:00000000 + +;072. intel CPU Tweak + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm\Parameters] +"AcpiFirmwareWatchDog"=dword:00000000 +"AmliWatchdogAction"=dword:00000000 +"AmliWatchdogTimeout"=dword:00000001 +"WatchdogTimeout"=dword:00000001 + + + +;073. WinLogon + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] +"EnableFirstLogonAnimation"=dword:00000000 +"AutoRestartShell"=dword:00000001 + + +;074. Firewall Rules + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] +"{1A6BFAD8-BA8C-4474-8E25-C9DB3D46523F}"="v2.31|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow TCP IN|EmbedCtxt=Fingerprint Unlock Module|" +"{A2D1CA01-D51F-4E64-9229-3D56A29D0D5C}"="v2.31|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow TCP OUT|EmbedCtxt=Fingerprint Unlock Module|" +"{64C4F529-DB31-425A-BA71-FBA3C881ADDC}"="v2.31|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow UDP IN|EmbedCtxt=Fingerprint Unlock Module|" +"{AA2CBA97-F20A-4A2B-98D0-6D1F84A6984D}"="v2.31|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow UDP OUT|EmbedCtxt=Fingerprint Unlock Module|" +"{ADEDD497-D9EB-4573-B73F-86C68AA3F377}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{6139A3AA-99A5-491F-843C-E343C83226F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{8DFBCF37-3975-4054-939D-280B80AC6E86}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{E4D61D8A-D28E-43BC-BA9F-B5E0138266AB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{E7763690-64E1-4AE6-92F6-2A0D87D372A0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{6AEC363C-0E0E-4041-ADC8-0B47ED7EF74E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{1ABEA816-DF00-4EC6-897D-D6BCB81779F8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{FBBDCD38-3A64-4C43-B4A6-C1F40A2AC511}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{D3BA6B7E-E614-49A5-AFE9-454EAD516B02}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{1FB7E5CC-1994-459D-BB57-C8CEA982B76C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{26FEAEAE-8808-4FCC-B50B-CA02A1F047C7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{25344817-661E-4748-932A-118CA38A025D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{7E32EF31-E1D6-4E7E-8D58-5035C9C491CB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{6DA9BD19-8492-4D26-A7AF-4B860CA20C61}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{3651797E-8F96-4813-AD2E-460ADF002D00}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D0C84C00-07C1-4D6D-9B55-CA2BD5DF88EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{05029DD4-6EF0-49FE-A265-C513E5A7DF9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{37D599B3-186C-40CB-B5C8-571F21AA33A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{A0CBF3AC-8C34-49AB-B202-35B0B22FEF88}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{1E803FB5-8410-42E3-843A-81C9874C7F16}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{3C642422-BC3E-4ACD-B7F0-873BACFE49B3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{2BCD3201-BC30-4F7F-81B2-45F59FCE9E52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F9AF067C-4A5E-4E27-886B-7BA01D57288C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{C89EFE6C-D514-483F-8608-799F1D11A309}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{2B50A864-E362-413F-B5FE-968D1D245132}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{2B58C6EB-1517-4EBB-BEA1-5E6B73FB7CF2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{451DCB00-92D3-4E01-8887-C462B74403B8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{57A0B1B2-EF30-4D6C-9FB7-D00CA393076A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{5691EAC0-5F14-4408-8652-46DD343F9238}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{F9B9EC52-6807-4987-988F-498859D5DFE7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{385551D0-2252-4C36-A349-0F6EA655235D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{F84AC383-9EEA-416A-8DC8-F3B62A46F92F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{29184E50-2741-444E-91DA-CF486FA362A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{52105157-D0B0-4863-BA19-D0DFD3054F32}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{EF7399D0-D073-4059-9717-D7F70605DBEE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{4AD5E10F-12E7-4875-9397-2205503D6255}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{3EB9C4E5-BF5C-4E42-8EBE-D88BCBB59FC5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{1B714C6D-DAA5-4277-93EC-092C2AF6D3F0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{CE039632-AD10-4BC5-A7C2-04EEB8F1970B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{75785327-A85E-422E-960A-823B6043C8A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{00F392E1-684A-4B57-8D28-AFD1AF3A33D6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{BD4B74D4-3CC4-46A7-B2CC-CD786CBE2408}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{58A67B88-585B-4E41-B914-140E95345797}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4A97C06B-7032-40B2-BA73-B05CB9B89624}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{82F59B86-B68D-4AF6-A05A-5DB6CBCFCFDD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{EF8FB5D4-A7B0-4642-81C7-AE744D4CB526}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D8463C28-4598-4C25-94C4-7E91E059411B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{94742D91-C3AB-4EFB-A3CF-3E9001D09065}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{0B5EA8E4-2904-4397-9062-B2E62D18D94F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{7EEA5128-2E77-429A-AAA0-1DCE104EA2CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{B5222588-9C53-4CA5-ADB1-5463F5BB381A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{EED9D903-BE0E-49E1-9063-58DD50FE876B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{9BA3B229-DBAA-46C7-B6A0-9C83F159DF70}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{B8CB1011-3DA3-4608-8386-DE12D17669CC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{8791D9AD-53E3-4633-B1A0-7E5433CA2875}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{F9D7DD31-D683-4DE6-A800-A123A39C4BC7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{A41CE4B9-FF56-4D7E-B7BD-124CF5A8A3F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{97A9560C-CED7-449F-B079-08E62B51BD6F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{913BA024-8698-4F60-8C7E-8F5D064242C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{AD537B18-7F52-441C-9D66-CE40DD60DD60}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{9F6C7D64-5F24-40BF-878E-5457D7D7FBCC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{BCE469CF-5FE3-402A-B5B2-3F5D3F312E05}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{F5583B4E-B7F0-4067-8482-998393C95021}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{9B963A37-0068-4A90-8C95-795DBA0D7A16}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{1D787C2A-20A0-4BB6-83D4-2B608D44A651}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{1CE30DC2-EF9A-4249-8421-E74F20FBEAE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{EB3728FE-D673-4B46-9C92-EB1753836C78}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{C8579BB8-4A1B-4D38-95A8-10B2DDBAD0AA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{A5443D36-6407-4A5C-9C26-F849B53800D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D283E223-E9FC-425E-8AD6-A33BAA9478E0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{3541E389-7992-4DB5-ABB1-A28F480FEFAA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{D9A3D2C6-1C0E-48A2-80D7-9282DDEED833}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{F3226711-34BE-411C-8EB6-1B53F1335D12}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{F9C956B0-5D4D-4761-BE5B-9331F57103A6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{5618F44B-E606-4B5E-B4E6-B5DF4F7A39E4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{221B7B28-499B-4113-865A-023E629A2665}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{477E4F55-3DBA-443A-8E26-1BF01CAE6F10}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{E98A936E-FD56-43FB-B4AF-515C9DC49E28}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{F8292803-C899-46F1-B956-820F89B28717}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A9C34DC6-36A9-4A24-84EC-8E2ED3F10E78}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{47706A1F-014E-4567-93B2-07B6D78974C5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{04B25DAB-31BD-42A2-9110-F98202619486}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{65C7F1F9-6F89-4DF8-A853-DBE7F4494939}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{92013DA1-B7F2-4885-A334-402A12D1EB21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{3D7E67B0-BA2E-462A-9760-AE229FC4E1AF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{8E53E989-28F3-44D2-9837-4CBEA1EAD7FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{77C6580C-A3B4-42E4-8D1C-05B0FB6D788B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{D6144267-D624-45FC-B279-B13E49F47901}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{F87E0087-CF47-4310-B96D-83AC94DCAA21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{6046898F-4B34-4C7B-A2E9-7309DB33AFF9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{8A47685B-2CE1-4997-9010-842F5D9E4C10}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{ECB0F8CC-D20D-4E40-AF06-62794E084FBD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{956A255A-0A14-442E-B0E3-671852BB5F20}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{3B75B607-EE3A-47FD-9AE0-1989F2A1E9EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{96EA7030-070C-4A29-AF9F-5A9115A043C3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{5B553C76-0D9C-48C7-A659-DF0765FA33BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{7338396A-D104-45F7-807C-3F882D47394F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{9956434E-7003-4C4B-BCBA-ED7C3585E569}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{B1820254-717D-4011-ABEA-15BA6C578580}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{586048D2-3A85-4436-909D-6CD61404EA84}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{ED0F819A-1E21-49C5-AFB6-763E73B3751C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{E823ABA8-9DD5-4016-A405-02E863B3493D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{994B0AAA-69F0-45C3-B999-EB57F185FAF5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{B529D897-AA88-423A-B57B-5749F062679B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{44D615DF-EA26-45A2-8EA1-04903F524600}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{1D03F092-29D6-4025-8233-1F73692665B0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{0BC5A9C7-6AD2-491F-B34D-8012D59AB9C4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{74A8D3D8-5B4A-4285-8E67-BC79EDB5E22E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{76F33769-EE9C-41E4-A76A-99C0DF92FA28}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{923C619F-AF59-4DE2-AD90-60393B4FC253}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{5A55BE7A-ED8F-46F0-8E4E-F9818499EF6E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{C3580C2E-88A2-419C-A4BD-AF902E919376}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{CCAE9171-B2BF-487F-BFCE-E7C58021D327}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{9604DB6A-5F98-43FE-A57D-E02496D84F0B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{840110FD-C296-49DC-9E8C-F0FF7CF8D338}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{D816EF80-C794-4C32-A738-51454E094BE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{FFE5515C-A5A8-4601-AD1D-1BEC708655A0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{0D08E371-8CD1-4985-89CB-C3F532539931}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{84825376-38FF-43D7-80A6-5E137AE5A569}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{882909F6-40EC-41CF-944C-5EEBA66C9100}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{237C330E-8CA5-4886-83E4-E52F9250D777}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{602B88F3-EF51-41D7-A29A-D440509E4D2C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{54C24BC7-9347-4492-828F-7CF404D50E97}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{444806C9-54E0-4EB3-B29F-7CA1B7F76C17}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{1167EBFA-9095-46E4-B8F0-F4521B2A8D3F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{9A51CF52-8B27-4AFF-8D77-559637CEDC8B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{BB3B0896-276B-44A5-A601-1758E0D47278}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{B32F1CD4-AFB1-4634-9865-05BC344D728E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{98724BDF-7A04-4D5E-AB20-D5B290615B77}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{C800A94C-CF93-44C0-AE32-2A7B0DC9F2EC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{88524DF2-C0DE-4907-B8CC-294928A5EB44}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{18C7302B-58FC-4BAD-94E8-5E4FE08F514A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{BA617ECF-4367-4A99-A370-8F30618CB761}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{1F6BC906-CED4-4232-9A56-51DF78997488}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{5868933A-5A35-4F2F-95D1-7C1F63D311C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{419905C1-4BBB-4D38-84DA-68A6E4431DC1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{7BB8293E-1B33-4377-9AD7-CED99DF04A55}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{3DDEF07C-3614-4C97-8C3B-C4B63D732800}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{8321D4B2-FC5D-4A41-9B11-4E31C993623B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{396CD532-1AB6-462E-80E0-2360B128B998}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{445FC3F9-1647-498E-B89D-D0517369B313}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{18762016-25DA-480E-A31A-BE251DE4A663}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{830CA81E-AEE4-4F7A-BE20-1DD702F42E48}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{6350333A-2A8A-412A-B92B-4EEA2D7B15CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{F6A6EF37-7CAB-4772-8465-C824E049F228}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{4E5BCAEE-1D6A-44D5-9910-FCA06EB4D419}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{4CE2AF1D-897E-424A-AADB-A8F7F3E15D0D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{62EEAD21-7B97-4573-A842-901358A87FCA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{73C961E5-5B42-4D5F-8090-2D520503AC2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4C9597A8-ED5B-4FEE-AF1A-D5B7ACB556DF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{41C9FA3D-AFB3-4C4F-8172-E01D0E1F292F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{996040C7-C60C-471A-A3E9-9F402BB54DE5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{AD125FB1-2F9D-413D-AE8D-E3AA7B7D9C92}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{2A189D20-C0CE-4C3E-8BAD-40A0ABE593DB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{66282D57-7671-4E26-92AB-FBE05D599B0D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{4B333796-5ECE-427A-A270-A94A29D45D7B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{A49BFFBF-6B22-4CBB-905D-9388D0D8E853}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{51BCE67A-6A52-41D5-B819-17CF3E7A7FF9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{2F6D6151-F9B7-4A00-88FE-A6D7AF70DD33}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{970D64EB-EB84-41B1-912D-5B9492E048D2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{2292CC30-3D4F-412A-A7DA-C59F30FD7BD7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{B753A166-5A60-4D15-A8D4-94A79E2D21E3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{2BF836ED-A5ED-4A8E-9106-9E5D3D02737F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{A24D220C-73FF-4DE5-AE4F-1F26CBB25433}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{27A43AEF-27E7-4965-A3CE-C0B309D818D4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{38FF9317-D383-4628-8B75-C2E35469F09E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0D6131BC-DE8D-4B85-987F-56E0C7326CA7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{D42B1A61-42CB-4BA2-9009-DA96CF9B4D39}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{C66DD24F-9F54-4D64-8ABD-DC2C76FC35E2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{1FC41BD3-A102-4484-8567-82C5D99C618D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{D7158814-C472-4F55-B1E1-E783706EB61D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{0A2BA905-07F7-4E41-8C31-2BFF1ACC9818}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{F31B4288-3C78-44F7-BE6A-2C15B30CE308}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{1225F521-B194-4F12-85C7-B0850E58A4B5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{60DF971C-8FF1-4A26-B761-03DAAE2F9E23}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{5952EE95-EFA6-4CFA-BC4B-A3261668C66C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{DEED4512-FE7C-4DE1-B14A-CD122739C1AA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{3F16D408-79DE-4932-A23C-E915A6E2CC00}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{742E95EA-CC2C-43A4-8B8A-EB9E80B55FAE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{7E816C99-850F-426B-8022-EF18117F6D62}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{4EBCDADA-234A-47A2-B1CB-BC35BD16214B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{86C8D379-9E38-443C-8F51-0A0FA761FDAF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{8CD1C63A-3DE9-424D-BA6E-DE8A9494D340}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{C9A494A4-47C1-495A-8680-1AC853DF67B4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A76DC0F8-FCC7-4306-B39A-E177167D675A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{C2794317-6FD2-437C-A781-449C5400F19B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{1A62BFE4-2EB9-43D1-8D57-92A80AF054A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{9B12861A-54D3-4385-B12D-55AD087F80AC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{2CF3E5FB-3D2F-418B-B26E-C02D7D19C763}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{C1728706-D583-4CEF-A6D4-A4013FD07FD9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{85B7E324-FAAF-4846-914B-B1578FD2463D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{930E4CDF-0B9F-4A5B-851C-E9D22E92D0FF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{ED1333B0-A38D-4C62-BEC8-CB89847D40AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{84FDBCD6-0BF4-4557-8010-EA4954C3304D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{55567EBF-38CC-463F-A9C4-81ACEBB5AE3A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{4B897D2B-856C-4D4B-9BA6-421EE5DC6D87}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{087AF2AE-7159-46CD-95E7-DE3D8112EEE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{85F7EF93-965A-4D9A-AFEE-986EFBAD0D19}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{831447DC-C38B-4AB2-B09E-991556598ABC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{4970DDF1-D1EB-4450-B341-E4188360A9A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{7ADFE507-30FB-42F0-8DB9-91D04E572DB6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4B47C2E3-A030-42A4-B8A3-656A76355622}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{E3917AE8-6AD3-41C7-8E73-AA9E308D2E6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{806A68C9-159E-4800-A4F6-7E43157CAC7A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{25D05800-49CD-491F-A193-4F2B7904D5C2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D66BA010-3DCB-4213-89B3-0BCE4B9C31A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{E7A96B26-8C91-498F-99EA-4198C1AA3D5F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{06185A7C-CFCF-4F8B-A11E-A1A8C59241C6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{ADE50361-73ED-402A-BED0-D83CE73FE012}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{0720EDD9-C226-4619-9246-6ED175FE72E6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{45A6720C-90C8-4397-9822-D98E9DBC30F1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{DA92DE42-5811-470E-A116-336A0635EABE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{AB335667-3D21-4921-8524-61C58916A9AF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{59213E32-ABF6-4459-93AA-5B98576B4356}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{54115EBC-91E2-405B-AFAF-08FEF8C89ABD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{7BFA7B88-F361-47AB-82D8-0DC331D7A4C0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{32CB1C98-3F3F-4FB3-97AC-9C6C8052EB3A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{23FD16CF-C432-4158-BCB3-242368F23B01}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{24C576D0-C6AC-402E-A7B9-944EF9131666}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{62C8E5B2-0FBD-4B41-BED2-53CC4C915700}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{B9E323AF-A847-40A7-A2D2-E7E63181EDE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{ABEDF61E-B727-4090-8BFD-25B3F1E0B7FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{9975673F-813F-4503-97BB-E89AAD93C6BD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{7A5A3377-9F40-43C7-B7A3-C16CE651DD2D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{AC4151C0-BCA9-4800-85B0-46F9C3C0A5F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{21315192-4267-490F-A99C-BE823B0CF38D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{2757E499-0A7A-41CB-BBF1-2F1ACF98CEA6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{A4ADAA4B-3BD7-4AA8-8446-5D3A3400F6A1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{AC3C0900-D66D-48CE-BD7C-0F8EBAAAB8E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{34C352A8-E57A-424C-8816-5C6D2C0A0FCC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{5EDF99BF-D5AB-49E3-B59C-C9CA40DA7049}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{E37D60EE-6DDC-4556-8A37-24C209E51A5F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{9BCEB768-1D44-47DC-8495-53480ECB1DC6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{0D0840F0-B77D-41D9-8C71-9DB86952D65E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{53D6BEE5-5883-489D-8E51-12AA49F727DE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{EB9D16ED-98FF-497D-B7CF-89E7EACDFD66}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{B9C32014-5270-4EBE-9570-FE54A3009FCA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{571CB96C-2F3E-4A3D-8EEE-BA85807E15A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{61B6B6BB-85E0-4FFE-B84F-4A7391CDA9E9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{44905744-600D-4B6B-92D3-B9E77CE55BF8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{836BA3D2-4B15-4961-8937-C6FA117DC1B3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{43E2C103-2856-4DAE-AFE6-F77E9BA662E7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{0A28D9A3-C1BF-407D-9EA5-46C23AB2561A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{63D99D74-FA6D-4DF4-BC49-B34D52C1DBC9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{4B946B93-E862-4975-9692-CD3E77F0B07B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{6AC91EFA-85B0-45B3-A51D-1F28461326AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{54453F96-53A4-4A0B-BAA5-ACE5F4685E80}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{5BB6228B-B0E1-41BE-8902-5124236D98D8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{09047D4A-9A01-416F-B7BA-681ABD5C785D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{6F5A9E1D-67D2-4709-BAB3-BC51DEAA0157}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{734F27DF-AF33-4083-9CE5-BE793E6ECD3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{877F399F-0DDF-4376-A079-401739E6E9B7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{736C5DED-45F3-43E7-BB0C-F3E675F0CC59}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{DA4EBA7E-84F6-4298-9351-AE6D3D71BF82}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{9110BA3B-2F0B-4518-8588-700443768238}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{6501C792-B8AA-40AE-89BB-4AF01CC698FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{EDF7CEC0-E4BE-4465-991A-52E5502E024C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{A716A6B1-F721-40A3-848B-2FDD326B3EE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{039B198D-705E-49B3-9E3D-828B56FD59D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{F7162BAF-365F-4D5D-B271-5BD418F01975}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{7EAE5C3D-307B-462A-A858-EA0B594CE82B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{63B55664-E517-41AE-9F09-DFCBFF9AC504}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{CE52B9D1-5897-4F03-9018-5DCDC89EDC2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{BC8BFA97-1F9D-457A-BCF3-109534E78138}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{CB28C9A0-0A12-4F2D-83DC-72BF557F7FEF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{2B5B36AD-4AF6-434A-A1CF-416AFA0FA052}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{E8743456-58A6-48D5-A52E-403C70C6ECA2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{3D3774C7-82FD-4550-8234-E64978B556FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{0810CCDB-D870-4EF4-BDB3-389917F04E80}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{50A0D057-8D59-4043-826B-7B6EC25210C8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{7577A582-AD09-4B6D-B4B9-F15A8BE752DC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{428F75FB-A150-4C1F-9B88-C2AEFA2B3A84}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{AE1F4440-4039-4A5B-BA84-B33D3E67EAD0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0AEEE225-A289-48BE-B94E-BB445DF9A42E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{41D429AD-F908-4F95-BB4D-277783A8CC9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{A7DAD158-0F9E-4D00-9B49-A7B8BA331BF0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{DE9CE2F9-7A55-4500-909F-5BB366F374BF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{CEEEF407-DCDC-42EA-B6A4-264D4D4625E2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{0B98B4C7-39C1-4CF0-A4E5-6B372EBE071F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{911A2BBC-E15E-4222-8E23-466106BFB6A3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{2E0D7F15-6DBE-442E-881A-49EC18F614D9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{3FDD1303-5E7C-4402-8ACC-2ABDEED6E896}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{44869CA9-EB15-4A02-A008-D9DEE9567A3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{A329DBE3-8C51-4ECE-BCC3-BEA6B2E0EF97}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{85A7D7D1-4FFD-47C3-86C0-0F0EF2625C3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{27DA754C-5D39-4064-887E-88AA167F3260}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{34E149FD-E60A-4271-91E8-12D99BDB0976}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{CB781C8C-90EB-4DDE-8412-8536BC822384}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{023390C2-B321-43E9-8646-789858902107}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{2D85B4F9-2C3E-46EC-AF8A-FC3E1C862AD4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{BB1DA088-376C-4A7A-A5DA-B398F3E43CEB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{D8A6F997-5AA9-45AD-A3B5-57162AF354B4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{8D4FAF89-BCEC-4D7D-806F-D8638B75F26E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{4B269D81-79E5-470F-9567-1692900473BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{0E8FECED-2F14-4411-BD47-66D744198A07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{F1F6330E-A436-401C-9901-9366DFDBBBAA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{766BB2D7-2195-49FB-9A12-47217072423C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{613B658A-93ED-42DA-A805-4856BE8F09D7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{E8CC2A7E-B4A9-45C3-AC5E-4EA0B3D36DCF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{BF628C87-FFC6-41B3-914D-2F23FB3358BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{B3A2B215-AABD-42E3-A508-1D4D0FC77CCD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{48AF6C0E-92F6-44C3-ABCF-0299708BFCC0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{3D9F00A0-ED7B-46E9-B276-4E29971252A9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{15E652CB-3192-4815-862A-C638037BC8CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{EBD18A9C-033C-4887-B2BD-CB460DB7B464}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{E2394666-7621-406A-86CD-15879139D22E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{BC4C1B01-03EA-4D93-B48A-A8ADACC4A5EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{13BF5504-C27F-46EA-9C52-415E342E2741}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{A900B289-6FD2-4833-A338-EB252FD7F16B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{0378E5CD-F0D4-4504-8A2D-6A825C04483A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{FF161DC3-5648-412C-80BF-9524551A9DBF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D94DDCEF-FF3E-4303-8F34-2ED2F926B712}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{3EC90262-3C8D-4E5F-8B48-33B579C6A2E1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{00A9B852-1B3B-4827-8A67-3FC043FEF4BA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{B64C51D2-17FF-4FAF-B9E1-E1023415406B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{8F3D470C-7132-4CEC-8308-0BB6745234A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{5123CE83-E233-49B6-989F-F4FDC19A090A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{672D504D-ADD9-4543-8A04-999325C53EDC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{B7335824-5F8D-4E3F-A5D2-FAEB3652B6F6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{E93E102F-08D0-424F-BDE4-2501D8B06630}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{05246B97-56B9-4EF3-A45F-CAB9234DD283}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{987E7F8C-FF0B-4331-872A-2F867D6B65A3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{8B08229B-38E4-4C00-BB4B-7C9A2809763C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{D1D54CB9-4FA2-44F4-B586-C5CCED80B5F4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{0E8EE5DA-A7E6-4DFC-A211-0E3826EBA949}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0010D7F5-4065-4F68-9F81-5F9B83B56B52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{A471A1E9-EADA-449F-A126-EB56C9DE418C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{7EDFF1D1-6283-4E08-A3A2-47134A78B427}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{2A5982EE-EC73-4115-B344-A9448D92261C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{B5A6CF6A-72BB-4C39-9613-BC921768FFF5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{E8BF7E1A-E228-4B7D-AADF-EA022F64A255}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{FFCAC4AB-263F-4D27-8E1F-48685F20BAEC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{17FFCF9D-AD3B-4889-B049-048D167EB1AB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{11CAC8B9-494A-4C98-B177-72A7CB7642D8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D30CFC0E-367A-430A-9EFD-2051E8ECB800}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{FEA81D5A-8D2C-46F9-AACD-102BE4F39A81}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{38C44A11-D9F0-4CEA-8C59-B224FC27920F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{B60744A3-3626-4327-BD82-285D4A745426}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{33EAE836-6546-4CB6-ABF1-4CB6A094D0CD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{883B687D-BA7F-4C43-B587-06715F39CEEF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{120CBB2C-EDC5-436F-BB0A-7DA7629C5929}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{9A946423-9CEF-4479-9EE9-EBF0CC2B7EC8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{7EA26CF7-AFDF-4195-8648-97890CA74DB0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{480AB8B6-ECC0-4FE2-AFE5-78D5F6A5BED2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{5E5967A5-FA55-48EB-B946-4533B93B84A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{47C6CA3A-080B-44FD-A1D8-8C1062044C56}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{EC3F2033-CE4D-4AE1-9882-E5FC66E872A6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{333DDC02-E7B3-436B-BB5D-113F000AA6E3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{63FBCF2C-3E7E-404C-8B9E-ADE0000F5834}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{052F30EC-4923-43A0-BD81-0997CCD110E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{A54A5799-50F6-4188-94DE-6F900B290C6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{1E2B04C4-8124-4182-A58A-5EEA6F06826A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{90261EB1-2221-4D5E-A676-3A53F36C40EF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{D87B24B6-98DC-462C-931E-8AB13E84B7D2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{F922DB43-EEB2-4DA4-86E9-C7722689084D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{FE0557F0-BB04-481C-A46B-8B469CB4DE95}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{2C860004-8BEC-443B-951C-D025192EB5BF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{85FD87E8-5C74-4670-AF47-BDCBE616CA07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{07D9D872-01A5-4F20-9ECF-555F0A2E0084}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{D755B785-6173-4B55-A993-793F5BF27928}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{2A339B18-F114-44A9-BB4C-E95A271600F5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{040B4775-3792-4287-995E-40E1ACED7F3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{081AD8EB-777B-4BC3-89B7-C5EA36CEB736}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{AB01407D-587C-4E9B-ACD8-DA05707E6811}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{FE0775D8-123A-4F81-9AED-8E7520EDC213}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{B2C3263E-F590-4338-9E8C-26ECE9313E95}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{CD46A599-9D05-468A-BE92-CA0B99EC4A47}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{69DFCE55-558C-4EED-A517-74BD1FD086AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{902BC3B7-1199-4C96-9512-6A7A5B5436C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{5809923C-16F1-4E5F-94D0-78854FA5B892}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{2DEF269D-4A61-4067-98BA-4402D5E60146}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{2B25BA5B-FD5A-40DC-A7A8-E9646E618123}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{1A8D33B4-0B26-434D-BA22-22251825D207}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{287217C6-AA67-4B88-9D06-31F5CB5AD859}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{8225FCB1-1685-4867-A9B4-2BCA0EE9C898}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{26F855F5-C42E-4713-8685-69B1EB146ED3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{6C7103FE-84FA-4C63-A686-9D48E50364CE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{DC6C833E-7509-4640-98FD-6F66AE91A1D7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{56E744E0-60C4-43BF-8DE8-0C057255DEE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{AE4152F0-A7DA-4193-B1F1-25B5C47893FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{F7FAF980-6370-488D-A8D8-7B17FA8DBCF8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{7ADFE28C-5C1F-46F2-9A28-D90CEB38A316}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{A3DB897E-4D94-4A07-8177-92CE1F3AF903}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{222E7604-7380-45ED-9322-64238EF72023}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{7AD0E036-0226-4FD9-98EB-2913AD76CA83}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{3BE26C79-6809-4B3C-91EB-7048927D3339}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{454BEA0C-1BAC-469C-8B59-09D428EC8742}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{973C1E16-B2D6-4D1E-8305-E69341F2688E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{1422A4A9-5B64-4662-82E5-EA0396565B5A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{0D8B6231-D8CB-4136-BF35-0552FA8C0A68}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{B68BFDB9-54AB-4EC6-91BA-FBEF718947C8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{C41BDAAA-4B3C-409F-8BAB-28BB8617950E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{AA21AD32-08AE-44E1-AD92-3F84918AD561}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F7C51446-29DA-4871-BDB1-9E87366B5E9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{3AFDDD61-9B21-442B-A2E5-A9569B9756EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{28F3A9E8-5CB4-43E8-A420-F58A5E8E0215}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{6B2DB471-2705-4BEB-8726-0DE47F433BD0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{DD9EB22E-A092-44B1-8655-C06A17D07A07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{E3160591-0CDB-43CA-B789-8B18FD06FF2A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{AE2EDABE-1FC9-4337-B4AB-FE5F30AF07BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{5E3404AC-ADDC-4B94-8753-149D126B308A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{2629FCEA-6CEA-4B43-B105-4FCAA339FCAF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{29940186-D4F5-44B4-AF81-9D8B2B759F7D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{35B2994F-926A-414D-AB64-C7A9013A6D6E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{8EE992AD-2D64-416B-A11C-B21D601090E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{C4F877C6-CF47-4CF3-BB66-849D32736764}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{E7E5C226-AF28-4A19-A1A9-D3CC86741C6A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{65785401-F682-4656-97AF-6D1E77379270}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{D8BEA1C9-A641-463D-AB06-CC99858E9B6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{F29072B1-DB28-4F11-A7CB-270A2F550E72}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{E5C4DAFF-1E42-4221-A456-17EC2E08DAF2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{94910D5D-4577-4CAF-AB2C-2EB080370AE3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{A12DA46A-421D-4961-A892-34798003BF52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{AFFC572B-8292-49AB-A966-A3A06344639C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{BC6E663D-A81A-477C-96DD-1C882B293857}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{4D74C129-09FD-49AA-B48B-B819358F9F5E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{36112616-2F62-4359-80B5-34952595A745}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{3F8F845A-577D-46E4-BCD8-54BB17E249CB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D18699DD-3663-48C4-8287-15D0A6FE2D21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{D166B5B9-A4BF-4068-947C-DBCC59783F4A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{62953C40-27B7-438B-BA1F-CDAFADD7BE81}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{48CD7CA4-0304-4691-B686-14BF64D2BF5B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{75095B6C-667E-49E4-91B2-73592D1ACE62}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{3025CB00-E332-46E2-9248-5B0632AA2458}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{24FD90F4-BF41-4927-912B-71E98DC19DC4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{D0A6EC14-C086-443A-B7F5-50A894FC2EC8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{9B0C4577-A348-43D0-8409-4DFEB1DFAE3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{6703587B-DDAD-46DF-8DD6-D1FED933D052}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{8515CE51-BDC8-4996-A4BB-768E5E6C5659}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{B9C070FC-B903-402E-8DB4-2FD986E4718A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{BBBE0D6E-946B-4A21-81B4-A6443D729A8D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{5B715575-CA69-4A17-9F59-A7A196599600}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{85E12E7F-37FF-4CC2-9ADF-3865E303F363}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{B5C3E6EA-918E-4F2A-A7E0-DB6A522BA951}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{E866851B-4352-4F59-81C4-6438151BB509}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{A3AFF576-D01E-44C7-BB3F-6C9D31F562D0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{4CFC1407-9AF8-4FE7-86A1-49F33F2BB07F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{EDC9DC78-295F-4CBB-B2E2-1ACFFDD729D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{1787E7A8-2279-4268-AB2D-F8098D46C544}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{26A39019-CBB5-478A-A6BE-122A36FC018B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{CD4D109A-C561-45EC-B94C-349BC9DAE8DB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{7A976567-874D-4412-8DAA-8D6C0284CA83}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{2B53B25B-4762-486C-9430-5B7A7450444E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{1DDBF75D-43B4-4A1A-AA30-9A181D90B05C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{4A8C81AA-FD97-4C07-85EF-3ACA05CE5691}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{D295F48C-16A2-4647-9245-5B817F4ACE15}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F9493F86-ACB9-453E-89D4-470168F5573C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{193DBAAC-A44C-48FB-A243-05660F8E5E30}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{DFC4811F-8044-4ADD-8DA6-5F2A47F1D871}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A12D27BE-1348-4DCC-8B62-837FA7E6CE1D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{17BB815E-338C-4518-8A5E-720D7E577817}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{E575AB30-9F18-4BCF-870B-DCDA16962D7B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{8A14BFB7-AEA0-48E2-BD72-7604675FC02C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{692D4DCE-F9A8-43DD-A66D-B5CEC589309F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{88E9FC39-00D1-404A-A0F3-AA8BA90C438D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{2571D842-A014-406E-A20B-256F482631B9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{4903107A-61A1-4916-82F6-962FCAD7AE2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{F8B79A87-1813-4A77-BB19-A05FAC3007BD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{F4723629-809F-42EB-8676-C8FCA8082C38}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{03687CAA-26F8-454C-846E-EB87CBDEF554}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{CDD4FD86-5B1B-4805-BFE1-4C34D0CF46EC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{7D96C65A-19E6-4B65-BBE9-FFF7E2BFC9FF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{B534C0BE-9719-468B-94F4-EBAC0849B3C7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{5C87CE16-1B9A-46C9-9082-C2C2B44BE54D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{2CAD68CE-0024-4E6D-9A84-95BA3C65CAFE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{3F1F39BD-6F42-4137-B0EC-42A3E62FC3E0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{5D607F7A-6B19-472C-AF51-3BC959512E8A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{1CD3ABE9-B6D6-4742-B22F-669CE1192DE7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{74D85154-2A03-4121-B752-08B480A174FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{4DF37154-D997-4A05-9B64-DD1BF9A1C8A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{8BD0774E-477A-474A-9B6B-2C74B7A6AF35}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{5310066A-AEE3-4CFF-97FE-A27F829C4ED4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{410031EB-900A-426E-BFE4-A51DD7E218BE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{5C90C829-D035-4FB2-9C35-8F560A22737E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{23FB6F20-8E80-4274-B2CE-5310A4543D7E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{CB3E27CB-7567-440E-A224-2F5F55F180FA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{D577FBC1-ACD1-4D2C-BBB7-BC9753C0725E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" + +;075. ViveTool Manipulation + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\105243275] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1084486795] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1105025673] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1111440523] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1140553355] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1167405706] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1254311563] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1286552203] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\129315978] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1323362443] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\133772938] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1431914635] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1497709195] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\151073418] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\152522890] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1570325131] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1593135754] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1604982409] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1707173514] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1711504522] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1740062347] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1826306186] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1879800970] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2061326475] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2080885386] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2098554507] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\210965642] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2122649227] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2141004426] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2159103626] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\221325962] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\230377099] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2475784331] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2528327818] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2536843915] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2553628810] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\261698187] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2628859531] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2674077835] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\269563531] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2736994955] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2778935433] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2845256331] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2866624651] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2888518282] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2891254923] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2940954250] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2954081930] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\296246922] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3054451851] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3073583755] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3135060107] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3298293899] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\345723018] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3535874698] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3543217290] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3655416971] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3665657483] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3784116360] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3793829003] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3928046731] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3928239754] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\395859593] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4045366411] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4095660171] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4122855562] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4134351499] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4145095306] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\463973000] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\469712011] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\479401098] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\523318411] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\525560971] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\553726602] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\581515914] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\589803146] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\641901194] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\644487817] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\653733002] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\65394315] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\783108235] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\814945418] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\892417163] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\957700746] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +;076. Service Removal + diff --git a/Melody 12.01 (Script for Windows 11)/ma.ps1 b/Melody 12.01 (Script for Windows 11)/ma.ps1 new file mode 100644 index 0000000..6112035 --- /dev/null +++ b/Melody 12.01 (Script for Windows 11)/ma.ps1 @@ -0,0 +1,38 @@ +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "WOL & Shutdown Link Speed" -DisplayValue "Not Speed Down" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Power Saving Mode" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "NS Offload" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Jumbo Frame" -DisplayValue "9014 bytes" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Green Ethernet" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Gigabit Lite" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Energy-Efficient Ethernet" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Flow Control" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Interrupt Moderation" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Interrupt Moderation Rate" -DisplayValue "Off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Enable PME" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Maximum Number of RSS Queues" -DisplayValue "4 Queues" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Transmit Buffers" -DisplayValue "128" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Receive Buffers" -DisplayValue "512" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Large Send Offload V2 (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Large Send Offload V2 (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "TCP Checksum Offload (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "TCP Checksum Offload (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "UDP Checksum Offload (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "UDP Checksum Offload (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "IPv4 Checksum Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Speed & Duplex" -DisplayValue "1.0 Gbps Full Duplex" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Gigabit Master Slave Mode" -DisplayValue "Force Slave Mode" For two NICs +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Maximum Number of RSS Processors" -DisplayValue "4 Processors" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "RSS load balancing profile" -DisplayValue "NUMAScaling" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Protocol ARP Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Protocol NS Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Ultra Low Power Mode" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Jumbo Packet" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Magic Packet" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Pattern Match" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Link Settings" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wait for Link" -DisplayValue "off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Energy Efficient Ethernet" -DisplayValue "Off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Reduce Speed On Power Down" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "System Idle Power Saver" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Log Link State Event" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Packet Priority & VLAN" -DisplayValue "Packet Priority & VLAN Disabled" \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows 11)/nircmd.exe b/Melody 12.01 (Script for Windows 11)/nircmd.exe new file mode 100644 index 0000000..e606a83 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/nircmd.exe differ diff --git a/Melody 12.01 (Script for Windows 11)/nircmdc.exe b/Melody 12.01 (Script for Windows 11)/nircmdc.exe new file mode 100644 index 0000000..6e7fe18 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/nircmdc.exe differ diff --git a/Melody 12.01 (Script for Windows 11)/secdrv.sys b/Melody 12.01 (Script for Windows 11)/secdrv.sys new file mode 100644 index 0000000..fd2fe65 Binary files /dev/null and b/Melody 12.01 (Script for Windows 11)/secdrv.sys differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/Blank.ico b/Melody 12.01 (Script for Windows Insider Preview)/Blank.ico new file mode 100644 index 0000000..f6748fa Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/Blank.ico differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/PowerRun.exe b/Melody 12.01 (Script for Windows Insider Preview)/PowerRun.exe new file mode 100644 index 0000000..524816b Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/PowerRun.exe differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/SDL.dll b/Melody 12.01 (Script for Windows Insider Preview)/SDL.dll new file mode 100644 index 0000000..a7981ff Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/SDL.dll differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/Toggle Camera in menu.bat b/Melody 12.01 (Script for Windows Insider Preview)/Toggle Camera in menu.bat new file mode 100644 index 0000000..d134b74 --- /dev/null +++ b/Melody 12.01 (Script for Windows Insider Preview)/Toggle Camera in menu.bat @@ -0,0 +1,172 @@ + + + +:: **************************************************************************************** +@echo off & title Turn on or off the camera. & mode con cols=80 lines=13 & color 17 +:: **************************************************************************************** +Set "【Item】=Toggle Camera On or Off" +Set "【Name】=Camera_on_off" +Set "【Path】=wscript.exe" +If not exist "%ProgramData%\Fidelity\" (mkdir "%ProgramData%\Fidelity\") +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%\Command" /VE /D "schtasks /run /tn ""Apps\%【Name】%""" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Icon" /T REG_SZ /D "%WinDir%\System32\DDORes.dll,86" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Position" /T REG_SZ /D "Bottom" /F) +Cls +If errorlevel 1 (echo. +echo ==================================================================== +echo. +echo The script has failed to perform the operations. +echo Press any key to exit. +echo. +echo ==================================================================== +pause > nul & EXIT) +echo. +echo The script is creating an elevated task with highest privileges. +echo Please wait for a while. +echo. +:: **************************************************************************************** +Set "Folder=%ProgramData%\Fidelity\Turn_on_or_off_the_camera" +If not exist "%Folder%" (MkDir "%Folder%") + +Set "Script=%Folder%\+Turn_on_or_off_the_camera.cmd" +If exist "%Script%" (del "%Script%") +( +echo :: **************************************************************************************** +echo @echo off ^& title Turn on or off the camera. ^& mode con cols=68 lines=6 ^& color 17 +echo :: **************************************************************************************** + +echo cd /d "%%~dp0" +echo For /f "tokens=3" %%%%# in ^('REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V "Value"'^) Do ^(Set ✱=%%%%#^) +echo If "%%✱%%"=="Allow" ^(goto Turn_off_the_camera^) ^& Exit +echo :: **************************************************************************************** +echo :Turn_on_the_camera +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V Value /T REG_SZ /D "Allow" /F^) +echo ^(Start "" "Enabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +echo :Turn_off_the_camera +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\webcam" /V Value /T REG_SZ /D "Deny" /F^) +echo ^(Start "" "Disabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +)> "%Script%" + +:: **************************************************************************************** +Set "【VBS】=%Folder%\+Run_the_CMD_script.vbs" +If exist "%【VBS】%" (del "%【VBS】%") +( +echo Path = split^(wscript.scriptFullName, wscript.scriptname^)^(0^) +echo Item = Path ^& "+Turn_on_or_off_the_camera.cmd" +echo CreateObject^("wscript.shell"^).run^("""" ^& Item ^& ""^),0 +echo WScript.Quit +)> "%【VBS】%" +:: **************************************************************************************** +Set "Enabled=%Folder%\Enabled.ps1" +If exist "%Enabled%" (del "%Enabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Camera enabled. Press the Windows + M keys for it to take effect if the camera cannot be used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Enabled%" +:: **************************************************************************************** +Set "Enabled✱=%Folder%\Enabled.vbs" +If exist "%Enabled✱%" (del "%Enabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Enabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Enabled✱%" +:: **************************************************************************************** +Set "Disabled=%Folder%\Disabled.ps1" +If exist "%Disabled%" (del "%Disabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Camera Disabled. Press the Windows + M keys for it to take effect if the camera is being used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Disabled%" +:: **************************************************************************************** +Set "Disabled✱=%Folder%\Disabled.vbs" +If exist "%Disabled✱%" (del "%Disabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Disabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Disabled✱%" +:: **************************************************************************************** +For /f "tokens=*" %%I in ('WhoAmI /user') Do (for %%A in (%%~I) Do (set "【SID】=%%A")) +IF EXIST "%temp%\%【Name】%.xml" (DEL "%temp%\%【Name】%.xml") +IF EXIST "%temp%\Task.vbs" (DEL "%temp%\Task.vbs") + +echo Set X=CreateObject("Scripting.FileSystemObject") >> "%temp%\Task.vbs" +echo Set Z=X.CreateTextFile("%temp%\%【Name】%.xml",True,True)>> "%temp%\Task.vbs" +Set "W=echo Z.writeline " +( +%W%"" +%W%"" +%W%"" +%W%"To run the application/CMD script as an administrator with no UAC prompt." +%W%"" +%W%"" +%W%"" +%W%"" +%W%"%【SID】%" +%W%"InteractiveToken" +%W%"HighestAvailable" +%W%"" +%W%"" +%W%"" +%W%"IgnoreNew" +%W%"false" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"" +%W%"true" +%W%"false" +%W%"" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"false" +%W%"true" +%W%"false" +%W%"PT72H" +%W%"7" +%W%"" +%W%"" +%W%"" +%W%"""%【Path】%""" +%W%"""%【VBS】%""" +%W%"" +%W%"" +%W%"" +)>> "%temp%\Task.vbs" +echo Z.Close >> "%temp%\Task.vbs" +"%temp%\Task.vbs" +Del "%temp%\Task.vbs" +schtasks /create /xml "%temp%\%【Name】%.xml" /tn "Apps\%【Name】%" + +If %errorlevel%==1 (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The script has failed to create the task "%【Name】%". +echo The task might already exist in "Task Scheduler Library"--^>"Apps". +echo Press any key to close this message. +echo ============================================================================ +pause > nul) else (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The item "%【Item】%" has been added into the desktop context +echo menu ^(right-click menu^). +echo The scheduled task is in "Task Scheduler Library"--^>"Apps". +echo Please press any key to close this message. +echo ============================================================================ +pause > nul ) \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows Insider Preview)/Toggle Microphone in menu.bat b/Melody 12.01 (Script for Windows Insider Preview)/Toggle Microphone in menu.bat new file mode 100644 index 0000000..8b5d9fc --- /dev/null +++ b/Melody 12.01 (Script for Windows Insider Preview)/Toggle Microphone in menu.bat @@ -0,0 +1,169 @@ +:: **************************************************************************************** +@echo off & title Turn on or off the microphone. & mode con cols=80 lines=13 & color 17 +:: **************************************************************************************** +Set "【Item】=Toggle Microphone On or Off" +Set "【Name】=Microphone_on_off" +Set "【Path】=wscript.exe" +If not exist "%ProgramData%\Fidelity\" (mkdir "%ProgramData%\Fidelity\") +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%\Command" /VE /D "schtasks /run /tn ""Apps\%【Name】%""" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Icon" /T REG_SZ /D "%WinDir%\System32\DDORes.dll,86" /F) +(REG Add "HKCR\DesktopBackground\Shell\%【Item】%" /V "Position" /T REG_SZ /D "Bottom" /F) +Cls +If errorlevel 1 (echo. +echo ==================================================================== +echo. +echo The script has failed to perform the operations. +echo Press any key to exit. +echo. +echo ==================================================================== +pause > nul & EXIT) +echo. +echo The script is creating an elevated task with highest privileges. +echo Please wait for a while. +echo. +:: **************************************************************************************** +Set "Folder=%ProgramData%\Fidelity\Turn_on_or_off_the_microphone" +If not exist "%Folder%" (MkDir "%Folder%") + +Set "Script=%Folder%\+Turn_on_or_off_the_microphone.cmd" +If exist "%Script%" (del "%Script%") +( +echo :: **************************************************************************************** +echo @echo off ^& title Turn on or off the microphone. ^& mode con cols=68 lines=6 ^& color 17 +echo :: **************************************************************************************** + +echo cd /d "%%~dp0" +echo For /f "tokens=3" %%%%# in ^('REG QUERY "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V "Value"'^) Do ^(Set ✱=%%%%#^) +echo If "%%✱%%"=="Allow" ^(goto Turn_off_the_microphone^) ^& Exit +echo :: **************************************************************************************** +echo :Turn_on_the_microphone +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V Value /T REG_SZ /D "Allow" /F^) +echo ^(Start "" "Enabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +echo :Turn_off_the_microphone +echo ^(REG ADD "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\CapabilityAccessManager\ConsentStore\microphone" /V Value /T REG_SZ /D "Deny" /F^) +echo ^(Start "" "Disabled.vbs" ^& EXIT^) +echo :: **************************************************************************************** +)> "%Script%" + +:: **************************************************************************************** +Set "【VBS】=%Folder%\+Run_the_CMD_script.vbs" +If exist "%【VBS】%" (del "%【VBS】%") +( +echo Path = split^(wscript.scriptFullName, wscript.scriptname^)^(0^) +echo Item = Path ^& "+Turn_on_or_off_the_microphone.cmd" +echo CreateObject^("wscript.shell"^).run^("""" ^& Item ^& ""^),0 +echo WScript.Quit +)> "%【VBS】%" +:: **************************************************************************************** +Set "Enabled=%Folder%\Enabled.ps1" +If exist "%Enabled%" (del "%Enabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Microphone enabled. Press the Windows + M keys for it to take effect if the microphone cannot be used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Enabled%" +:: **************************************************************************************** +Set "Enabled✱=%Folder%\Enabled.vbs" +If exist "%Enabled✱%" (del "%Enabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Enabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Enabled✱%" +:: **************************************************************************************** +Set "Disabled=%Folder%\Disabled.ps1" +If exist "%Disabled%" (del "%Disabled%") +( +echo [reflection.assembly]::loadwithpartialname^("System.Windows.Forms"^) +echo [reflection.assembly]::loadwithpartialname^("System.Drawing"^) +echo $X = new-object system.windows.forms.notifyicon +echo $X.icon = [System.Drawing.SystemIcons]::Information +echo $X.visible = $true +echo $X.showballoontip^(10,"", "Microphone Disabled. Press the Windows + M keys for it to take effect if the microphone is being used.",[system.windows.forms.tooltipicon]::None^) +echo $X.dispose^(^) +echo ^(New-Object Media.SoundPlayer "C:\Windows\Media\Ring06.wav"^).PlaySync^(^); +)> "%Disabled%" +:: **************************************************************************************** +Set "Disabled✱=%Folder%\Disabled.vbs" +If exist "%Disabled✱%" (del "%Disabled✱%") +( +echo Set X = CreateObject^("WScript.Shell"^) +echo PS = "%Disabled%" +echo X.run "powershell -executionpolicy bypass -file " ^& chr^(34^) ^& PS ^& chr^(34^), 0, true +)> "%Disabled✱%" +:: **************************************************************************************** +For /f "tokens=*" %%I in ('WhoAmI /user') Do (for %%A in (%%~I) Do (set "【SID】=%%A")) +IF EXIST "%temp%\%【Name】%.xml" (DEL "%temp%\%【Name】%.xml") +IF EXIST "%temp%\Task.vbs" (DEL "%temp%\Task.vbs") + +echo Set X=CreateObject("Scripting.FileSystemObject") >> "%temp%\Task.vbs" +echo Set Z=X.CreateTextFile("%temp%\%【Name】%.xml",True,True)>> "%temp%\Task.vbs" +Set "W=echo Z.writeline " +( +%W%"" +%W%"" +%W%"" +%W%"To run the application/CMD script as an administrator with no UAC prompt." +%W%"" +%W%"" +%W%"" +%W%"" +%W%"%【SID】%" +%W%"InteractiveToken" +%W%"HighestAvailable" +%W%"" +%W%"" +%W%"" +%W%"IgnoreNew" +%W%"false" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"" +%W%"true" +%W%"false" +%W%"" +%W%"true" +%W%"true" +%W%"false" +%W%"false" +%W%"false" +%W%"true" +%W%"false" +%W%"PT72H" +%W%"7" +%W%"" +%W%"" +%W%"" +%W%"""%【Path】%""" +%W%"""%【VBS】%""" +%W%"" +%W%"" +%W%"" +)>> "%temp%\Task.vbs" +echo Z.Close >> "%temp%\Task.vbs" +"%temp%\Task.vbs" +Del "%temp%\Task.vbs" +schtasks /create /xml "%temp%\%【Name】%.xml" /tn "Apps\%【Name】%" + +If %errorlevel%==1 (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The script has failed to create the task "%【Name】%". +echo The task might already exist in "Task Scheduler Library"--^>"Apps". +echo Press any key to close this message. +echo ============================================================================ +pause > nul & Exit) else (DEL "%temp%\%【Name】%.xml" & echo. +echo ============================================================================ +echo The item "%【Item】%" has been added into the desktop context +echo menu ^(right-click menu^). +echo The scheduled task is in "Task Scheduler Library"--^>"Apps". +echo Please press any key to close this message. +echo ============================================================================ +pause > nul & Exit) \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/MicRooCerAut2011_2011_03_22.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/MicRooCerAut2011_2011_03_22.crt new file mode 100644 index 0000000..1ae4740 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/MicRooCerAut2011_2011_03_22.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/MicRooCerAut_2010-06-23.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/MicRooCerAut_2010-06-23.crl new file mode 100644 index 0000000..8166d95 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/MicRooCerAut_2010-06-23.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl new file mode 100644 index 0000000..174c487 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt new file mode 100644 index 0000000..3eb2c12 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Product Root Certificate Authority 2018.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Root Certificate Authority 2017.crl new file mode 100644 index 0000000..9ca82c0 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Root Certificate Authority 2017.crt new file mode 100644 index 0000000..86658ae Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl new file mode 100644 index 0000000..77a7065 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt new file mode 100644 index 0000000..d29764b Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft ECC TS Root Certificate Authority 2018.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl new file mode 100644 index 0000000..257bc74 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt new file mode 100644 index 0000000..90a7a79 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV ECC Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl new file mode 100644 index 0000000..0deac11 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt new file mode 100644 index 0000000..8835c44 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft EV RSA Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft RSA Root Certificate Authority 2017.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft RSA Root Certificate Authority 2017.crl new file mode 100644 index 0000000..0bcbf32 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft RSA Root Certificate Authority 2017.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft RSA Root Certificate Authority 2017.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft RSA Root Certificate Authority 2017.crt new file mode 100644 index 0000000..7031f88 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft RSA Root Certificate Authority 2017.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl new file mode 100644 index 0000000..8ab0e74 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crl differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt new file mode 100644 index 0000000..8a7a17f Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/certificates/Microsoft Time Stamp Root Certificate Authority 2014.crt differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/command2.bat b/Melody 12.01 (Script for Windows Insider Preview)/command2.bat new file mode 100644 index 0000000..059985b --- /dev/null +++ b/Melody 12.01 (Script for Windows Insider Preview)/command2.bat @@ -0,0 +1,890 @@ +:: Start with setting the location + +pushd "%CD%" +CD /D "%~dp0" + +:: Starting +reg.exe add "HKCU\Software\Classes\CLSID\{86ca1aa0-34aa-4e8b-a509-50c905bae2a2}\InprocServer32" /f /ve +PowerRun "Toggle Camera in menu.bat" +PowerRun "Toggle Microphone in menu.bat" +PowerRun.exe Regedit.exe /S fidelityreg_reg11.reg +Regedit.exe /S fidelityreg_reg11.reg + + + +:: Enable DirectPlay + +"powershell.exe" Enable-WindowsOptionalFeature -Online -FeatureName LegacyComponents -all -NoRestart +"powershell.exe" Enable-WindowsOptionalFeature -Online -FeatureName DirectPlay -all -NoRestart + +:: Installing Microsoft's Certs (because they removed sometime)... + +echo Now installing Root certs +for /f "delims=" %%f in ('dir /b "%~dp0\certificates\*"') do ( + echo Installing %%f... + certutil -f -addstore Root "%~dp0\certificates\%%f" +) + +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fidelity" /v DisplayName /t reg_sz /d "Melody 12.0 (EAS, partially applied)" /f + +:: Removal of Components + + +::Handwriting + +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~af-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~bs-LATN-BA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ca-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~cy-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~eu-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ga-IE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~gd-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~gl-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~hi-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~id-ID~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~lb-LU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~mi-NZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ms-BN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ms-MY~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nn-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~nso-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~rm-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~rw-RW~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sq-AL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sr-CYRL-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sr-LATN-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~sw-KE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~tn-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~wo-SN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~xh-ZA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zh-TW~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Handwriting~~~zu-ZA~0.0.1.0 /NoRestart + + +::OCR + +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ar-SA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~bg-BG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~bs-LATN-BA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~hu-HU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sr-CYRL-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sr-LATN-RS~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.OCR~~~zh-TW~0.0.1.0 /NoRestart + +::Speech Recongnition + +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-AU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.Speech~~~zh-TW~0.0.1.0 /NoRestart + + +::TTS Packs + +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ar-EG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ar-SA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~bg-BG~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ca-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~cs-CZ~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~da-DK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-AT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~de-DE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~el-GR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-AU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-GB~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-IE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~en-US~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~es-ES~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~es-MX~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fi-FI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-CA~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-CH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~fr-FR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~he-IL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hi-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hr-HR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~hu-HU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~id-ID~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~it-IT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ja-JP~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ko-KR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ms-MY~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nb-NO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nl-BE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~nl-NL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pl-PL~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pt-BR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~pt-PT~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ro-RO~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ru-RU~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sk-SK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sl-SI~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~sv-SE~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~ta-IN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~th-TH~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~tr-TR~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~vi-VN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-CN~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-HK~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Language.TextToSpeech~~~zh-TW~0.0.1.0 /NoRestart + +::Network Drivers +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Intel.E1i68x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Intel.E2f68~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Vmware.Vmxnet3~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Ethernet.Client.Realtek.Rtcx21x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmpciedhd63~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmwl63al~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Broadcom.Bcmwl63a~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwbw02~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwew00~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwew01~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwlv64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwns64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwsw00~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw02~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw04~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw06~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw08~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Intel.Netwtw10~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Marvel.Mrvlpcie8897~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Athw8x~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Athwnx~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Qualcomm.Qcamain10x64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Ralink.Netr28x~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl8187se~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl8192se~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl819xp~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtl85n64~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane01~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane13~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.Wifi.Client.Realtek.Rtwlane~~~~0.0.1.0 /NoRestart + +::Windows Tools +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.IoTDeviceUpdateCenter~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.PowerShell.ISE~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Microsoft.Windows.WordPad~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OneCoreUAP.OneSync~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Client~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OneCoreUAP.OneSync~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Print.Fax.Scan~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:MathRecognizer~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Media.WindowsMediaPlayer~~~~0.0.12.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:OpenSSH.Server~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Accessibility.Braille~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Analog.Holographic.Desktop~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.StepsRecorder~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.Support.QuickAssist~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:App.WirelessDisplay.Connect~~~~0.0.1.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Browser.InternetExplorer~~~~0.0.11.0 /NoRestart +dism /Online /Remove-Capability /CapabilityName:Hello.Face.20134~~~~0.0.1.0 /NoRestart +:: Applying Network Settings + +netsh int tcp set heuristics disabled +netsh int tcp set supp internet congestionprovider=ctcp +netsh int tcp set global rss=enabled +netsh int tcp set global chimney=disabled +netsh int tcp set global ecncapability=enabled +netsh int tcp set global timestamps=disabled +netsh int tcp set global initialRto=3000 +netsh int tcp set global timestamps=disabled +netsh int tcp set global rsc=disabled +netsh int tcp set global nonsackttresiliency=disabled +netsh int tcp set global MaxSynRetransmissions=2 +netsh int tcp set global fastopen=enabled +netsh int tcp set global fastopenfallback=enabled +netsh int tcp set global pacingprofile=off +netsh int tcp set global hystart=disabled +netsh int tcp set heuristics disabled +netsh int tcp set global dca=enabled +netsh int tcp set global netdma=enabled +netsh int 6to4 set state state=enabled +netsh int udp set global uro=enabled +netsh winsock set autotuning on +netsh int tcp set supplemental template=custom icw=10 +netsh interface teredo set state enterprise +netsh int tcp set security mpp=disabled +netsh int tcp set security profiles=disabled +netsh interface ipv4 set subinterface "Wi-Fi" mtu=1500 store=persistent +netsh interface ipv6 set subinterface "Ethernet" mtu=1500 store=persistent +netsh interface ipv6 set subinterface "Ethernet" mtu=1500 store=persistent +netsh interface ipv4 set subinterface "Wi-Fi" mtu=1500 store=persistent +netsh int tcp set global autotuning=experimental +netsh advfirewall firewall set rule group="Remote Assistance" new enable=no + +for /f "tokens=3*" %%s in ('Reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NetworkCards" /f "ServiceName" /s^|findstr /i /l "ServiceName"') do ( + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Psched\Parameters\Adapters\%%s" /v "NonBestEffortLimit" /t Reg_DWORD /d "0" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "DeadGWDetectDefault" /t Reg_DWORD /d "1" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "PerformRouterDiscovery" /t Reg_DWORD /d "1" /f >nul + ::Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpInitialRTT" /t Reg_DWORD /d "0" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TCPNoDelay" /t Reg_DWORD /d "1" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpAckFrequency" /t Reg_DWORD /d "1" /f >nul + Reg add "HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\%%s" /v "TcpDelAckTicks" /t Reg_DWORD /d "0" /f >nul + ) + + +for %%i in (svchost explorer edge steam steamclient operagx Fornite-Win64-Shipping EA explorer chrome notepad++ steamwebviewer winword powerpnt excel mysummercar metin2 csgo VALORANT-Win64-Shipping javaw FortniteClient-Win64-Shipping ModernWarfare r5apex) do ( + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Application Name" /t Reg_SZ /d "%%i.exe" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Version" /t Reg_SZ /d "1.0" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Protocol" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local Port" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local IP" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Local IP Prefix Length" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote Port" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote IP" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Remote IP Prefix Length" /t Reg_SZ /d "*" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "DSCP Value" /t Reg_SZ /d "46" /f + Reg add "HKLM\Software\Policies\Microsoft\Windows\QoS\%%i" /v "Throttle Rate" /t Reg_SZ /d "-1" /f +) + +for /f %%r in ('Reg query "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}" /f "PCI\VEN_" /d /s^|Findstr HKEY_') do ( +Reg add %%r /v "AutoDisableGigabit" /t Reg_SZ /d "0" /f +Reg add %%r /v "EnableGreenEthernet" /t Reg_SZ /d "0" /f +Reg add %%r /v "GigaLite" /t Reg_SZ /d "0" /f +Reg add %%r /v "PowerSavingMode" /t Reg_SZ /d "0" /f +) + +reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPerServer /t REG_DWORD /d 8 /f +reg add "HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPer1_0Server /t REG_DWORD /d 8 /f +reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPerServer /t REG_DWORD /d 8 /f +reg add "HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v MaxConnectionsPer1_0Server /t REG_DWORD /d 8 /f + +for /f %%a in ('Reg query HKLM /v "*WakeOnMagicPacket" /s ^| findstr "HKEY"') do ( +for /f %%i in ('Reg query "%%a" /v "*EEE" ^| findstr "HKEY"') do (Reg add "%%i" /v "*EEE" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "*FlowControl" ^| findstr "HKEY"') do (Reg add "%%i" /v "*FlowControl" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableSavePowerNow" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableSavePowerNow" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnablePowerManagement" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnablePowerManagement" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableDynamicPowerGating" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableDynamicPowerGating" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnableConnectedPowerGating" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnableConnectedPowerGating" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "AutoPowerSaveModeEnabled" ^| findstr "HKEY"') do (Reg add "%%i" /v "AutoPowerSaveModeEnabled" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "AdvancedEEE" ^| findstr "HKEY"') do (Reg add "%%i" /v "AdvancedEEE" /t Reg_DWORD /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "ULPMode" ^| findstr "HKEY"') do (Reg add "%%i" /v "ULPMode" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "ReduceSpeedOnPowerDown" ^| findstr "HKEY"') do (Reg add "%%i" /v "ReduceSpeedOnPowerDown" /t Reg_SZ /d "0" /f) +for /f %%i in ('Reg query "%%a" /v "EnablePME" ^| findstr "HKEY"') do (Reg add "%%i" /v "EnablePME" /t Reg_SZ /d "0" /f) +) + +PowerShell -NoProfile -ExecutionPolicy Bypass -Command "& {Start-Process PowerShell -ArgumentList '-NoProfile -ExecutionPolicy Bypass -File ""%~dp0.\ma.ps1""' -Verb RunAs}" + +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001" /v "*RSSProfile" /t REG_SZ /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "ParamDesc" /t REG_SZ /d "RSS load balancing profile" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "default" /t REG_SZ /d "1" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile" /v "type" /t REG_SZ /d "enum" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "1" /t REG_SZ /d "ClosestProcessor" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "2" /t REG_SZ /d "ClosestProcessorStatic" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "3" /t REG_SZ /d "NUMAScaling" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "4" /t REG_SZ /d "NUMAScalingStatic" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Control\Class\{4d36e972-e325-11ce-bfc1-08002be10318}\0001\Ndi\Params\*RSSProfile\Enum" /v "5" /t REG_SZ /d "ConservativeScaling" /f + +powershell -Command "Disable-NetAdapterChecksumOffload -Name * -IpIPv4 -TcpIPv4 -TcpIPv6 -UdpIPv4 -UdpIPv6" + +:: Services Part + +sc config MsKeyboardFilter start= disabled +sc config GraphicsPerfSvc start= disabled +sc config DiagTrack start= disabled +sc config TroubleshootingSvc start= disabled +sc config RemoteRegistry start= disabled +sc config shpamsvc start= disabled +sc config UevAgentService start= disabled +sc config MSiSCSI start= disabled +sc config NetTcpPortSharing start= disabled +sc config diagnosticshub.standardcollector.service start= disabled +sc config diagsvc start= disabled +sc config dmwappushservice start= disabled +sc config edgeupdate start= disabled + +::Search + +sc config WSearch start= disabled + +::Remote Desktop Native + +sc config tsusbflt start= disabled +sc config tsusbhub start= disabled +sc config TsUsbGD start= disabled +sc config TermService start= disabled +sc config SessionEnv start= disabled + +::Networking Services + +sc config PNRPsvc start= disabled +sc config p2psvc start= disabled +sc config p2pimsvc start= disabled +sc config PeerDistSvc start= disabled +sc config PerfHost start= disabled +sc config PNRPAutoReg start= disabled +sc config ALG start= disabled +sc config Fax start= disabled +sc config SNMPTrap start= disabled +sc config autotimesvc start= disabled +sc config LanmanWorkstation start= disabled +sc config LanmanServer start= disabled +sc config webthreatdefsvc start= disabled +sc config webthreatdefusersvc_63b8d start= disabled +sc config InventorySvc start= disabled +sc config MapsBroker start= disabled +sc config pla start= disabled + +::VR Services + +sc config perceptionsimulation start= disabled +sc config SharedRealitySvc start= disabled +sc config spectrum start= disabled +sc config MixedRealityOpenXRSvc start= disabled + +::Retail Demo + +sc config RetailDemo start= disabled + +::Virtual Machine + +sc config HvHost start= disabled +sc config vmickvpexchange start= disabled +sc config vmicguestinterface start= disabled +sc config vmicshutdown start= disabled +sc config vmicheartbeat start= disabled +sc config vmicvmsession start= disabled +sc config vmicrdv start= disabled +sc config vmictimesync start= disabled +sc config vmicvss start= disabled +sc config VMAuthdService start=demand +sc config VMnetDHCP start= demand +sc config VMware NAT Service start= demand +sc config VMUSBArbService start= demand +sc config VMwareHostd start= demand +sc config wcncsvc start= disabled +reg add "HKLM\SYSTEM\CurrentControlSet\Services\MessagingService" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKCU\Control Panel\Sound" /v "Beep" /t REG_SZ /d "no" /f + +::Blotware + + +sc config lfsvc start= disabled +sc config GoogleChromeBetaElevationService start= demand +sc config gupdate start= demand +sc config gupdatem start= demand +sc config GamingServices start= demand +sc config sppsvc start= demand +sc config DoSvc start= demand +sc config CDPSvc start= demand +sc config ClickToRunSvc start= demand +sc config DtsApo4Service start= demand +sc config TrkWks start= demand +sc config VacSvc start= disabled +sc config VSStandardCollectorService150 +sc config ss_conn_service start= demand +sc config ss_conn_service2 start= demand +sc config AudioEndpointBuilder start= demand +sc config RpcLocator start= disabled +sc config Sense start= disabled +sc config TapiSrv start= disabled +sc config KtmRm start= disabled +sc config SEMgrSvc start= disabled +sc config SCardSvr start= disabled +sc config ScDeviceEnum start= disabled +sc config AppVClient start= disabled +sc config SysMain start= disabled +sc config SSDPSRV start= disabled +sc config IKEEXT start= demand +sc config FontCache3.0.0.0 start= disabled +sc config WinRM start= disabled +sc config AxInstSV start= disabled +sc config WpcMonSvc start= disabled +sc config pla start= disabled +sc config COMSysApp start= disabled +sc config AGMService start= disabled +sc config AGSService start= disabled +sc stop TroubleshootingSvc +sc config TroubleshootingSvc start=disabled +sc stop MapsBroker +sc config MapsBroker start=disabled +sc stop SysMain +sc config SysMain start=disabled +sc config DusmSvc start= disabled +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpcMonSvc" /v "Start" /t REG_DWORD /d "4" /f + +:: Driver Service 2 +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\rdbss" /v "Start" /t REG_DWORD /d "1" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\pcmcia" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\lltdio" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\hwpolicy" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\vdrvroot" /v "Start" /t REG_DWORD /d "0" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\tcpipreg" /v "Start" /t REG_DWORD /d "2" / +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\TrustedInstaller" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\srvnet" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\services\rspndr" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\CurrentControlSet\Services\Schedule" /v "Start" /t REG_DWORD /d "2" /f +Reg.exe add "HKLM\SYSTEM\ControlSet001\Services\TrkWks" /v "Start" /t REG_DWORD /d "3" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GoogleChromeElevationService" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BcastDVRUserService" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PhoneSvc" /v "Start" /t REG_DWORD /d "4" /f +reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Fax" /v "Start" /t REG_DWORD /d "4" /f + +::TabletPC + +sc config SensorDataService start= disabled +sc config SensrSvc start= disabled +sc config SensorService start= disabled +sc config SmsRouter start= disabled +sc config PhoneSvc start= disabled +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wscsvc" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DEFRAGSVC" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\upnphost" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SSDPSRV" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MessagingService_1c6e8" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\webthreatdefusersvc_77ac1" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MessagingService" /v "Start" /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\stisvc" /v "Start" /t REG_DWORD /d "2" /f +REG ADD "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\irmon" /v Start /t REG_DWORD /d "4" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\AxInstSV" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinRM" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinHttpAutoProxySvc" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TrkWks" /v "Start" /t REG_DWORD /d "3" /f +Reg.exe add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\luafv" /v "Start" /t REG_DWORD /d "4" /f + +::Task Disabler +::.net + +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical" /disable +schtasks /Change /TN "Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical" /disable + +::ad tms management + +schtasks /Change /TN "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual)" /disable +schtasks /Change /TN "\Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated)" /disable + +::Mentenanta + +schtasks /Change /TN "\Microsoft\Windows\Chkdsk\ProactiveScan" /disable +schtasks /Change /TN "\Microsoft\Windows\Chkdsk\SyspartRepair" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan" /disable +schtasks /Change /TN "\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery" /disable +schtasks /Change /TN "\Microsoft\Windows\Defrag\ScheduledDefrag" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskCleanup\SilentCleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\FileHistory\File History (maintenance mode)" /disable +schtasks /Change /TN "\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE" /disable +schtasks /Change /TN "\Microsoft\Windows\Registry\RegIdleBackup" /disable + +:: telemetry +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\BthSQM" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Consolidator" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\KernelCeipTask" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\Uploader" /disable +schtasks /Change /TN "Microsoft\Windows\Customer Experience Improvement Program\UsbCeip" /disable +schtasks /change /TN "\Microsoft\Windows\Autochk\Proxy" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\AitAgent" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\PcaPatchDbTask" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\ProgramDataUpdater" /disable +schtasks /Change /TN "Microsoft\Windows\Application Experience\StartupAppTask" /disable +schtasks /Change /TN "Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /disable +schtasks /Change /TN "Microsoft\Windows\DiskFootprint\Diagnostics" /disable +schtasks /Change /TN "Microsoft\Windows\Windows Error Reporting\QueueReporting" /disable +schtasks /Change /TN "\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem" /disable +schtasks /Change /TN "\Microsoft\Windows\NetTrace\GatherNetworkInfo" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClient" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\Scheduled" /disable +schtasks /Change /TN "\Microsoft\Windows\Application Experience\PcaPatchDbTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Device information\Device" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Setup\Metadata Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" /disable +schtasks /Change /TN "\Microsoft\Windows\Location\Notifications" /disable +schtasks /Change /TN "\Microsoft\Windows\Speech\SpeechModelDownloadTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Maintenance\WinSAT" /disable +schtasks /Change /TN "\Microsoft\Windows\PI\Sqm-Tasks" /disable +del /F /Q "C:\Windows\System32\Tasks\Microsoft\Windows\SettingSync\*" +schtasks /Change /TN "\Microsoft\Windows\AppListBackup\Backup" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Information\Device" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Information\Device User" /disable +schtasks /Change /TN "\Microsoft\Windows\Device Setup\Metadata Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner" /disable +schtasks /Change /TN "\Microsoft\Windows\Diagnosis\Scheduled" /disable +schtasks /Change /TN "\Microsoft\Windows\DirectX\DXGIAdapterCache" /disable +schtasks /Change /TN "\Microsoft\Windows\DirectX\DirectXDatabaseUpdater" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskFootprint\Diagnostics" /disable +schtasks /Change /TN "\Microsoft\Windows\DiskFootprint\StorageSense" /disable +schtasks /Change /TN "\Microsoft\Windows\DUSM\dusmtask" /disable +schtasks /Change /TN "\Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClient" /disable +schtasks /Change /TN "\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting" /disable +schtasks /Change /TN "\Microsoft\Windows\Flighting\OneSettings\RefreshCache" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\LocalUserSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\MouseSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\PenSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\Input\TouchpadSyncDataAvailable" /disable +schtasks /Change /TN "\Microsoft\Windows\International\Synchronize Language Settings" /disable +schtasks /Change /TN "\Microsoft\Windows\Kernel\La57Cleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\Location\WindowsActionDialog" /disable +schtasks /Change /TN "\Microsoft\Windows\Management\Provisioning\Logon" /disable +schtasks /Change /TN "\Microsoft\Windows\Management\Provisioning\Cellular" /disable +schtasks /Change /TN "\Microsoft\Windows\Maps\MapsToastTask" /disable +schtasks /Change /TN "\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents" /disable +schtasks /Change /TN "\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic" /disable +schtasks /Change /TN "\Microsoft\Windows\NlaSvc\WiFiTask" /disable +schtasks /Change /TN "\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask" /disable +schtasks /Change /TN "\Microsoft\Windows\RetailDemo\CleanupOfflineContent" /disable +schtasks /Change /TN "\Microsoft\Windows\Servicing\StartComponentCleanup" /disable +schtasks /Change /TN "\Microsoft\Windows\Shell\FamilySafetyRefreshTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Shell\FamilySafetyMonitor" /disable +schtasks /Change /TN "\Microsoft\Windows\Sysmain\WsSwapAssessmentTask" /disable +schtasks /Change /TN "\Microsoft\Windows\Sysmain\ResPriStaticDbSync" /disable +schtasks /Change /TN "\Microsoft\Windows\SystemRestore\SR" /disable +schtasks /Change /TN "\Microsoft\Windows\TPM\Tpm-HASCertRetr" /disable +schtasks /Change /TN "\Microsoft\Windows\TPM\Tpm-Maintenance" /disable +schtasks /Change /TN "\Microsoft\Windows\UPnP\UPnPHostConfig" /disable +schtasks /Change /TN "\Microsoft\Windows\WlanSvc\CDSSync" /disable +schtasks /Change /TN "\Microsoft\Windows\WwanSvc\NotificationTask" /disable +schtasks /Change /TN "\Microsoft\Windows\WwanSvc\OobeDiscovery" /disable + + +::automatic App Update Windows +schtasks /Change /TN "Microsoft\Windows\WindowsUpdate\Automatic Update" /disable + +:: Office Telemetry Disable + +schtasks /Change /TN "\Microsoft\Office\OfficeTelemetryAgentFallBack2016" /disable +schtasks /Change /TN "\Microsoft\Office\OfficeTelemetryAgentLogOn2016" /disable + + +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\HandleCommand" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\HandleWnsCommand" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\LocateCommandUserSession" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged" /disable +schtasks /Change /TN "\Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceSettingChange" /disable + +:: Remove Telemetry + +takeown /f C:\Windows\System32\smartscreen.exe +cacls C:\Windows\System32\smartscreen.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\smartscreen.exe" +takeown /f C:\Windows\System32\smartscreenps.dll +cacls C:\Windows\System32\smartscreenps.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\smartscreenps.dll" +takeown /f C:\Windows\System32\DeviceCensus.exe +cacls C:\Windows\System32\DeviceCensus.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\DeviceCensus.exe" +takeown /f C:\Windows\System32\CompatTelRunner.exe +cacls C:\Windows\System32\CompatTelRunner.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\CompatTelRunner.exe" +takeown /f C:\Windows\System32\dmclient.exe +cacls C:\Windows\System32\dmclient.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\dmclient.exe" +takeown /f C:\Windows\hh.exe +cacls C:\Windows\hh.exe /E /P %username%:F +del /F /Q "C:\Windows\hh.exe" +takeown /f C:\Windows\HelpPane.exe +cacls C:\Windows\HelpPane.exe /E /P %username%:F +del /F /Q "C:\Windows\HelpPane.exe" + + +:: Boot Parameters +bcdedit /set allowedinmemorysettings 0 +bcdedit /set hypervisorlaunchtype Off +bcdedit /set tscsyncpolicy Enhanced +bcdedit /set debug No +bcdedit /set isolatedcontext No +bcdedit /set bootmenupolicy Legacy +bcdedit /set usefirmwarepcisettings No +bcdedit /set sos Yes +bcdedit /set x2apicpolicy Enable +bcdedit /set vsmlaunchtype Off +bcdedit /set usephysicaldestination No +bcdedit /set ems No +bcdedit /set firstmegabytepolicy UseAll +bcdedit /set configaccesspolicy Default +bcdedit /set linearaddress57 optin +bcdedit /set noumex Yes +bcdedit /set bootems No +bcdedit /set graphicsmodedisabled No +bcdedit /set extendedinput Yes +bcdedit /set highestmode Yes +bcdedit /set forcefipscrypto No +bcdedit /set perfmem 0 +bcdedit /set clustermodeaddressing 1 +bcdedit /set usefirmwarepcisettings No +bcdedit /set uselegacyapicmode No +bcdedit /set onecpu No +bcdedit /set halbreakpoint No +bcdedit /set forcelegacyplatform No +bcdedit /set tpmbootentropy ForceDisable +bcdedit /timeout 0 +bcdedit /set allowedinmemorysettings 0x0 +bcdedit /set isolatedcontext No +bcdedit /set configaccesspolicy Default +bcdedit /set MSI Default +bcdedit /set usephysicaldestination No +bcdedit /set usefirmwarepcisettings No +bcdedit /set linearaddress57 OptOut +bcdedit /set increaseuserva 268435328 +bcdedit /set firstmegabytepolicy UseAll +bcdedit /set avoidlowmemory 0x8000000 +bcdedit /set nolowmem Yes +bcdedit /set allowedinmemorysettings 0x0 +bcdedit /set vm No +bcdedit /set pae ForceEnable +bcdedit /set useplatformclock No +bcdedit /set {current} recoveryenabled no +bcdedit /create {0cb3b571-2f2e-4343-a879-d86a476d7215} /d +bcdedit /set {bootmgr} bootsequence {0cb3b571-2f2e-4343-a879-d86a476d7215} +bcdedit /set {0cb3b571-2f2e-4343-a879-d86a476d7215} loadoptions DISABLE-LSA-ISO,,DISABLE-VBS +bcdedit /set {current} disableelamdrivers yes +bcdedit /set vsmlaunchtype off +bcdedit /set recoveryenabled NO +bcdedit -set NOINTEGRITYCHECKS OFF +bcdedit -set TESTSIGNING OFF +bcdedit /set tscsyncpolicy legacy +bcdedit /set x2apicpolicy enable +bcdedit /set disabledynamictick yes +bcdedit /deletevalue useplatformclock +bcdedit /set useplatformtick yes +bcdedit /set nx AlwaysOff +bcdedit /set bootmenupolicy Legacy + + +:: Copy Files to Windows Folder +xcopy secdrv.sys ""C:\Windows\system32\drivers" /Y +xcopy "*.ico" "C:\Windows" /Y + +:: Mitigation Stuff + +powershell "ForEach($v in (Get-Command -Name \"Set-ProcessMitigation\").Parameters[\"Disable\"].Attributes.ValidValues){Set-ProcessMitigation -System -Disable $v.ToString().Replace(\" \", \"\").Replace(\"`n\", \"\") -ErrorAction SilentlyContinue}" +powershell "Set-ProcessMitigation -System -Enable CFG" +powershell "Set-ProcessMitigation -Name vgc.exe -Enable AuditDynamicCode" +powershell "Set-ProcessMitigation -Name vgc.exe -Enable CFG" +powershell "Set-ProcessMitigation -Name csgo.exe -Disable CFG" +powershell "Set-ProcessMitigation -Name FarCry6.exe -Disable CFG" + +echo Security Tweaks + +Reg add "HKLM\System\CurrentControlSet\Control\Class{4d36e96c-e325-11ce-bfc1-08002be10318}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{4d36e967-e325-11ce-bfc1-08002be10318}" /v "LowerFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{6bdd1fc6-810f-11d0-bec7-08002be2092f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{71a27cdd-812a-11d0-bec7-08002be2092f}" /v "LowerFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{71a27cdd-812a-11d0-bec7-08002be2092f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f +Reg add "HKLM\System\CurrentControlSet\Control\Class{ca3e7ab9-b4c3-4ae6-8251-579ef933890f}" /v "UpperFilters" /t Reg_MULTI_SZ /d "" /f + +xcopy "*.exe" "C:\Windows\System32" /Y + + +:: File Remover +takeown /f C:\Windows\System32\GamePanel.exe +cacls C:\Windows\System32\GamePanel.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanel.exe" +takeown /f C:\Windows\System32\wermgr.exe +cacls C:\Windows\System32\wermgr.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\wermgr.exe" +takeown /f C:\Windows\System32\wersvc.dll +cacls C:\Windows\System32\wersvc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\wersvc.dll" +takeown /f C:\Windows\System32\werui.dll +cacls C:\Windows\System32\werui.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werui.dll" +takeown /f C:\Windows\System32\WerEnc.dll +cacls C:\Windows\System32\WerEnc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\WerEnc.dll" +takeown /f C:\Windows\System32\WerFault.exe +cacls C:\Windows\System32\WerFault.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\WerFault.exe" +takeown /f C:\Windows\System32\wercplsupport.dll +cacls C:\Windows\System32\wercplsupport.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\wercplsupport.dll" +takeown /f C:\Windows\System32\werdiagcontroller.dll +cacls C:\Windows\System32\werdiagcontroller.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werdiagcontroller.dll" +takeown /f C:\Windows\System32\lfsvc.dll +cacls C:\Windows\System32\lfsvc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\lfsvc.dll" +takeown /f C:\Windows\System32\WerEnc.dll +cacls C:\Windows\System32\WerEnc.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\WerEnc.dll" +takeown /f C:\Windows\System32\werui.dll +cacls C:\Windows\System32\werui.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\werui.dll" +takeown /f C:\Windows\System32\WerFaultSecure.exe +cacls C:\Windows\System32\WerFaultSecure.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\WerFaultSecure.exe" +takeown /f C:\Windows\System32\gameux.dll +cacls C:\Windows\System32\gameux.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\gameux.dll" +takeown /f C:\Windows\System32\GamePanelExternalHook.dll +cacls C:\Windows\System32\GamePanelExternalHook.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanelExternalHook.dll" +takeown /f C:\Windows\System32\GamePanel.exe +cacls C:\Windows\System32\GamePanel.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GamePanel.exe" +takeown /f C:\Windows\System32\gamemode.dll +cacls C:\Windows\System32\gamemode.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\gamemode.dll" +takeown /f C:\Windows\System32\GameBarPresenceWriter.exe +cacls C:\Windows\System32\GameBarPresenceWriter.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\GameBarPresenceWriter.exe" +takeown /f C:\Windows\System32\zipcontainer.dll +cacls C:\Windows\System32\zipcontainer.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\zipcontainer.dll" +takeown /f C:\Windows\System32\msfeeds.dll +cacls C:\Windows\System32\msfeeds.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\msfeeds.dll" +takeown /f C:\Windows\System32\MsSpellCheckingHost.exe +cacls C:\Windows\System32\MsSpellCheckingHost.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\MsSpellCheckingHost.exe" +takeown /f C:\Windows\System32\ieapfltr.dll +cacls C:\Windows\System32\ieapfltr.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\ieapfltr.dll" +takeown /f C:\Windows\System32\MsSpellCheckingFacility.dll +cacls C:\Windows\System32\MsSpellCheckingFacility.dll /E /P %username%:F +del /F /Q "C:\Windows\System32\MsSpellCheckingFacility.dll" +takeown /f C:\Windows\System32\LocationNotificationWindows.exe +cacls C:\Windows\System32\LocationNotificationWindows.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\LocationNotificationWindows.exe" +takeown /f C:\Windows\System32\msfeedssync.exe +cacls C:\Windows\System32\msfeedssync.exe /E /P %username%:F +del /F /Q "C:\Windows\System32\msfeedssync.exe" +takeown /f C:\Windows\winhlp32.exe +cacls C:\Windows\winhlp32.exe /E /P %username%:F +del /F /Q "C:\Windows\winhlp32.exe" +takeown /f C:\Windows\System32\WpcMon.exe +cacls "C:\Windows\System32\WpcMon.exe" /E /P %username%:F +del /F /Q "C:\Windows\System32\WpcMon.exe" +takeown /f C:\Windows\System32\atieclxx.exe +cacls "C:\Windows\System32\atieclxx.exe" /E /P %username%:F +del /F /Q "C:\Windows\System32\atieclxx.exe" + +:: Windows Error Reporting +Reg.exe add "HKLM\Software\Microsoft\Windows\Windows Error Reporting\Assert Filtering Policy" /v "ReportAndContinue" /t REG_DWORD /d "0" /f +sc delete WerSvc +sc delete wercplsupport + +:: Disable Windows Update Driver Search + +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching" /v "SearchOrderConfig" /t REG_DWORD /d "3" /f +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\DriverMetadata" /v "PreventDeviceMetadataFromNetwork" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\default\Update" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\WindowsUpdate\UX\Settings" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKLM\SOFTWARE\Microsoft\PolicyManager\current\device\Update" /v "ExcludeWUDriversInQualityUpdate" /t REG_DWORD /d "1" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" /v "DontSearchWindowsUpdate" REG_DWORD /d "1" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DriverSearching" /v "DontPromptForWindowsUpdate" REG_DWORD /d "1" /f + +:: Copying SDL in System 32... + +copy "%~dp0\SDL.dll" "C:\Windows\System32\SDL.dll" /Y +copy "%~dp0\SDL.dll" "C:\Windows\SysWOW64\SDL.dll" /Y + +:: Windows Defender Configuration + +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System" /v "EnableSmartScreen" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter" /v "EnabledV9" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender" /v "DisableRoutinelyTakingAction" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\SmartScreen" /v "ConfigureAppInstallControlEnabled" /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "1" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "2" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "4" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Threats\ThreatSeverityDefaultAction" /v "5" /t REG_SZ /d "6" /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\UX Configuration" /v "Notification_Suppress" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpyNetReporting /t REG_DWORD /d 0 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SubmitSamplesConsent /t REG_DWORD /d 2 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v DontReportInfectionInformation /t REG_DWORD /d 1 /f + +netsh Advfirewall set allprofiles state on + + +:: Another Tweaks +for /f %%i in ('Reg query "HKLM\SYSTEM\CurrentControlSet\Services" /s /f DmaRemappingCompatible ^| find /i "Services\" ') do ( +Reg add "%%i" /v "DmaRemappingCompatible" /t Reg_DWORD /d "0" /f ) +reg add "HKU\!USER_SID!\Control Panel\Mouse" /v "SmoothMouseXCurve" /t REG_BINARY /d "0000000000000000c0cc0c0000000000809919000000000040662600000000000033330000000000" /f +reg add "HKU\!USER_SID!\Control Panel\Mouse" /v "SmoothMouseYCurve" /t REG_BINARY /d "0000000000000000000038000000000000007000000000000000a800000000000000e00000000000" /f + +::Get Insider Updates without joining the Insider Program and without having Telemetry enabled +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v "BranchReadinessLevel" /t REG_DWORD /d 2 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v "ManagePreviewBuilds" /t REG_DWORD /d 1 /f +reg add "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate" /v "ManagePreviewBuildsPolicyValue" /t REG_DWORD /d 2 /f + +reg add "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fidelity" /v DisplayName /t reg_sz /d "Melody 12.0 (EAS)" /f +shutdown /r /f /t 0 + + + diff --git a/Melody 12.01 (Script for Windows Insider Preview)/fidelityreg_reg11.reg b/Melody 12.01 (Script for Windows Insider Preview)/fidelityreg_reg11.reg new file mode 100644 index 0000000..a9e5e33 --- /dev/null +++ b/Melody 12.01 (Script for Windows Insider Preview)/fidelityreg_reg11.reg @@ -0,0 +1,8444 @@ +Windows Registry Editor Version 5.00 + +;001.Optimize GPU Usage (set system and productivity Apps to iGPU) + +[HKEY_CURRENT_USER\Software\Microsoft\DirectX\UserGpuPreferences] +"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"="AutoHDREnable=1;GpuPreference=1;" +"C:\Windows\System32\rundll32.exe"="AutoHDREnable=1;GpuPreference=1;" +"C:\\Windows\\System32\\bdeunlock.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bdechangepin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipDLS.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ScriptRunner.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplySettingsTemplateCatalog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Microsoft.Uev.CscUnpinTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UevAppMonitor.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Microsoft.Uev.SyncController.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chgport.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chgusr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\query.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\logoff.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qappsrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qprocess.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\reset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rwinsta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tscon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tsdiscon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tskill.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\quser.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\qwinsta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\baaupdate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\logagent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mfpmp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PackageInspector.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\manage-bde.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PresentationSettings.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AgentService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\repair-bde.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipRenew.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CustomShellHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AssignedAccessGuard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mavinject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BitLockerDeviceEncryption.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpshell.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AppVClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BdeHdCfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CameraSettingsUIHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RemoteAppLifetimeManager.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpsign.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fveprompt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iotstartup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fvenotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WPDShextAutoplay.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BdeUISrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbengine.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MsSpellCheckingHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bootim.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinBioDataModelOOBE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UevAppMonitor.exe.config" +"C:\\Windows\\System32\\AppV\\AppVStreamingUX.exe.config" +"C:\\Windows\\System32\\PresentationHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rstrui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\srdelayed.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SrTasks.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SpaceAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\provlaunch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EduPrintProv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UNPUXHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UNPUXLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UNP\\UpdateNotificationMgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Spectrum.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SIHClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\xwizard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\takeown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vssadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\where.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cacls.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eventcreate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsavailux.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ftp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\grpconv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runas.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systeminfo.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\taskkill.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tasklist.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\timeout.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\waitfor.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\whoami.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mstsc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TSTheme.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wkspbroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TSWbPrxy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSa.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSaProxy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RdpSaUacHelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sessionmsg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TieringEngineService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpclip.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdpinput.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TapiUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dialer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tcmsetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MultiDigiMon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tabcal.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\FsIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dvdplay.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\calc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\charmap.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\credwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\certreq.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\certutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\klist.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ksetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nltest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regini.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regsvr32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setspn.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\regedt32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ResetEngine.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SysResetErr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systemreset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemResetPlatform\\SystemResetPlatform.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\migwiz\\mighost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pwlauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fodhelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Fondue.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\OptionalFeatures.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CheckNetIsolation.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msiexec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mblctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msconfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LocationNotificationWindows.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mmc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsActionDialog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cliconfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\odbcad32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\odbcconf.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iscsicpl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iscsicli.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\IESettingSync.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ie4uinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ie4ushowIE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\F12\\IEChooser.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ieUnatt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\iexpress.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wextract.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mshta.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wiaacmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wiawow64.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bridgeunattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eventvwr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpresult.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\gpupdate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\esentutl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\eudcedit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wecutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\easinvoker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EhStorAuthn.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DpiScaling.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dxpserver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceProperties.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DisplaySwitch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsRemoveDevice.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SyncHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DevicePairingWizard.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ComputerDefaults.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DataExchangeHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompMgmtLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\convert.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\find.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ktmutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\label.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\openfiles.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\replace.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Robocopy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\stordiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\choice.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\clip.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\doskey.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\forfiles.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\print.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\subst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cttune.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cttunesvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\help.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\msdtc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CastSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserDataSource.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\curl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tar.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spaceman.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spaceutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EDPCleanup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MDMAppInstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ARP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\finger.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\HOSTNAME.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MRINFO.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NETSTAT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ROUTE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sort.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TCPSVCS.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\xcopy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\auditpol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mountvol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\net.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\net1.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netsh.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PATHPING.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PING.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\reg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TRACERT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\attrib.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ClipUp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskusage.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\findstr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\icacls.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ipconfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CIDiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\comp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\recover.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sdclt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PerceptionSimulation\\PerceptionSimulationService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tcblaunch.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\securekernel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SgrmBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SgrmLpac.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\upnpcont.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BioIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NgcIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dusmtask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinBioPlugIns\\FaceFodUninstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GamePanel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GameBarPresenceWriter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\oobeldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\windeploy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\audit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\AuditShD.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MBR2GPT.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\Setup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\poqexec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PkgMgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dism\\DismHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmdkey.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dpapimig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LsaIso.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RmClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecEdit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wscript.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\icsunattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NetHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmmon32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmstp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmdl32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasautou.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasdial.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rasphone.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ntprint.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\printui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceEject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\powercfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sigverif.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\drvinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\hdwwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pnputil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wowreg32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\InfDefault-"="GpuPreference=1;" +"C:\\Windows\\System32\\ndadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\newdev.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\driverquery.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PnPUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\FirstLogonAnim.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\msoobe.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\oobe\\UserOOBEBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netbtugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netiougc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nbtstat.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\NetCfgNotifyObjectHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\djoin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\getmac.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\shrpubw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesAdvanced.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesComputerName.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesDataExecutionPrevention.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesHardware.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesPerformance.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesProtection.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemPropertiesRemote.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sxstrace.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Sysprep\\sysprep.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSCollect.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSReset.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\changepk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LicensingUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\phoneactivate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UpgradeResultsUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\GenValObj.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\slui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SppExtComObj.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sppsvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech\\SpeechUX\\SpeechUXWiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\snmptrap.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\immersivetpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rmttpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tpmvscmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tpmvscmgrsvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\OpenWith.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ThumbnailExtractionHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verclsid.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WallpaperHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\prevhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rundll32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mcbuilder.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MSchedExe.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WUDFCompanionHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WUDFHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AxInstUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\consent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LanguageComponentsInstallerComHandler.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LockAppHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\la57setup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lpk-"="GpuPreference=1;" +"C:\\Windows\\System32\\lpksetup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lpremove.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DsmUserTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\netcfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runonce.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\secinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\colorcpl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dccw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Dism.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\proquota.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserAccountControlSettings.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\shutdown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\efsui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cipher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\edpnotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeCP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rekeywiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dnscacheugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\nslookup.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lodctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\unlodctr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ddodiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\omadmclient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\omadmprc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DmOmaCpMo.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\coredpussvr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceEnroller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmcertinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmcfghost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CredentialUIBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SensorDataService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\prproc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Windows.Media.BackgroundPlayback.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sfc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wusa.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\wbemtest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\scrcons.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplyTrustOffline.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CustomInstallExec.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\deploymentcsphelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\expand.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ReAgentc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RelPost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MuiUnattend.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dxdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fontdrvhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winlogon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DiagSvcs\\DiagnosticsHub.StandardCollector.Service.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\drivers\\ExecutionContext.sys" +"C:\\Windows\\System32\\ucsvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fltMC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\lsass.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ntoskrnl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\services.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\smss.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\csrss.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Boot\\winload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AggregatorHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dtdump.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\runexehelper.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\rdrleakdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wpr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pacjsworker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\userinit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wininit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceCensus.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dllhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\conhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\extrac32.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\makecab.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\svchost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\compact.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dwm.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dcomcnfg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Locator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Com\\MigRegDB.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RpcPing.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mtstocom.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Com\\comrepl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dllhst3g.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setupcl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\setupugc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wimserv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chkdsk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\chkntfs.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wsqmcons.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\autochk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\browser_broker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\browserexport.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Boot\\winresume.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winresume.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bthudtask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fsquirt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bitsadmin.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\refsutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidcertstorecheck.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidpolicyconverter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SndVol.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\appidtel.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompatTelRunner.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sdbinst.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pcalua.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\aitstatic.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LaunchTM.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pcaui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Taskmgr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Utilman.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EaseOfAccessDialog.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Narrator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\osk.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sethc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AtBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Magnify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\EoAExperiences.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CloudExperienceHostBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApplicationFrameHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SecurityHealthSystray.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ShellAppRuntime.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\desktopimgdownldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsAdminFlows.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\VSSVC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\convertvhd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wuauclt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotifyIcon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WindowsUpdateElevatedInstaller.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotification.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MusNotificationUx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MoNotificationUx.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UsoClient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech_OneCore\\common\\SpeechModelDownload.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Speech_OneCore\\common\\SpeechRuntime.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DeviceCredentialDeployment.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LegacyNetUXHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wevtutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dasHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DiskSnapshot.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verifier.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Register-CimProvider.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WinMgmt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WmiPrvSE.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winrs.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\winrshost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WMIC.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WSManHTTPConfig.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wsmprovhost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LogonUI.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mpnotify.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wlrmdr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskpart.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\diskraid.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vds.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\vdsldr.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fixmapi.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Netplwiz.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PasswordOnWakeSettingFlyout.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UserAccountBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LaunchWinApp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\verifiergui.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tzsync.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wksprt.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\InputSwitchToastHandler.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UIMgrBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ctfmon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\taskhostw.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\at.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\schtasks.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MdmDiagnosticsTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\alg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\cmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PackagedCWALauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\mmgaserver.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AuthHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\backgroundTaskHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\VaultCmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\licensingdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CertEnrollCtrl.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RuntimeBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\BackgroundTransferHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ByteCodeGenerator.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WWAHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WaaSMedicAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\upfc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wuapihost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ttdinject.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tttracer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\sihost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\pospaymentsworker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RemotePosWorker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LicenseManagerShellext.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ISM.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchFilterHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchIndexer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SearchProtocolHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\directxdatabaseupdater.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dispdiag.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Windows.WARP.JITService.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dxgiadaptercache.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeSH.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TokenBrokerCookies.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\AppHostRegistrationVerifier.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dstokenclean.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WinRTNetMUAHostServer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PickerHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\execmodelproxy.dll" +"C:\\Windows\\System32\\ExecModelClient.dll" +"C:\\Windows\\System32\\SystemUWPLauncher.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DataStoreCacheDumpTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CredentialEnrollmentManager.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wlanext.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\LockScreenContentServer.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SlideToShutDown.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\systray.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RunLegacyCPLElevated.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\control.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\fontview.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wifitask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\tzutil.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\w32tm.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dmclient.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\dsregcmd.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\UtcDecoderHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TpmTool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\HealthAttestationClientAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TpmInit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CloudNotifications.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SystemSettingsBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\mofcomp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\unsecapp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WMIADAP.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\wbem\\WmiApSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_isv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_ssp.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\RMActivate_ssp_isv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\printfilterpipelinesvc.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\provtool.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PrintIsolationHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\spoolsv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\PinEnrollmentBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WpcTok.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\WpcMon.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ApproveChildRequest.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ofdeploy.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\DmNotificationBroker.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MDMAgent.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\MicrosoftEdgeBCHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\Eap3Host.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bcdboot.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bcdedit.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\bootsect.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\audiodg.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\SpatialAudioLicenseSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\CompPkgSrv.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\agentactivationruntimestarter.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\IcsEntitlementHost.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\ShellUpdateAgentTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\XblGameSaveTask.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\en-US\\notepad.exe.mui" +"C:\\Windows\\System32\\notepad.exe"="GpuPreference=1;" +"C:\\Windows\\System32\\TsWpfWrp.exe"="GpuPreference=1;" + +; 002. IRQ Priority + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouclass\Parameters] +"ThreadPriority"=dword:0000001f + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\mouhid\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DXGKrnl\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\USBXHCI\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\USBHUB3\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\amdkmdap\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\nvlddmkm\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\amd_sata\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BTUSB\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BthLEEnum\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BthHFEnum\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\umbus_A1614B8FA282BCE3\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RTWlanE\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RtkBtManServ\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\RtkBtFilter\Parameters] +"ThreadPriority"=dword:0000001f + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\rtump64x64\Parameters] +"ThreadPriority"=dword:0000001f + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PriorityControl] +"IRQ4294967253Priority"=dword:00000001 +"IRQ4294967254Priority"=dword:00000001 +"IRQ4294967259Priority"=dword:00000001 +"IRQ4294967256Priority"=dword:00000001 +"IRQ4294967257Priority"=dword:00000001 +"IRQ4294967258Priority"=dword:00000001 +"IRQ4294967260Priority"=dword:00000002 +"IRQ4294967261Priority"=dword:00000002 +"IRQ4294967262Priority"=dword:00000001 +"IRQ39Priority"=dword:00000001 +"IRQ1024Priority"=dword:00000001 +"IRQ4294967287Priority"=dword:00000001 +"IRQ4294967288Priority"=dword:00000001 +"IRQ4294967289Priority"=dword:00000001 +"IRQ4294967290Priority"=dword:00000001 +"IRQ4294967291Priority"=dword:00000001 +"IRQ4294967292Priority"=dword:00000001 +"IRQ4294967293Priority"=dword:00000001 +"IRQ4294967294Priority"=dword:00000001 +"IRQ1Priority"=dword:00000001 +"IRQ6Priority"=dword:00000001 +"IRQ7Priority"=dword:00000001 +"IRQ25Priority"=dword:00000001 +"IRQ36Priority"=dword:00000001 +"IRQ55Priority"=dword:00000001 +"IRQ57Priority"=dword:00000001 +"IRQ8Priority"=dword:00000001 +"Win32PrioritySeparation"=dword:00000038 + + +; 003. MMSSVC + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Audio] +"Affinity"=dword:00000007 +"Background Only"="True" +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000006 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Low Latency] +"Affinity"=dword:00000000 +"Background Only"="False" +"BackgroundPriority"=dword:00000000 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000002 +"Scheduling Category"="High" +"SFIO Priority"="High" +"Latency Sensitive"="True" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Audio] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000001 +"Priority"=dword:00000002 +"Scheduling Category"="High" +"SFIO Priority"="High" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Capture] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000005 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\DisplayPostProcessing] +"Affinity"=dword:00000000 +"Background Only"="True" +"BackgroundPriority"=dword:00000008 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000008 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Distribution] +"Affinity"=dword:00000000 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000004 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Playback] +"Affinity"=dword:00000007 +"Background Only"="False" +"BackgroundPriority"=dword:00000004 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000008 +"Priority"=dword:00000003 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Pro Audio] +"Affinity"=dword:00000007 +"Background Only"="False" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000001 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Window Manager] +"Affinity"=dword:00000007 +"Background Only"="True" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000005 +"Scheduling Category"="High" +"SFIO Priority"="Normal" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\DisplayPostProcessing] +"Affinity"=dword:00000000 +"Background Only"="True" +"BackgroundPriority"=dword:00000018 +"Clock Rate"=dword:00002710 +"GPU Priority"=dword:00000012 +"Priority"=dword:00000008 +"Scheduling Category"="High" +"SFIO Priority"="High" +"Latency Sensitive"="True" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile\Tasks\Games] +"Affinity"=dword:00000000 +"Background Only"="False" +"GPU Priority"=dword:00000008 +"Priority"=dword:00000006 +"Scheduling Category"="High" +"SFIO Priority"="High" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile] +"NoLazyMode"=dword:00000001 +"AlwaysOn"=dword:00000001 +"NetworkThrottlingIndex"=dword:ffffffff +"SystemResponsiveness"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\NetworkProvider] +"RestoreConnection"=dword:00000001 +"WakeUp"=dword:00000000 + +; 004. Contextual Menu + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay] +"Icon"="display.dll,-1" +"MUIVerb"="Turn off display" +"Position"="Bottom" +"SubCommands"="" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\01menu] +"Icon"="powercpl.dll,-513" +"MUIVerb"="Turn off display" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\01menu\command] +@="nircmd.exe cmdwait 1000 monitor async_off" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\02menu] +"MUIVerb"="Lock computer and Turn off display" +"CommandFlags"=dword:00000020 +"Icon"="imageres.dll,-59" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\TurnOffDisplay\shell\02menu\command] +@="cmd /c \"nircmd.exe cmdwait 1000 monitor async_off & rundll32.exe user32.dll, LockWorkStation\"" + + + +[HKEY_CLASSES_ROOT\exefile\shell\Priority] +"MUIVerb"="Run with priority" +"SubCommands"="" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\001flyout] +@="Realtime" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\001flyout\command] +@="cmd.exe /c start \"\" /Realtime \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\002flyout] +@="High" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\002flyout\command] +@="cmd.exe /c start \"\" /High \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\003flyout] +@="Above normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\003flyout\command] +@="cmd.exe /c start \"\" /AboveNormal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\004flyout] +@="Normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\004flyout\command] +@="cmd.exe /c start \"\" /Normal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\005flyout] +@="Below normal" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\005flyout\command] +@="cmd.exe /c start \"\" /BelowNormal \"%1\"" + + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\006flyout] +@="Low" + +[HKEY_CLASSES_ROOT\exefile\Shell\Priority\shell\006flyout\command] +@="cmd.exe /c start \"\" /Low \"%1\"" + + + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shell\Windows.PermanentDelete] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E9571AB2-AD92-4ec6-8924-4E5AD33790F5}" +"Icon"="shell32.dll,-240" +"Position"="Bottom" + + + +[HKEY_CLASSES_ROOT\Msi.Package\shell\Extract\command] +@="msiexec.exe /a \"%1\" /qb TARGETDIR=\"%1 Contents\"" + + +[HKEY_CLASSES_ROOT\VBSFile\Shell\runas\command] +@="C:\\Windows\\System32\\WScript.exe \"%1\" %*" + + +[HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\batfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\cmdfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\docxfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\fonfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\htmlfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\inffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\inifile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\JSEFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\otffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\pfmfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\regfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\rtffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\ttcfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\ttffile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\txtfile\shell\print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\VBEFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\VBSFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\WSFFile\Shell\Print] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash] +"MUIVerb"="Hash" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\01SHA1] +"MUIVerb"="SHA1" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\01SHA1\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA1 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\02SHA256] +"MUIVerb"="SHA256" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\02SHA256\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA256 | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\03SHA384] +"MUIVerb"="SHA384" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\03SHA384\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA384 | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\04SHA512] +"MUIVerb"="SHA512" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\04SHA512\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm SHA512 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\05MACTripleDES] +"MUIVerb"="MACTripleDES" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\05MACTripleDES\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm MACTripleDES | format-list" + + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\06MD5] +"MUIVerb"="MD5" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\06MD5\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm MD5 | format-list" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\07RIPEMD160] +"MUIVerb"="RIPEMD160" + +[HKEY_CLASSES_ROOT\*\shell\GetFileHash\shell\07RIPEMD160\command] +@="powershell.exe -noexit get-filehash -literalpath '%1' -algorithm RIPEMD160 | format-list" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\UEV\Agent] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WorkFolders] +"AutoProvision"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRE] +"DisableSetup"=dword:00000001 + +[HKEY_CLASSES_ROOT\*\shell\TakeOwnership] +@="Take Ownership" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"NeverDefault"="" + +[HKEY_CLASSES_ROOT\*\shell\TakeOwnership\command] +@="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l' -Verb runAs\"" +"IsolatedCommand"= "powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\Directory\shell\TakeOwnership] +@="Take Ownership" +"AppliesTo"="NOT (System.ItemPathDisplay:=\"C:\\Users\" OR System.ItemPathDisplay:=\"C:\\ProgramData\" OR System.ItemPathDisplay:=\"C:\\Windows\" OR System.ItemPathDisplay:=\"C:\\Windows\\System32\" OR System.ItemPathDisplay:=\"C:\\Program Files\" OR System.ItemPathDisplay:=\"C:\\Program Files (x86)\")" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"Position"="middle" + +[HKEY_CLASSES_ROOT\Directory\shell\TakeOwnership\command] +@="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" /r /d y && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l /q' -Verb runAs\"" +"IsolatedCommand"="powershell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/c takeown /f \\\"%1\\\" /r /d y && icacls \\\"%1\\\" /grant *S-1-3-4:F /t /c /l /q' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\Drive\shell\runas] +@="Take Ownership" +"Extended"=- +"HasLUAShield"="" +"NoWorkingDirectory"="" +"Position"="middle" +"AppliesTo"="NOT (System.ItemPathDisplay:=\"C:\\\")" + +[HKEY_CLASSES_ROOT\Drive\shell\runas\command] +@="cmd.exe /c takeown /f \"%1\\\" /r /d y && icacls \"%1\\\" /grant *S-1-3-4:F /t /c" +"IsolatedCommand"="cmd.exe /c takeown /f \"%1\\\" /r /d y && icacls \"%1\\\" /grant *S-1-3-4:F /t /c" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart] +"Icon"="shell32.dll,-16739" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\001flyout] +"MUIVerb"="Force apps to close, and full shutdown and restart PC with no time-out or warning" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\001flyout\command] +@="shutdown /r /f /t 0" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\002flyout] +"MUIVerb"="Full shutdown and restart PC with warning" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\002flyout\command] +@="shutdown /r" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\003flyout] +"MUIVerb"="Full shutdown and restart PC. After rebooted, restart any opened registered apps." +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\003flyout\command] +@="shutdown /g /t 0" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\004flyout] +"MUIVerb"="Restart to Advanced Startup Options" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart\shell\004flyout\command] +@="shutdown /r /o /f /t 0" + + +[-HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs] + +[HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs] +@="Install" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\CABFolder\Shell\RunAs\Command] +@="cmd /k dism /online /add-package /packagepath:\"%1\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars] +"MUIVerb"="Environment variables" +"Icon"="sysdm.cpl,-1" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\01UserVars] +"MUIVerb"="User variables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\01UserVars\Command] +@="rundll32.exe sysdm.cpl,EditEnvironmentVariables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\02SystemVars] +"HasLUAShield"="" +"MUIVerb"="System variables" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\EnvVars\shell\02SystemVars\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process rundll32 -ArgumentList '/s,/c, sysdm.cpl,EditEnvironmentVariables' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\*\shell\Copy Content to Clipboard] +"MUIVerb"="Copy Content to Clipboard" +"Icon"="DxpTaskSync.dll,-52" +"Position"="Center" + +[HKEY_CLASSES_ROOT\*\shell\Copy Content to Clipboard\Command] +@="cmd /c clip < \"%1\"" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Safely Remove Hardware] +"MUIVerb"="Safely Remove Hardware" +"Icon"="hotplug.dll,-100" +"Position"="Center" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Safely Remove Hardware\Command] +@="C:\\Windows\\system32\\control.exe hotplug.dll" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall] +"MUIVerb"="Windows Firewall" +"Icon"="FirewallControlPanel.dll,-1" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command001] +"MUIVerb"="Windows Firewall" +"Icon"="FirewallControlPanel.dll,-1" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command001\Command] +@="RunDll32.exe shell32.dll,Control_RunDLL firewall.cpl" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command002] +"MUIVerb"="Windows Firewall with Advanced Security" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command002\Command] +@="mmc.exe /s wf.msc" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command003] +"MUIVerb"="Configure Allowed Apps" +"Icon"="FirewallControlPanel.dll,-1" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command003\Command] +@="explorer.exe shell:::{4026492F-2F69-46B8-B9BF-5654FC07E423} -Microsoft.WindowsFirewall\\pageConfigureApps" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command004] +"MUIVerb"="Turn On Windows Firewall" +"HasLUAShield"="" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command004\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall set allprofiles state on' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command005] +"MUIVerb"="Turn Off Windows Firewall" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command005\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall set allprofiles state off' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command006] +"MUIVerb"="Reset Windows Firewall" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Firewall\shell\Command006\Command] +@="powershell.exe -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/c,netsh advfirewall reset' -Verb runAs\"" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\KillNRTasks] +"icon"="taskmgr.exe,-30651" +"MUIverb"="Kill all not responding tasks" +"Position"="Top" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\KillNRTasks\command] +@="CMD.exe /C taskkill.exe /f /fi \"status eq Not Responding\" & Pause" + + +[HKEY_CURRENT_USER\Software\Classes\*\shellex\ContextMenuHandlers\PintoStartScreen] +@="{470C0EBD-5D73-4d58-9CED-E91E22E23282}" + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex\ContextMenuHandlers] + +[HKEY_CURRENT_USER\Software\Classes\AllFileSystemObjects\shellex\ContextMenuHandlers\PintoStartScreen] +@="{470C0EBD-5D73-4d58-9CED-E91E22E23282}" + + + +[-HKEY_CLASSES_ROOT\DesktopBackground\Shell\AdvancedBootOptions] + + +[HKEY_CLASSES_ROOT\*\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + +[HKEY_CLASSES_ROOT\Directory\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shell\windows.copyaspath] +"CanonicalName"="{707C7BC6-685A-4A4D-A275-3966A5A3EFAA}" +"CommandStateHandler"="{3B1599F9-E00A-4BBF-AD3E-B3F99FA87779}" +"CommandStateSync"="" +"Description"="@shell32.dll,-30336" +"Icon"="imageres.dll,-5302" +"InvokeCommandOnSelection"=dword:00000001 +"MUIVerb"="@shell32.dll,-30329" +"VerbHandler"="{f3d06e7c-1e45-4a26-847e-f9fcdee59be0}" +"VerbName"="copyaspath" + +[HKEY_CLASSES_ROOT\Drive\shell\Advanced Security] +"CommandStateSync"="" +"ExplorerCommandHandler"="{E2765AC3-564C-40F9-AC12-CD393FBAAB0F}" +"Icon"="ntshrui.dll,-122" +"Position"="Center" + + +; 1.6. Restart File Explorer + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer] +"icon"="explorer.exe" +"Position"="Center" +"SubCommands"="" +"MUIVerb"="Restart/Pause File Explorer " + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell] + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\01menu] +"MUIVerb"="Restart File Explorer" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\01menu\command] +@="cmd.exe /c taskkill /f /im explorer.exe & start explorer.exe" + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\02menu] +"MUIVerb"="Pause File Explorer" +"CommandFlags"=dword:00000020 + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\Restart Explorer\shell\02menu\command] +@="cmd.exe /c @echo off & echo. & echo Stopping explorer.exe process . . . & echo. & taskkill /f /im explorer.exe & echo. & echo. & echo Waiting to start explorer.exe process when you are ready . . . & pause && start explorer.exe && exit" + + +[HKEY_CLASSES_ROOT\DesktopBackground\Shell\DismContextMenu] +"Icon"="WmiPrvSE.exe" +"MUIVerb"="Repair Windows Image" +"Position"="Bottom" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\CheckHealth] +"HasLUAShield"="" +"MUIVerb"="Check Health of Windows Image" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\CheckHealth\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, Dism /Online /Cleanup-Image /CheckHealth' -Verb runAs\"" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\RestoreHealth] +"HasLUAShield"="" +"MUIVerb"="Repair Windows Image" + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\RestoreHealth\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, Dism /Online /Cleanup-Image /RestoreHealth' -Verb runAs\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions] +"HasLUAShield"="" +"MUIVerb"="Check for Corruptions" + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions\command] +@="PowerShell -windowstyle hidden -command \"Start-Process cmd -ArgumentList '/s,/k, sfc.exe /scannow' -Verb runAs\"" + + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions_log] +"HasLUAShield"="" +"MUIVerb"="View Scan Logs" + + +[HKEY_CLASSES_ROOT\DesktopBackground\shell\DismContextMenu\shell\Corruptions_log\command] +@="PowerShell (Select-String [SR] $env:windir\\Logs\\CBS\\CBS.log -s).Line >\"$env:userprofile\\Desktop\\SFC_LOG.txt\"" + + + +;; 1.2.Windows Terminal + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked] +"{9F156763-7844-4DC4-B2B1-901F640F5155}"="" + +[HKEY_CLASSES_ROOT\Directory\shell\OpenWindowsTerminalProfiles] +"MUIVerb"="Open in Windows Terminal" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile] +"MUIVerb"="Default Profile" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile\command] +@="cmd.exe /c start wt.exe -d \"%1\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile] +"MUIVerb"="Command Prompt" +"Icon"="imageres.dll,-5323" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile\command] +@="cmd.exe /c start wt.exe -p \"Command Prompt\" -d \"%1\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile] +"MUIVerb"="PowerShell" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile\command] +@="cmd.exe /c start wt.exe -p \"Windows PowerShell\" -d \"%1\"" + +[HKEY_CLASSES_ROOT\Directory\Background\shell\OpenWindowsTerminalProfiles] +"MUIVerb"="Open in Windows Terminal" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile] +"MUIVerb"="Default Profile" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\01DefaultProfile\command] +@="cmd.exe /c start wt.exe -d \"%V\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile] +"MUIVerb"="Command Prompt" +"Icon"="imageres.dll,-5323" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\02CommandPromptProfile\command] +@="cmd.exe /c start wt.exe -p \"Command Prompt\" -d \"%V\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile] +"MUIVerb"="PowerShell" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\OpenWindowsTerminalProfiles\shell\03PowerShellProfile\command] +@="cmd.exe /c start wt.exe -p \"Windows PowerShell\" -d \"%V\"" + + +; 1.2.1 Windows Terminal for Directory + +[HKEY_CLASSES_ROOT\Directory\shell\WindowsTerminalAsAdmin] +"HasLUAShield"="" +"MUIVerb"="Open in Windows Terminal as Administrator" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile] +"MUIVerb"="Open in Windows Terminal as Administrator - Default Profile" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\02Cmd] +"MUIVerb"="Open in Windows Terminal as Administrator - Command Prompt" +"Icon"="imageres.dll,-5324" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\02Cmd\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Command Prompt\"\"\"','-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\03PS] +"MUIVerb"="Open in Windows Terminal as Administrator - PowerShell" +"HasLUAShield"="" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Shell\WindowsTerminalAsAdmin\shell\03PS\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Windows PowerShell\"\"\"','-d','.')\"" + +; Directory\Background + +[HKEY_CLASSES_ROOT\Directory\Background\shell\WindowsTerminalAsAdmin] +"HasLUAShield"="" +"MUIVerb"="Open in Windows Terminal as Administrator" +"SubCommands"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile] +"MUIVerb"="Open in Windows Terminal as Administrator - Default Profile" +"HasLUAShield"="" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\01defaultProfile\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\02Cmd] +"MUIVerb"="Open in Windows Terminal as Administrator - Command Prompt" +"Icon"="imageres.dll,-5324" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\02Cmd\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Command Prompt\"\"\"','-d','.')\"" + + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\03PS] +"MUIVerb"="Open in Windows Terminal as Administrator - PowerShell" +"HasLUAShield"="" +"Icon"="powershell.exe" + +[HKEY_CLASSES_ROOT\Directory\Background\Shell\WindowsTerminalAsAdmin\shell\03PS\command] +@="powershell.exe -WindowStyle Hidden \"Set-Location -literalPath '%V';Start-Process -Verb RunAs wt.exe -ArgumentList @('-p','\"\"\"Windows PowerShell\"\"\"','-d','.')\"" + +;005. Removal of Components in Registry + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\HomeFolderDesktop\NameSpace\DelegateFolders\{3134ef9c-6b18-4996-ad04-ed5912e00eb5}] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\HomeFolderDesktop\NameSpace\DelegateFolders\{3134ef9c-6b18-4996-ad04-ed5912e00eb5}] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Play] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Play] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Play] + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\Windows.IsoFile\shell\burn] + +[-HKEY_CLASSES_ROOT\MediaCenter.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.DVR-MSFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3G2\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3GP\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ADTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AIFF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AU\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AVI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.FLAC\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M2TS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.m3u\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M4A\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MIDI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MK3D\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MOV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP3\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP4\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MPEG\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.TTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WPL\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WVX\shell\Enqueue] + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.bmp\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpeg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpe\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.jpg\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.png\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.gif\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.tif\Shell\3D Edit] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SystemFileAssociations\.tiff\Shell\3D Edit] + +[-HKEY_CLASSES_ROOT\Directory\Background\shell\WSL] + +[-HKEY_CLASSES_ROOT\Directory\shell\WSL] + +[-HKEY_CLASSES_ROOT\Drive\shell\WSL] + +[-HKEY_CLASSES_ROOT\MediaCenter.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\Stack.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Audio\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\Directory.Image\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.DVR-MSFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP.WTVFile\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3G2\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.3GP\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ADTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AIFF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASF\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.ASX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AU\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.AVI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.FLAC\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M2TS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.m3u\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.M4A\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MIDI\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MK3D\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MKV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MOV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP3\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MP4\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.MPEG\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.TTS\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WAX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMA\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WMV\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WPL\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\WMP11.AssocFile.WVX\shell\Enqueue] + +[-HKEY_CLASSES_ROOT\*\shell\UpdateEncryptionSettingsWork] + +[-HKEY_CLASSES_ROOT\Directory\shell\UpdateEncryptionSettings] + +[HKEY_CLASSES_ROOT\IE.AssocFile.URL\ShellEx\ContextMenuHandlers\{09799AFB-AD67-11d1-ABCD-00C04FC30936}] + +[-HKEY_CLASSES_ROOT\Drive\shell\Optimize using PerfectDisk] + +[-HKEY_CLASSES_ROOT\SystemFileAssociations\image\shell\print] + +[-HKEY_CLASSES_ROOT\batfile\shell\print] + +[-HKEY_CLASSES_ROOT\cmdfile\shell\print] + +[-HKEY_CLASSES_ROOT\docxfile\shell\print] + +[-HKEY_CLASSES_ROOT\fonfile\shell\print] + +[-HKEY_CLASSES_ROOT\htmlfile\shell\print] + +[-HKEY_CLASSES_ROOT\inffile\shell\print] + +[-HKEY_CLASSES_ROOT\inifile\shell\print] + +[-HKEY_CLASSES_ROOT\JSEFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\otffile\shell\print] + +[-HKEY_CLASSES_ROOT\pfmfile\shell\print] + +[-HKEY_CLASSES_ROOT\regfile\shell\print] + +[-HKEY_CLASSES_ROOT\rtffile\shell\print] + +[-HKEY_CLASSES_ROOT\ttcfile\shell\print] + +[-HKEY_CLASSES_ROOT\ttffile\shell\print] + +[-HKEY_CLASSES_ROOT\txtfile\shell\print] + +[-HKEY_CLASSES_ROOT\VBEFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\VBSFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\WSFFile\Shell\Print] + +[-HKEY_CLASSES_ROOT\Drive\shell\unlock-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\manage-bde] + + + +[HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\SendTo] +@="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\*\shell\UpdateEncryptionSettingsWork] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\Directory\shell\UpdateEncryptionSettings] +"ProgrammaticAccessOnly"="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Blocked] +"{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}"="" + +[HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellEdit] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\AppX43hnxtbyyps62jhe9sqpdzxn1790zetc\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\AppXk0g4vb8gvt7b93tg50ybcy892pge6jmt\Shell\ShellCreateVideo] + +[-HKEY_CLASSES_ROOT\Folder\ShellEx\ContextMenuHandlers\Library Location] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Drive\shell\change-passphrase] + +[-HKEY_CLASSES_ROOT\Drive\shell\change-pin] +"ProgrammaticAccessOnly"="" + +[-HKEY_CLASSES_ROOT\Drive\shell\encrypt-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\encrypt-bde-elev] + +[-HKEY_CLASSES_ROOT\Drive\shell\manage-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\resume-bde] + +[-HKEY_CLASSES_ROOT\Drive\shell\resume-bde-elev] + +[-HKEY_CLASSES_ROOT\Drive\shell\unlock-bde] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ModernSharing] + +[-HKEY_CLASSES_ROOT\Directory\Background\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\CopyHookHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Directory\shellex\PropertySheetHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\LibraryFolder\background\shellex\ContextMenuHandlers\Sharing] + +[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\CLSID\{09A47860-11B0-4DA5-AFA5-26D86198A780}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\EPP] + +[-HKEY_CLASSES_ROOT\DesktopBackground\Shell\ControlledFolderAccess] + +[-HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Drive\shellex\PropertySheetHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\CLSID\{450D8FBA-AD25-11D0-98A8-0800361B1103}\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[-HKEY_CLASSES_ROOT\Drive\shellex\ContextMenuHandlers\{596AB062-B4D2-4215-9F74-E9109B0A8153}] + +[HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications] +"Windows Photo Viewer"="-" + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Photo Viewer\Capabilities] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Bitmap] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.JFIF] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Jpeg] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Png] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.FileAssoc.Wdp] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\photoviewer.dll] +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DiagnosticLogCSP] + + +;006. Add Files for NEW Menu + + +[HKEY_CLASSES_ROOT\.cpp\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.c\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.py\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.js\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.code\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.aup\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.php\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.cmd\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.ini\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.ini\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.reg\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.txt\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.bat\ShellNew] +"NullFile"="" +"ItemName"=hex(2):40,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,\ + 6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,\ + 00,61,00,63,00,70,00,70,00,61,00,67,00,65,00,2e,00,64,00,6c,00,6c,00,2c,00,\ + 2d,00,36,00,30,00,30,00,32,00,00,00 + +[HKEY_CLASSES_ROOT\.html\ShellNew] +"NullFile"="" + +[HKEY_CLASSES_ROOT\.vbs\ShellNew] +"NullFile"="" +"ItemName"=hex(2):40,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\ + 73,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,77,00,73,\ + 00,68,00,65,00,78,00,74,00,2e,00,64,00,6c,00,6c,00,2c,00,2d,00,34,00,38,00,\ + 30,00,32,00,00,00 + + +; 007. App Priority + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acrobat.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acrobat.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acrotray.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\acrotray.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Among Us.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Among Us.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\audiodg.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\audiodg.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BananaBugs.exe] +"MaxLoaderThreads"=dword:00000002 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BananaBugs.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bitwarden.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bitwarden.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BlueMail.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\BlueMail.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bookworm.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Bookworm.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\candycrushsaga.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\candycrushsaga.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe] +"MaxLoaderThreads"=dword:00000004 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\chrome.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Chuzzle.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Chuzzle.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CIU.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\CIU.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cmd.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\converter.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\converter.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csgo.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csgo.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrss.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrss.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ctfmon.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cyberpunk2077.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Cyberpunk2077.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discord.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Discord.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ditto.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ditto.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DoomEternalx64vk.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DoomEternalx64vk.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DragonCity.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DragonCity.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwm.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dwm.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EABackgroundService.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EABackgroundService.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EarTrumpet.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\EarTrumpet.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eurotrucks2.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\eurotrucks2.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe] +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ext2Srv.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FarCry6.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\firefox.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\fontdrvhost.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FortniteClient-Win64-Shipping.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FortniteClient-Win64-Shipping.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon3.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon3.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon4.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon4.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon5.exe] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ForzaHorizon5.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\game] +"MaxLoaderThreads"=dword:00000008 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\game\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GameOverlayUI.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GameOverlayUI.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GeometryDash.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GeometryDash.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyCtrl.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyCtrl.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyHelp32.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupyHelp64.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySrv.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc32.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc32.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc64.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GroupySvc64.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-iii.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-iii.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-lc.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-lc.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-sa.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-sa.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-vc.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\gta-vc.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GTAV.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\GTAV.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IDMan.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\IDMan.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iScrRec.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iScrRec.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lghub_updater.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lghub_updater.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightroom.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightroom.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightshot.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Lightshot.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ludo King.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Ludo King.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MegaRun-WinStore.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MegaRun-WinStore.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\metin2client.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\metin2client.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly_Plus.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Monopoly_Plus.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mpc-hc64.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe] +"MaxLoaderThreads"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msedge.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Muck.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Muck.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysummercar.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mysummercar.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Notepad++.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Notepad++.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\notepad.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\NVDisplay.Container.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfficeClickToRun.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OfficeClickToRun.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe] +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\opera.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\operagx.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\operagx.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photoshop.exe] +"MitigationOptions"=hex:00,00,00,00,00,02,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\photoshop.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PizzaFrenzy.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PizzaFrenzy.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlantsVsZombies.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlantsVsZombies.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlayGtaV.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\PlayGtaV.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\powerpnt.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rambox.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Rambox.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RAVCpl64.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re6.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re6.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re7.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re7.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re8.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\re8.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Resolve.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Resolve.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RuntimeBroker.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\RuntimeBroker.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\ShellExperienceHost.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SnowRunner.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SnowRunner.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SonicMania.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SonicMania.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\spoolsv.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Spotify.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Spotify.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SpotifyStartupTask.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\SpotifyStartupTask.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11Srv.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11Srv.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11_64.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Start11_64.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Steam.exe] +"MaxLoaderThreads"=dword:00000001 +"mpc-hc64.exe"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Steam.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steamwebhelper.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\steamwebhelper.exe\PerfOptions] +"CpuPriorityClass"=dword:00000001 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe] +"MaxLoaderThreads"=dword:00000001 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\svchost.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Teams.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Teams.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Terraria.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Terraria.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2_BE.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\TheCrew2_BE.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Update.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Update.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vgc.exe] +"MitigationOptions"=hex:00,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00 +"MitigationAuditOptions"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VideoEditorPlus.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\VideoEditorPlus.exe\PerfOptions] +"CpuPriorityClass"=dword:00000004 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WheresMyWater2.WindowsStore.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WheresMyWater2.WindowsStore.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinBM.exe] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WinBM.exe\PerfOptions] +"CpuPriorityClass"=dword:00000003 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 +"EAFModules"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winword.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WmiPrvSE.exe] +"MaxLoaderThreads"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\WmiPrvSE.exe\PerfOptions] +"CpuPriorityClass"=dword:00000005 +"IoPriority"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zoom.exe] +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22 +"MitigationAuditOptions"=hex:22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,22,\ + 22,22,22,22,22,22,22,22 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Zoom.exe\PerfOptions] +"CpuPriorityClass"=dword:00000006 +"IoPriority"=dword:00000003 + + +; 008. Connections + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER] +"explorer.exe"=dword:00000002 +"sllauncher.exe"=dword:00000006 +"winword.exe"=dword:0000000d +"mspub.exe"=dword:0000000d +"powerpnt.exe"=dword:0000000d +"outlook.exe"=dword:0000000d +"onenote.exe"=dword:0000000d +"excel.exe"=dword:0000000d +"msaccess.exe"=dword:0000000d +"csgo.exe"=dword:0000000d +"jaraw.exe"=dword:0000000d +"chrome.exe"=dword:0000000d +"msedge.exe"=dword:0000000d +"edge.exe"=dword:0000000d +"opera.exe"=dword:0000000d +"firefox.exe"=dword:0000000d + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER] +"explorer.exe"=dword:00000002 +"sllauncher.exe"=dword:00000006 +"winword.exe"=dword:0000000d +"mspub.exe"=dword:0000000d +"powerpnt.exe"=dword:0000000d +"outlook.exe"=dword:0000000d +"onenote.exe"=dword:0000000d +"excel.exe"=dword:0000000d +"msaccess.exe"=dword:0000000d +"csgo.exe"=dword:0000000d +"jaraw.exe"=dword:0000000d +"chrome.exe"=dword:0000000d +"msedge.exe"=dword:0000000d +"edge.exe"=dword:0000000d +"opera.exe"=dword:0000000d +"firefox.exe"=dword:0000000d + + +;009. +20GB Disk Space + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power] +"HibernateEnabled"=dword:00000000 +"HiberbootEnabled"=dword:00000000 +"ExitLatency "=dword:00000001 +"DisableVsyncLatencyUpdate"=dword:00000001 +"DisableSensorWatchdog"=dword:00000001 +"ExitLatencyCheckEnabled"=dword:00000001 +"Latency"=dword:00000001 +"LatencyToleranceDefault"=dword:00000000 +"LatencyToleranceFSVP"=dword:00000000 +"LatencyToleranceIdleResiliency"=dword:00000000 +"LatencyTolerancePerfOverride"=dword:00000000 +"LatencyToleranceScreenOffIR"=dword:00000000 +"LatencyToleranceVSyncEnabled"=dword:00000000 +"RtlCapabilityCheckLatency "=dword:00000001 +"MfBufferingThreshold"=dword:00000000 +"CoalescingTimerInterval"=dword:00000000 +"CsEnabled"=dword:00000000 +"EnergyEstimationEnabled"=dword:00000000 +"PerfCalculateActualUtilization"=dword:00000000 +"SleepReliabilityDetailedDiagnostics"=dword:00000000 +"EventProcessorEnabled"=dword:00000000 +"QosManagesIdleProcessors"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager\Memory Management] +"PagingFiles"=hex(7):00,00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager] +"ShippedWithReserves"=dword:00000000 +"PassedPolicy"=dword:00000000 + + +;010. Realtek HDA Tweaks + +[HKEY_CURRENT_USER\Software\Realtek\Audio\RtkNGUI64\General] +"JDPopup"=dword:00000001 +"CplExecuted_104386C7_104386C7"=dword:00000001 +"LastFixDefaultTime"=hex:e2,07,0c,00,02,00,04,00,00,00,20,00,33,00,fd,00 +"RenderDefaultFixed"=dword:00000001 +"CaptureDefaultFixed"=dword:00000001 +"Language"=dword:00000000 +"CplExecuted_103C830C_103C830C"=dword:00000001 +"AutoSelectChannelByJackConf"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Realtek\Audio\RtkNGUI64\PowerMgnt] +"Enabled"=dword:00000001 +"DelayTime"=dword:00000003 +"OnlyBattery"=dword:00000000 +"PowerState"=dword:00000000 + +;011. Disable System Restore + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore] +"DisableSR"=dword:00000001 + +;012. Add Open With.. for URL Files + + +[HKEY_CLASSES_ROOT\IE.AssocFile.URL\ShellEx\ContextMenuHandlers\{09799AFB-AD67-11d1-ABCD-00C04FC30936}] + +;013. Prefetch Disable + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters] +"EnablePrefetcher"=dword:00000000 +"EnableSuperfetch"=dword:00000000 +"BootId"=- +"BaseTime"=- + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main] +"AllowPrelaunch"=dword:00000000 + +;014. Disable Keyboard shortcuts with Accesibility + + +[HKEY_CURRENT_USER\Control Panel\Accessibility\HighContrast] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\Keyboard Response] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\MouseKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\SoundSentry] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\StickyKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\TimeOut] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\ToggleKeys] +"Flags"="0" + +[HKEY_CURRENT_USER\Control Panel\Accessibility\SlateLaunch] +"ATapp"=- + +[HKEY_CURRENT_USER\Control Panel\Accessibility\TimeOut] +"Flags"="0" + + +;015. Disable Animation and Transparency + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\VisualEffects] +"VisualFxSetting"=dword:00000003 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"DITest"=dword:00000000 + +[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\DWM] +"CompositionPolicy"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\DWM] +"CompositionPolicy"=dword:00000000 + + +[HKEY_USERS\.DEFAULT\Control Panel\Desktop] +"ForegroundLockTimeout"=dword:00000000 +"MenuShowDelay"="0" +"MouseWheelRouting"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] +"DesktopHeapLogging"=dword:00000000 +"DwmInputUsesIoCompletionPort"=dword:00000000 +"EnableDwmInputProcessing"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Dwm] +"AnimationAttributionEnabled"=dword:00000000 +"AnimationAttributionHashingEnabled"=dword:00000000 +"OneCoreNoBootDWM"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Dwm] +"ForceEffectMode"=- + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DWM] +"DWMWA_TRANSITIONS_FORCEDISABLED"=dword:00000001 +"DisallowFlip3d"=dword:00000001 +"DisallowColorizationColorChanges"=dword:00000001 +"DisallowAnimations"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\DWM] +"Composition"=dword:00000000 +"EnableAeroPeek"=dword:00000000 +"AlwaysHibernateThumbnails"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\International] +"s1159"="AM" +"s2359"="PM" +"sCurrency"="$" +"sDate"="." +"sDecimal"="," +"sGrouping"="3;0" +"sList"="." +"sLongDate"="dddd, dd.MM.yyyy" +"sMonDecimalSep"="." +"sMonGrouping"="3;0" +"sMonThousandSep"="," +"sNativeDigits"="0123456789" +"sNegativeSign"="-" +"sPositiveSign"="" +"sShortDate"="dd.MM.yyyy" +"sThousand"="." +"sTime"=":" +"sTimeFormat"="HH:mm:ss" +"sShortTime"="HH:mm" +"iFirstDayOfWeek"="0" +"iLZero"="1" +"iMeasure"="0" +"iNegCurr"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MultiTaskingView\AllUpView] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Desktop] +"DragFullWindows"="1" +"FontSmoothing"="2" +"FontSmoothingType"=dword:00000002 +"MenuShowDelay"="0" +"UserPreferencesMask"=hex:90,12,01,80,10 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes\Personalize] +"EnableTransparency"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ThemeManager] +"ThemeActive"="0" + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MultitaskingView\AllUpView] +"AllUpView"=dword:00000000 +"Remove TaskView"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer] +"AltTabSettings"=dword:00000001 +"ExplorerStartupTraceRecorded"=dword:00000000 +"UserSignedIn"=dword:00000001 +"TelemetrySalt"=dword:00000000 +"SIDUpdatedOnLibraries"=dword:00000001 +"LocalKnownFoldersMigrated"=dword:00000001 +"SlowContextMenuEntries"=- +"FirstRunTelemetryComplete"=- +"PostAppInstallTasksCompleted"=dword:00000001 +"NoPreviousVersionsPage"=dword:00000001 +"MultipleInvokePromptMinimum"=dword:00001388 +"AltTabSettings"=dword:00000001 +"link"=hex:00,00,00,00 +"ExcludedFromStableAnaheimDownloadPromotionSL"=dword:00000001 +"IrisClientRefresh"=dword:00000000 +"Reason Setting"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\People] +"PeopleBand"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics] +"PaddedBorderWidth"="0" + +[HKEY_CURRENT_USER\Control Panel\Desktop\WindowMetrics] +"MinAnimate"="0" +"MaxAnimate"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE] +"DisableExternalDMAUnderLock"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Reliability] +"TimeStampInterval"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"DisableThumbnails"=- + +[HKEY_CLASSES_ROOT\*] +"DefaultDropEffect"=dword:00000001 + +[HKEY_CLASSES_ROOT\AllFilesystemObjects] +"DefaultDropEffect"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer] +"ThumbnailQuality"=dword:00000032 +"SmartScreenEnabled"="Off" +"NoPreviousVersionsPage"=dword:00000001 +"HubMode"=dword:00000001 +"Max Cached Icons"="4096" +"EnableAutoTray"=dword:00000001 +"DesktopProcess"=dword:00000001 +"ShowRecent"=dword:00000000 +"ShowFrequent"=dword:00000000 + +;016. DirectX API Optimization + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000001 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Direct3D] +"DisableVidMemVBs"=dword:00000000 +"MMX Fast Path"=dword:00000001 +"FlipNoVsync"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Direct3D\Drivers] +"SoftwareOnly"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\DirectDraw] +"EmulationOnly"=dword:00000000 + + +;017. Internet Security Zone Setiings + + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones] +"SelfHealCount"=dword:00000001 +"SecuritySafe"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones] +"SelfHealCount"=dword:00000001 +"SecuritySafe"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3] +"2001"=dword:00000000 +"2004"=dword:00000000 +"CurrentLevel"=dword:00011500 +"Flags"=dword:00000001 +"1200"=dword:00000000 +"1400"=dword:00000000 +"1001"=dword:00000001 +"1004"=dword:00000003 +"1201"=dword:00000003 +"1206"=dword:00000003 +"1207"=dword:00000003 +"1208"=dword:00000003 +"1209"=dword:00000003 +"120A"=dword:00000003 +"120C"=dword:00000003 +"1402"=dword:00000000 +"1405"=dword:00000000 +"1406"=dword:00000003 +"1407"=dword:00000001 +"1408"=dword:00000003 +"1409"=dword:00000000 +"140A"=dword:00000000 +"140C"=dword:00000003 +"1601"=dword:00000000 +"1604"=dword:00000000 +"1605"=dword:00000000 +"1606"=dword:00000000 +"1607"=dword:00000003 +"1608"=dword:00000000 +"1609"=dword:00000001 +"160A"=dword:00000003 +"160B"=dword:00000000 +"1802"=dword:00000000 +"1803"=dword:00000000 +"1804"=dword:00000001 +"1806"=dword:00000000 +"1809"=dword:00000000 +"1812"=dword:00000001 +"1A00"=dword:00020000 +"1A02"=dword:00000000 +"1A03"=dword:00000000 +"1A04"=dword:00000003 +"1A05"=dword:00000001 +"1A06"=dword:00000000 +"1C00"=dword:00010000 +"2000"=dword:00000000 +"2005"=dword:00000003 +"2007"=dword:00010000 +"2100"=dword:00000000 +"2101"=dword:00000000 +"2102"=dword:00000003 +"2103"=dword:00000003 +"2104"=dword:00000003 +"2105"=dword:00000003 +"2106"=dword:00000000 +"2107"=dword:00000003 +"2200"=dword:00000003 +"2201"=dword:00000003 +"2300"=dword:00000001 +"2301"=dword:00000000 +"2302"=dword:00000003 +"2400"=dword:00000003 +"2401"=dword:00000000 +"2402"=dword:00000003 +"2600"=dword:00000000 +"2700"=dword:00000000 +"2701"=dword:00000000 +"2702"=dword:00000000 +"2703"=dword:00000003 +"2704"=dword:00000000 +"2708"=dword:00000003 +"2709"=dword:00000003 +"270B"=dword:00000003 +"270C"=dword:00000000 +"270D"=dword:00000003 +"2500"=dword:00000003 +"2707"=dword:00000000 +"120B"=dword:00000003 +"1A10"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings] +"CertificateRevocation"=dword:00000001 +"DisableCachingOfSSLPages"=dword:00000000 +"PrivacyAdvanced"=dword:00000001 +"SecureProtocols"=dword:00002aa0 +"EnableNegotiate"=dword:00000001 +"MigrateProxy"=dword:00000001 +"ProxyEnable"=dword:00000000 +"WarnonZoneCrossing"=dword:00000000 +"EnableHttp1_1"=dword:00000001 +"ProxyHttp1.1"=dword:00000001 +"EnableHTTP2"=dword:00000001 +"EnablePunycode"=dword:00000001 +"UrlEncoding"=dword:00000000 +"DisableIDNPrompt"=dword:00000000 +"ShowPunycode"=dword:00000000 +"WarnonBadCertRecving"=dword:00000001 +"WarnOnPostRedirect"=dword:00000001 +"SyncMode5"=dword:00000003 + + +[HKEY_USERS\.DEFAULT\Microsoft\Windows\CurrentVersion\Internet Settings] +"CertificateRevocation"=dword:00000001 +"DisableCachingOfSSLPages"=dword:00000000 +"PrivacyAdvanced"=dword:00000001 +"SecureProtocols"=dword:00002aa0 +"EnableNegotiate"=dword:00000001 +"MigrateProxy"=dword:00000001 +"ProxyEnable"=dword:00000000 +"WarnonZoneCrossing"=dword:00000000 +"EnableHttp1_1"=dword:00000001 +"ProxyHttp1.1"=dword:00000001 +"EnableHTTP2"=dword:00000001 +"EnablePunycode"=dword:00000001 +"UrlEncoding"=dword:00000000 +"DisableIDNPrompt"=dword:00000000 +"ShowPunycode"=dword:00000000 +"WarnonBadCertRecving"=dword:00000001 +"WarnOnPostRedirect"=dword:00000001 +"SyncMode5"=dword:00000003 + + +;018. Microsoft Windows's Keylogger Disable + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\AppModel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Cellcore] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Circular Kernel Context Logger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\CloudExperienceHostOobe] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DataMarket] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\DiagLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\HolographicDevice] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\iclsClient] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\iclsProxy] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\LwtNetLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Mellanox-Kernel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Microsoft-Windows-AssignedAccess-Trace] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Microsoft-Windows-Setup] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\NBSMBLOGGER] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\PEAuthLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\RdrLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\ReadyBoot] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SetupPlatform] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SetupPlatformTel] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SocketHeciServer] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SpoolerLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\SQMLogger] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TCPIPLOGGER] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TileStore] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\Tpm] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\TPMProvisioningService] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\UBPM] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WdiContextLog] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WFP-IPsec Trace] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiDriverIHVSession] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiDriverIHVSessionRepro] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WiFiSession] +"Start"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\WinPhoneCritical] +"Start"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\PwdlessAggregator] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\PwdlessAggregator\{fb3cd94d-95ef-5a73-b35c-6c78451095ef}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{025d2741-697b-5e0e-7e77-9a36140251f7}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{2504bc27-0e8b-5fed-7a9f-d86972086285}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{46b13027-2dfd-46e1-832d-e41e2810e6e5}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{59dd67cc-7ce1-52f8-cf74-fe8a257a2b6b}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{a8b932c2-51ec-5c22-63fc-0115fd79b9e0}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{cee50f59-e321-4691-9bb7-9b75494f6aab}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateHeartbeatScan\{d48679eb-8aa3-4138-be24-f1648C874e49}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{025d2741-697b-5e0e-7e77-9a36140251f7}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{59dd67cc-7ce1-52f8-cf74-fe8a257a2b6b}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{a8b932c2-51ec-5c22-63fc-0115fd79b9e0}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdatePolicyScenarioReliabilityAggregator\{e77a560c-3696-4ac0-911c-545ceca6be3c}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{18D6CBEB-1E21-500A-27E2-8BA2BEAC7C00}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{3D6120A6-0986-51C4-213A-E2975903051D}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{59DD67CC-7CE1-52F8-CF74-FE8A257A2B6B}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{8BE48F34-1F58-4180-8C12-DBE6E6E71A81}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{AC8D9176-9E0-5047-9B60-1AABC45281B8}] +"Enabled"=dword:00000000 +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{B39B8CEA-EAAA-5A74-5794-4948E222C663}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{BBC9A2C9-EEED-58D4-9483-6C87118F9EC6}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{CEE50F59-E321-4691-9BB7-9B75494F6AAB}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UpdateReboot\{D059A021-6947-44FB-976A-B18C9B73D1D8}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{1377561d-9312-452c-ad13-c4a1c9c906e0}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{1a1dfad0-6d37-5521-1d72-1f87dd20423c}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{3E0D88DE-AE5C-438A-BB1C-C2E627F8AECB}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{76AD4308-DF7C-5F43-E668-FCEA4FA1179D}] +"Enabled"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{b6acef34-fab6-5909-6b6b-b1c2cc84057f}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{D1094A14-063E-7A21-A301-F2FE3BA23F62}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\ControlGroups\UusFailover\{EC4BA041-1DFE-5F76-EF6D-0251DA19D178}] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Host] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Host\0] +"Status"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\PwdlessAggregator] +"HbStart"=dword:00000000 +"HbStop"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdateHeartbeatScan] + +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdatePolicyScenarioReliabilityAggregator] +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UpdateReboot] +"HbStart"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Aggregation\Instrumentation\UusFailover] +"HbStart"=dword:00000000 + + +;019. Disable Telemetry + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\AppV\CEIP] +"CEIPEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\FirewallAPI] +"Active"=dword:00000000 +"ControlFlags"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\Microsoft\PlugPlay\SETUPAPI] +"Active"=dword:00000000 +"ControlFlags"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Tracing\SCM\Regular] +"TracingDisabled"=dword:00000001 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\AsimovUploader] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventMonitors] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling] +"PowerThrottlingOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\EnergyEstimation\TaggedEnergy] +"DisableTaggedEnergyLogging"=dword:00000001 +"TelemetryMaxApplication"=dword:00000000 +"TelemetryMaxTagPerApplication"=dword:00000000 + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection] +"AllowTelemetry"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CloudContent] +"DisableWindowsConsumerFeatures"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Narrator\NoRoam] +"WinEnterLaunchEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\StorPort] +"TelemetryPerformanceEnabled"=dword:00000000 +"TelemetryErrorDataEnabled"=dword:00000000 +"Tele­metry­DeviceHealthEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub\hubg] +"DisableOnSoftRemove"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction] +"Enable"="N" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl] +"AutoReboot"=dword:00000000 +"CrashDumpEnabled"=dword:00000000 +"DumpFile"=hex(2):70,00,75,00,6c,00,61,00,00,00 +"DumpLogLevel"=dword:00000000 +"EnableLogFile"=dword:00000000 +"LogEvent"=dword:00000000 +"MinidumpDir"=hex(2):70,00,75,00,6c,00,61,00,00,00 +"MinidumpsCount"=dword:00000000 +"Overwrite"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard] +"ExitOnMSICW"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DataCollection] +"DisableDiagnosticDataViewer"=dword:00000001 +"DisableOneSettingsDownloads"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 +"DisableTelemetryOptInChangeNotification"=dword:00000000 +"DisableTelemetryOptInSettingsUx"=dword:00000000 +"AllowCommercialDataPipeline"=dword:00000000 +"AllowDesktopAnalyticsProcessing"=dword:00000000 +"AllowDeviceNameInTelemetry"=dword:00000000 +"AllowTelemetry"=dword:00000000 +"AllowUpdateComplianceProcessing"=dword:00000000 +"AllowWUfBCloudProcessing"=dword:00000000 +"DisableDeviceDelete"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000000 +"LimitDumpCollection"=dword:00000001 +"LimitEnhancedDiagnosticDataWindowsAnalytics"=dword:00000001 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\DataCollection] +"AllowTelemetry"=dword:00000000 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 +"DisableDiagnosticDataViewer"=dword:00000001 +"DisableOneSettingsDownloads"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 +"DisableTelemetryOptInChangeNotification"=dword:00000000 +"DisableTelemetryOptInSettingsUx"=dword:00000000 +"AllowCommercialDataPipeline"=dword:00000000 +"AllowDesktopAnalyticsProcessing"=dword:00000000 +"AllowDeviceNameInTelemetry"=dword:00000000 +"AllowUpdateComplianceProcessing"=dword:00000000 +"AllowWUfBCloudProcessing"=dword:00000000 +"DisableDeviceDelete"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000000 +"LimitDumpCollection"=dword:00000001 +"LimitEnhancedDiagnosticDataWindowsAnalytics"=dword:00000001 +"MaxTelemetryAllowed"=dword:00000000 +"EnableExtendedBooksTelemetry"=dword:00000000 +"MicrosoftEdgeDataOptIn"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] +"TargetGroup"="Workstations" +"TargetGroupEnabled"=dword:00000000 +"WUServer"="http://x.x.x.x:8530" +"WUStatusServer"="http://x.x.x.x:8530" +"DeferUpgrade"=dword:00000001 +"DisableOSUpgrade"=dword:00000001 +"SetActiveHoursMaxRange"=dword:00000001 +"ActiveHoursMaxRange"=dword:00000012 +"AllowAutoWindowsUpdateDownloadOverMeteredNetwork"=dword:00000001 +"NoAutoRebootWithLoggedOnUsers"=dword:00000001 +"NoAUShutdownOption"=dword:00000001 +"NoAUAsDefaultShutdownOption"=dword:00000001 +"AlwaysAutoRebootAtScheduledTime"=dword:00000001 +"AlwaysAutoRebootAtScheduledTimeMinutes"=dword:0000000f +"EnableFeaturedSoftware"=dword:00000000 +"DisableWindowsUpdateAccess"=dword:00000001 +"SetAutoRestartNotificationDisable"=dword:00000001 +"SetActiveHours"=dword:00000001 +"ActiveHoursStart"=dword:00000007 +"ActiveHoursEnd"=dword:00000016 +"SetPolicyDrivenUpdateSourceForFeatureUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForQualityUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForDriverUpdates"=dword:00000000 +"SetPolicyDrivenUpdateSourceForOtherUpdates"=dword:00000000 +"DoNotConnectToWindowsUpdateInternetLocations"=dword:00000001 +"DisableDualScan"=dword:00000001 +"SetUpdateNotificationLevel"=dword:00000001 +"UpdateNotificationLevel"=dword:00000001 +"AcceptTrustedPublisherCerts"=dword:00000001 +"ElevateNonAdmins"=dword:00000001 +"ManagePreviewBuildsPolicyValue"=dword:00000002 +"BranchReadinessLevel"=dword:00000002 +"TargetReleaseVersion"=dword:00000000 +"DisableWUfBSafeguards"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\TraceManager] +"MiniTraceSlotContentPermitted"=dword:00000000 +"MiniTraceSlotEnabled"=dword:00000000 +"alternativeTraceScenarioId"="" +"alternativeTraceStartTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceStopTime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceHasStopTime"=dword:00000000 +"alternativeTracePriority"=dword:00000000 +"alternativeTraceIsExclusive"=dword:00000000 +"alternativeTraceIsAutoLogger"=dword:00000000 +"alternativeTraceProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"alternativeTraceIsThrottled"=dword:00000000 +"alternativeTraceRequiredBufferSpace"=dword:00000000 +"alternativeTraceThrottleState"=dword:00000000 +"aotScenarioId"="" +"aotStartTime"=hex(b):00,00,00,00,00,00,00,00 +"aotSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"aotStopTime"=hex(b):00,00,00,00,00,00,00,00 +"aotMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"aotHasStopTime"=dword:00000000 +"aotPriority"=dword:00000000 +"aotIsExclusive"=dword:00000000 +"aotIsAutoLogger"=dword:00000000 +"aotProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"aotIsThrottled"=dword:00000000 +"aotRequiredBufferSpace"=dword:00000000 +"aotThrottleState"=dword:00000000 +"miniTraceScenarioId"="" +"miniTraceStartTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceStopTime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceHasStopTime"=dword:00000000 +"miniTracePriority"=dword:00000000 +"miniTraceIsExclusive"=dword:00000000 +"miniTraceIsAutoLogger"=dword:00000000 +"miniTraceProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"miniTraceIsThrottled"=dword:00000000 +"miniTraceRequiredBufferSpace"=dword:00000000 +"miniTraceThrottleState"=dword:00000000 +"diagScenarioId"="" +"diagStartTime"=hex(b):00,00,00,00,00,00,00,00 +"diagSessionStartTime"=hex(b):00,00,00,00,00,00,00,00 +"diagStopTime"=hex(b):00,00,00,00,00,00,00,00 +"diagMinTraceDurationFiletime"=hex(b):00,00,00,00,00,00,00,00 +"diagHasStopTime"=dword:00000000 +"diagPriority"=dword:00000000 +"diagIsExclusive"=dword:00000000 +"diagIsAutoLogger"=- +"diagProfileHash"=hex(b):00,00,00,00,00,00,00,00 +"diagIsThrottled"=dword:00000000 +"diagRequiredBufferSpace"=dword:00000000 +"diagThrottleState"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack] +"DiagTrackStatus"=dword:00000002 +"DiagTrackAuthorization"=dword:00000375 +"ConnectivityNoNetworkTime"=dword:00000000 +"ConnectivityRestrictedNetworkTime"=dword:00000000 +"UploadPermissionReceived"=dword:00000000 +"ShowedToastAtLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Dnscache\Parameters] +"DisableParallelAandAAAA"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DNSClient] +"DisableSmartNameResolution"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Wacom\Analytics] +"Analytics_On"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\ProviderControl] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\SettingsRequests\] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Tenants] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\TriggerListener] +"MatchEngineBufferSize"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventTranscriptKey] +"EnableEventTranscript"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\OmittedIds] +"w:B04E2543-63EB-D3C6-4722-FBFE64FA31C0"=dword:00000000 +"w:5B08FD5C-0859-F5E6-7503-0D19552D498E"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\Features] +"EventTagDropUserIds"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\InputPersonalization] +"RestrictImplicitInkCollection"=dword:00000001 +"RestrictImplicitTextCollection"=dword:00000001 +"Installed"=dword:00000000 +"Shutdown"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SpeechGestures] +"RDCPolicyCollectionLevel"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy] +"HasAccepted"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\PPP] +"RestartTimer"=dword:00000000 +"ForceEncryptedData"=dword:00000001 +"ForceEncryptedPassword"=dword:00000002 +"SecureVPN"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LLTD] +"EnableLLTDIO"=dword:00000000 +"AllowLLTDIOOnDomain"=dword:00000000 +"AllowLLTDIOOnPublicNet"=dword:00000000 +"ProhibitLLTDIOOnPrivateNet"=dword:00000001 +"EnableRspndr"=dword:00000000 +"AllowRspndrOnDomain"=dword:00000000 +"AllowRspndrOnPublicNet"=dword:00000000 +"ProhibitRspndrOnPrivateNet"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager] +"FeatureManagementEnabled"=dword:00000000 +"SlideshowEnabled"=dword:00000000 +"OemPreInstalledAppsEnabled"=dword:00000000 +"PreInstalledAppsEnabled"=dword:00000000 +"RotatingLockScreenEnabled"=dword:00000000 +"RotatingLockScreenOverlayEnabled"=dword:00000000 +"SilentInstalledAppsEnabled"=dword:00000000 +"SoftLandingEnabled"=dword:00000000 +"SystemPaneSuggestionsEnabled"=dword:00000000 +"SubscribedContent-338389Enabled"=dword:00000000 +"SubscribedContent-338388Enabled"=dword:00000000 +"PreInstalledAppsEverEnabled"=dword:00000000 +"SubscribedContent-88000326Enabled"=dword:00000000 +"SubscribedContent-338393Enabled"=dword:00000000 +"SubscribedContent-353694Enabled"=dword:00000000 +"SubscribedContent-353696Enabled"=dword:00000000 +"SubscribedContent-353698Enabled"=dword:00000000 +"SubscribedContentEnabled"=dword:00000000 +"RemediationRequired"=dword:00000000 +"ShowSyncProviderNotifications"=dword:00000000 +"SubscribedContent-310093Enabled"=dword:00000000 +"SubscribedContent-314563Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AdvertisingInfo] +"DisabledByGroupPolicy"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\StorageTelemetry] +"DeviceDumpEnabled"=dword:00000000 +"StorageTCCode_0"=dword:00000000 +"StorageTCCode_1"=dword:00000000 +"StorageTCCode_2"=dword:00000000 +"StorageTCCode_3"=dword:00000000 +"StorageTCCode_4"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\CrashControl\LiveKernelReports] +"DeleteLiveMiniDumps"=dword:00000000 + + +;020. Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"NoInstrumentation"=dword:00000001 +"NoRecentDocsMenu"=dword:00000001 +"MemCheckBoxInRunDlg"=dword:00000001 +"NoSMConfigurePrograms"=dword:0000000 +"NoRemoteRecursiveEvents"=dword:00000001 +"NoLowDiskSpaceChecks"=dword:00000001 +"LinkResolveIgnoreLinkInfo"=dword:00000001 +"NoResolveSearch"=dword:00000001 +"NoResolveTrack"=dword:00000001 +"NoInternetOpenWith"=dword:00000001 +"DisableSearchBoxSuggestions"=dword:00000001 +"NoLowDiskSpaceChecks"=dword:00000001 +"ConfirmFileDelete"=dword:00000000 +"HideSCAMeetNow"=dword:00000001 +"NoRecentDocsNetHood"=dword:00000001 +"NoNetConnectDisconnect"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\QuietHours] +"Enable"=dword:00000000 +"AllowCalls"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel] +"AllItemsIconView"=dword:00000002 +"StartupPage"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Serialize] +"StartupDelayInMSec"=dword:00000000 + + + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LocationAndSensors] +"DisableLocation"=dword:00000001 +"DisableLocationScripting"=dword:00000001 +"DisableWindowsLocationProvider"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Siuf\Rules] +"NumberOfSIUFInPeriod"=dword:00000000 +"PeriodInNanoSeconds"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"SeparateProcess"=dword:00000001 +"HideFileExt"=dword:00000000 +"DontPrettyPath"=dword:00000001 +"ShowInfoTip"=dword:00000001 +"MapNetDrvBtn"=dword:00000000 +"WebView"=dword:00000000 +"ShowSuperHidden"=dword:00000001 +"MMTaskbarGlomLevel"=dword:00000000 +"Start_ShowRun"=dword:00000001 +"ExtendedUIHoverTime"=dword:00000001 +"ListviewShadow"=dword:00000000 +"TaskbarAnimations"=dword:00000000 +"ListviewAlphaSelect"=dword:00000000 +"ListviewWatermark"=dword:00000000 +"StartShownOnUpgrade"=dword:00000001 +"TaskbarDa"=dword:00000000 +"LaunchTo"=dword:00000001 +"TaskbarMn"=dword:00000000 +"Start_NotifyNewApps"=dword:00000000 +"ShowSecondsInSystemClock"=dword:00000001 +"ShowSyncProviderNotifications"=dword:00000000 +"NavPaneShowAllFolders"=dword:00000000 +"NoNetCrawling"=dword:00000001 +"TaskbarSi"=dword:00000001 +"JointResize"=dword:00000000 +"SnapAssist"=dword:00000000 +"SnapFill"=dword:00000000 +"LastActiveClick"=dword:00000001 +"TaskbarSizeMove"=dword:00000001 +"ShowStatusBar"=dword:00000001 +"HideSCAMeetNow"=dword:00000001 +"NoRecentDocsNetHood"=dword:00000001 +"IconsOnly"=dword:00000000 +"Start_TrackProgs"=dword:00000000 +"Start_TrackDocs"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shutdown] +"CleanShutdown"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\AuxilliaryPins] +"MailPin"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel] +"AllItemsIconView"=dword:00000002 +"StartupPage"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel] +"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu] +"{20D04FE0-3AEA-1069-A2D8-08002B30309D}"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\pci\Parameters] +"ASPMOptOut"=dword:00000001 + + +;021. AutoPlay + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\ShowPicturesOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\WPD] + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\WPD\ImageSource] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\CameraAlternate] + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\CameraAlternate\ShowPicturesOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlersDefaultSelection\StorageOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\UserChosenExecuteHandlers\StorageOnArrival] +@="MSOpenFolder" + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers] +"DisableAutoplay"=dword:00000000 + + +;022. Internet Optimization + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\ServiceProvider] +"DnsPriority"=dword:00000006 +"LocalPriority"=dword:00000004 +"NetbtPriority"=dword:00000007 +"HostPriority"=dword:00000005 +"HostsPriority"=dword:00000005 +"Class"=dword:00000008 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters] +"EnableWsd"=dword:00000000 +"DisableDynamicDiscovery"=dword:00000001 +"EnablePMTUDiscovery"=dword:00000000 +"EnablePMTUBDetect"=dword:00000000 +"EnableICMPRedirect"=dword:00000001 +"DisableTaskOffload"=dword:00000000 +"TcpMaxDupAcks"=dword:00000002 +"Tcp1323Opts"=dword:00000001 +"TcpTimedWaitDelay"=dword:00000002 +"MaxFreeTcbs"=dword:00010000 +"TCPCongestionControl"=dword:00000001 +"SackOpts"=dword:00000000 +"DefaultTTL"=dword:00000040 +"CongestionAlgorithm"=dword:00000001 +"MultihopSets"=dword:0000000f +"FastCopyReceiveThreshold"=dword:00004000 +"FastSendDatagramThreshold"=dword:00004000 +"DelayedAckFrequency"=dword:00000000 +"DelayedAckTicks"=dword:00000000 +"UseDomainNameDevolution"=dword:00000000 +"IGMPLevel"=dword:00000000 +"GlobalMaxTcpWindowSize"=dword:00256960 +"TcpWindowSize"=dword:00256960 +"MaxConnectionsPer1_0Server"=dword:00000016 +"MaxConnectionsPerServer"=dword:00000016 +"MaxUserPort"=dword:00065534 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\Standard TCP/IP Port\Ports] +"LprAckTimeout"=dword:00000002 +"StatusUpdateEnabled"=dword:00000001 +"StatusUpdateInterval"=dword:0000000a + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\QoS] +"Do not use NLA"=dword:00000001 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Winsock] +"UseDelayedAcceptance"=dword:00000000 +"MaxSockAddrLength"=dword:00000010 +"MinSockAddrLength"=dword:00000010 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Internet Connection Wizard] +"ExitOnMSICW"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetworkConnectivityStatusIndicator] +@="" +"NoActiveProbe"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender] +"DisableRoutinelyTakingAction"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Policies\Microsoft\Windows Defender] +"DisableRoutinelyTakingAction"=dword:00000001 + +[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\QoS] +"Do not use NLA"="1" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSMQ\Parameters] +"TCPNoDelay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces] +"TcpAckFrequency"=dword:00000001 +"TCPNoDelay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TCPIP\v6Transition] +"Teredo_ClientPort"=dword:00000000 +"Teredo_DefaultQualified"="Enabled" +"Teredo_RefreshRate"=dword:0000001e +"Teredo_ServerName"="win10.ipv6.microsoft.com" +"Teredo_State"="Enterprise Client" + +;023. Disable Sound at Startup + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\BootControl] +"BootProgressAnimation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Authentication\LogonUI\Boot] +"DisableStartupSound"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NlaSvc\Parameters\Internet] +"ActiveDnsProbeContent"="208.67.222.222" +"ActiveDnsProbeContentV6"="2620:119:35::35" +"ActiveDnsProbeHost"="resolver1.opendns.com" +"ActiveDnsProbeHostV6"="resolver1.opendns.com" +"ActiveWebProbeContent"="success" +"ActiveWebProbeContentV6"="success" +"ActiveWebProbeHost"="detectportal.firefox.com" +"ActiveWebProbeHostV6"="detectportal.firefox.com" +"ActiveWebProbePath"="success.txt" +"ActiveWebProbePathV6"="success.txt" + +[HKEY_LOCAL_MACHINE\Software\Microsoft\PolicyManager\default\WiFi\AllowAutoConnectToWiFiSenseHotspots] +"value"=dword:00000000 + +;024. Region Part + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\CodePage] +"1250"="c_1251.nls" +"1251"="c_1251.nls" +"1252"="c_1251.nls" +"1253"="c_1251.nls" +"1254"="c_1251.nls" +"1255"="c_1251.nls" + +;025. GPU-n Driver Optimization + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"PlatformSupportMiracast"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\NVIDIA Corporation\Global\NVTweak\Devices\509901423-0\Color] +"NvCplUseColorCorrection"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems] +"Optional"="" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\FTS] +"EnableRID61684"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm\Global\NVTweak] +"DisplayPowerSaving"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Scheduler] +"EnablePreemption"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0000] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"TdrLevel"=dword:00000000 +"UseGpuTimer"=dword:00000001 +"RmGpsPsEnablePerCpuCoreDpc"=dword:00000001 +"PowerSavingTweaks"=dword:00000000 +"DisableWriteCombining"=dword:00000001 +"EnableRuntimePowerManagement"=dword:00000000 +"PrimaryPushBufferSize"=dword:00000001 +"FlTransitionLatency"=dword:00000000 +"D3PCLatency"=dword:00000000 +"RMDeepLlEntryLatencyUsec"=dword:00000000 +"PciLatencyTimerControl"=dword:00000020 +"Node3DLowLatency"=dword:00000001 +"LOWLATENCY"=dword:00000001 +"RmDisableRegistryCaching"=dword:00000001 +"RMDisablePostL2Compression"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers\Power] +"UseGpuTimer"=dword:00000001 +"RmGpsPsEnablePerCpuCoreDpc"=dword:00000001 +"PowerSavingTweaks"=dword:00000000 +"DisableWriteCombining"=dword:00000001 +"EnableRuntimePowerManagement"=dword:00000000 +"PrimaryPushBufferSize"=dword:00000001 +"FlTransitionLatency"=dword:00000000 +"D3PCLatency"=dword:00000000 +"RMDeepLlEntryLatencyUsec"=dword:00000000 +"PciLatencyTimerControl"=dword:00000020 +"Node3DLowLatency"=dword:00000001 +"LOWLATENCY"=dword:00000001 +"RmDisableRegistryCaching"=dword:00000001 +"RMDisablePostL2Compression"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceNoContext"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceMonitorOff"=dword:00000001 +"DefaultMemoryRefreshLatencyToleranceActivelyUsed"=dword:00000001 +"DefaultLatencyToleranceTimerPeriod "=dword:00000001 +"DefaultLatencyToleranceOther"=dword:00000001 +"DefaultLatencyToleranceNoContextMonitorOff"=dword:00000001 +"DefaultLatencyToleranceNoContext"=dword:00000001 +"DefaultLatencyToleranceMemory"=dword:00000001 +"DefaultLatencyToleranceIdle1MonitorOff"=dword:00000001 +"DefaultLatencyToleranceIdle1"=dword:00000001 +"DefaultLatencyToleranceIdle0MonitorOff"=dword:00000001 +"DefaultLatencyToleranceIdle0"=dword:00000001 +"DefaultD3TransitionLatencyIdleVeryLongTime"=dword:00000001 +"DefaultD3TransitionLatencyIdleShortTime"=dword:00000001 +"DefaultD3TransitionLatencyIdleNoContext"=dword:00000001 +"DefaultD3TransitionLatencyIdleMonitorOff"=dword:00000001 +"DefaultD3TransitionLatencyIdleLongTime"=dword:00000001 +"DefaultD3TransitionLatencyActivelyUsed"=dword:00000001 +"Latency"=dword:00000001 +"DefaultD3TransitionLatencyActivelyUsed"=dword:00000001 +"TransitionLatency"=dword:00000001 +"MonitorRefreshLatencyTolerance"=dword:00000001 +"MonitorLatencyTolerance"=dword:00000001 +"MiracastPerfTrackGraphicsLatency"=dword:00000001 +"MaxIAverageGraphicsLatencyInOneBucket"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\GraphicsDrivers] +"DpiMapIommuContiguous"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0001] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D220F-16B0-11EC-AA00-D49CC0720C6C}\0002] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0000] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0001] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0002] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Video\{3D9D2216-16B0-11EC-AA00-005056C00008}\0003] +"DDC2Disabled"=dword:00000001 +"MultiFunctionSupported"=dword:00000001 +"TimingSelection"=dword:00000000 +"VgaCompatible"=dword:00000000 +"Adaptive De-interlacing"=dword:00000000 +"VPE Adaptive De-interlacing"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"TVEnableOverscan"=dword:00000000 +"UA_Enabled"=dword:00000001 +"KMD_EnableOPM2Interface"=dword:00000001 +"WmAgpMaxIdleClk"=dword:00000020 +"MemInitLatencyTimer"=dword:00000001 +"GamePerformanceAdviserEnabled"=dword:00000000 +"DisableAllClockGating"=dword:00000001 +"DisableGfxCGPowerGating"=dword:00000001 +"DisableCpPowerGating"=dword:00000001 +"DisableStaticGfxMGPowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisablePowerGating"=dword:00000001 +"DisablePCIConfigAsicReset"=dword:00000001 +"KMD_CursorMagnificationThreshold"=-0 +"DisableDynamicGfxMGPowerGating"=dword:00000001 +"EnableLBPWSupport"=dword:00000001 +"DisableRlcSmuPGHandshake"=dword:00000001 +"DisableSysClockGating"=dword:00000001 +"DisableGfxClockGating"=dword:00000001 +"EnableUlps"=dword:00000000 +"DisableFBCSupport"=dword:00000001 +"EnableCrossFireAutoLink"=dword:00000000 +"ExtEvent_BIOSEventByInterrupt"=dword:00000000 +"TVDisableModes"=dword:00000001 +"LazyPreload"=dword:00000001 +"DisableForceRemoveWrite"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0001] +"LTRSnoopL1Latency"=dword:00000001 +"LTRSnoopL0Latency"=dword:00000001 +"LTRNoSnoopL1Latency"=dword:00000001 +"LTRMaxNoSnoopLatency"=dword:00000001 +"KMD_RpmComputeLatency"=dword:00000001 +"DalUrgentLatencyNs"=dword:00000001 +"memClockSwitchLatency"=dword:00000001 +"PP_RTPMComputeF1Latency"=dword:00000001 +"PP_DGBMMMaxTransitionLatencyUvd"=dword:00000001 +"PP_DGBPMMaxTransitionLatencyGfx"=dword:00000001 +"DalNBLatencyForUnderFlow"=dword:00000001 +"DalDramClockChangeLatencyNs"=dword:00000001 +"BGM_LTRSnoopL1Latency"=dword:00000001 +"BGM_LTRSnoopL0Latency"=dword:00000001 +"BGM_LTRNoSnoopL1Latency"=dword:00000001 +"BGM_LTRNoSnoopL0Latency"=dword:00000001 +"BGM_LTRMaxSnoopLatencyValue"=dword:00000001 +"BGM_LTRMaxNoSnoopLatencyValue"=dword:00000001 +"EnableVceSwClockGating"=dword:00000001 +"EnableUvdClockGating"=dword:00000001 +"DisableVCEPowerGating"=dword:00000000 +"DisableUVDPowerGatingDynamic"=dword:00000000 +"DisablePowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisableFBCForFullScreenApp"="0" +"DisableFBCSupport"=dword:00000000 +"DisableEarlySamuInit"=dword:00000001 +"PP_GPUPowerDownEnabled"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_SclkDeepSleepDisable"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000001 +"PP_ActivityTarget"=dword:0000001e +"PP_ODNFeatureEnable"=dword:00000001 +"EnableUlps"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"PP_AllGraphicLevel_DownHyst"=dword:00000014 +"PP_AllGraphicLevel_UpHyst"=dword:00000000 +"KMD_FRTEnabled"=dword:00000000 +"DisableDMACopy"=dword:00000001 +"DisableBlockWrite"=dword:00000000 +"PP_ODNFeatureEnable"=dword:00000001 +"KMD_MaxUVDSessions"=dword:00000020 +"DalAllowDirectMemoryAccessTrig"=dword:00000001 +"DalAllowDPrefSwitchingForGLSync"=dword:00000000 +"WmAgpMaxIdleClk"=dword:00000020 +"StutterMode"=dword:00000000 +"TVEnableOverscan"=dword:00000000 +"PowerMizerEnable"=dword:00000001 +"PowerMizerLevel"=dword:00000001 +"PowerMizerLevelAC"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4d36e968-e325-11ce-bfc1-08002be10318}\0000] +"LTRSnoopL1Latency"=dword:00000001 +"LTRSnoopL0Latency"=dword:00000001 +"LTRNoSnoopL1Latency"=dword:00000001 +"LTRMaxNoSnoopLatency"=dword:00000001 +"KMD_RpmComputeLatency"=dword:00000001 +"DalUrgentLatencyNs"=dword:00000001 +"memClockSwitchLatency"=dword:00000001 +"PP_RTPMComputeF1Latency"=dword:00000001 +"PP_DGBMMMaxTransitionLatencyUvd"=dword:00000001 +"PP_DGBPMMaxTransitionLatencyGfx"=dword:00000001 +"DalNBLatencyForUnderFlow"=dword:00000001 +"DalDramClockChangeLatencyNs"=dword:00000001 +"BGM_LTRSnoopL1Latency"=dword:00000001 +"BGM_LTRSnoopL0Latency"=dword:00000001 +"BGM_LTRNoSnoopL1Latency"=dword:00000001 +"BGM_LTRNoSnoopL0Latency"=dword:00000001 +"BGM_LTRMaxSnoopLatencyValue"=dword:00000001 +"BGM_LTRMaxNoSnoopLatencyValue"=dword:00000001 +"EnableVceSwClockGating"=dword:00000001 +"EnableUvdClockGating"=dword:00000001 +"DisableVCEPowerGating"=dword:00000000 +"DisableUVDPowerGatingDynamic"=dword:00000000 +"DisablePowerGating"=dword:00000001 +"DisableSAMUPowerGating"=dword:00000001 +"DisableFBCForFullScreenApp"="0" +"DisableFBCSupport"=dword:00000000 +"DisableEarlySamuInit"=dword:00000001 +"PP_GPUPowerDownEnabled"=dword:00000000 +"DisableDrmdmaPowerGating"=dword:00000001 +"PP_SclkDeepSleepDisable"=dword:00000001 +"PP_ThermalAutoThrottlingEnable"=dword:00000001 +"PP_ActivityTarget"=dword:0000001e +"PP_ODNFeatureEnable"=dword:00000001 +"EnableUlps"=dword:00000000 +"GCOOPTION_DisableGPIOPowerSaveMode"=dword:00000001 +"PP_AllGraphicLevel_DownHyst"=dword:00000014 +"PP_AllGraphicLevel_UpHyst"=dword:00000000 +"KMD_FRTEnabled"=dword:00000000 +"DisableDMACopy"=dword:00000001 +"DisableBlockWrite"=dword:00000000 +"PP_ODNFeatureEnable"=dword:00000001 +"KMD_MaxUVDSessions"=dword:00000020 +"DalAllowDirectMemoryAccessTrig"=dword:00000001 +"DalAllowDPrefSwitchingForGLSync"=dword:00000000 +"WmAgpMaxIdleClk"=dword:00000020 +"StutterMode"=dword:00000000 +"TVEnableOverscan"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\nvlddmkm] +"NVFBCEnable"=dword:00000001 +"DisablePreemption"=dword:00000001 +"DisableCudaContextPreemption"=dword:00000001 +"DisableWriteCombining"=dword:00000001 +"EnableTiledDisplay"=dword:00000000 +"ComputePreemption"=dword:00000000 +"DisablePreemptionOnS3S4"=dword:00000001 +"EnableCEPreemption"=dword:00000000 + +[HKLM\SYSTEM\CurrentControlSet\Services\DXGKrnl] +"MonitorLatencyTolerance"=dword:00000001 + +[HKLM\SYSTEM\CurrentControlSet\Services\DXGKrnl] +"MonitorRefreshLatencyTolerance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouhid\Parameters] +"TreatAbsolutePointerAsAbsolute"=dword:00000001 +"TreatAbsoluteAsRelative"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\CDP] +"CdpSessionUserAuthzPolicy"=dword:00000000 +"RomeSdkChannelUserAuthzPolicy"=dword:00000000 + +;026. Session Manager Configuration (Meltown and Spectre) + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"DisablePagingExecutive"=dword:00000001 +"LargeSystemCache"=dword:00000001 +"NonPagedPoolSize"=dword:000000c0 +"PagedPoolSize"=dword:000000c0 +"FeatureSettings"=dword:00000001 +"FeatureSettingsOverride"=dword:00000003 +"FeatureSettingsOverrideMask"=dword:00000003 +"PoolUsageMaximum"=dword:000000c0 +"EnableCfg"=dword:00000000 +"IoPageLockLimit"=dword:ffffffff +"ProtectionMode"=dword:00000000 +"ThirdLevelDataCache"=dword:00008192 +"MoveImages"=dword:00000000 +"PhysicalAddressExtension"=dword:00000001 +"SecondLevelDataCache"=dword:00003072 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel] +"DpcWatchdogProfileOffset"=dword:00000000 +"DpcTimeout"=dword:00000000 +"DpcWatchdogPeriod"=dword:00000000 +"DisableExceptionChainValidation"=dword:00000001 +"KernelSEHOPEnabled"=dword:00000000 +"DpcWatchdogProfileOffset"=dword:00000000 +"MitigationOptions"=hex:22,22,22,22,22,22,22,22,20,02,00,00,00,20,00,00 +"MitigationAuditOptions"=hex:20,00,00,20,20,20,22,22,00,00,00,00,00,00,00,00 +"DisableExceptionChainValidation"=dword:00000001 +"MaximumSharedReadyQueueSize"=dword:00000001 +"DisableAutoBoost"=dword:00000001 +"DistributeTimers"=dword:00000001 +"IdealDpcRate"=dword:00000001 +"MaximumDpcQueueDepth"=dword:00000001 +"MinimumDpcRate"=dword:00000001 +"ThreadDpcEnable"=dword:00000001 +"AdjustDpcThreshold"=dword:00000000 +[HKEY_LOCAL_MACHINE\SYSTEM] +"MinimumWorkingSet"=hex(b):00,00,00,00,00,10,00,00 +"MinimumFileCacheSize"=hex(b):00,00,00,00,00,10,00,00 +"increaseuserva"=dword:0fffff80 +"InterruptSteeringDisabled"=dword:00000001 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 +"OverlayTestMode"=dword:00000005 +"UseLargePages"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsMitigation] +"UserPreference"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"MinimumWorkingSet"=hex(b):00,00,00,00,00,10,00,00 +"MinimumFileCacheSize"=hex(b):00,00,00,00,00,10,00,00 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 +"OverlayTestMode"=dword:00000005 +"UseLargePages"=dword:00000001 +"LargePageDrivers"=hex(7):41,00,46,00,44,00,00,00,61,00,6d,00,64,00,68,00,75,\ + 00,62,00,33,00,31,00,00,00,61,00,6d,00,64,00,78,00,68,00,63,00,33,00,31,00,\ + 00,00,64,00,69,00,73,00,6b,00,00,00,44,00,58,00,47,00,4b,00,72,00,6e,00,6c,\ + 00,00,00,48,00,44,00,41,00,75,00,64,00,42,00,75,00,73,00,00,00,48,00,69,00,\ + 64,00,55,00,73,00,62,00,00,00,6b,00,62,00,64,00,63,00,6c,00,61,00,73,00,73,\ + 00,00,00,6b,00,62,00,64,00,68,00,69,00,64,00,00,00,6d,00,6f,00,75,00,63,00,\ + 6c,00,61,00,73,00,73,00,00,00,6d,00,6f,00,75,00,68,00,69,00,64,00,00,00,4e,\ + 00,44,00,49,00,53,00,00,00,6e,00,76,00,6c,00,64,00,64,00,6d,00,6b,00,6d,00,\ + 00,00,54,00,63,00,70,00,69,00,70,00,00,00,75,00,73,00,62,00,68,00,75,00,62,\ + 00,00,00,55,00,53,00,42,00,48,00,55,00,42,00,33,00,00,00,55,00,53,00,42,00,\ + 58,00,48,00,43,00,49,00,00,00,57,00,64,00,66,00,30,00,31,00,30,00,30,00,30,\ + 00,00,00,78,00,62,00,6f,00,78,00,67,00,69,00,70,00,00,00,78,00,69,00,6e,00,\ + 70,00,75,00,74,00,68,00,69,00,64,00,00,00,69,00,67,00,64,00,6d,00,64,00,36,\ + 00,34,00,00,00,00,00 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCompatCache] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\xusb22\Parameters] +"IoQueueWorkItem"=dword:0000000a + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip6\Parameters] +"DisabledComponents"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseSensitivity"="10" + + +;027.SecDrv + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SecDrv] +"Type"=dword:00000001 +"Start"=dword:00000003 +"ErrorControl"=dword:00000001 +"ImagePath"=hex(2):43,00,3a,00,5c,00,57,00,49,00,4e,00,44,00,4f,00,57,00,53,00,\ + 5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,64,00,72,00,69,\ + 00,76,00,65,00,72,00,73,00,5c,00,53,00,45,00,43,00,44,00,52,00,56,00,2e,00,\ + 53,00,59,00,53,00,00,00 +"DisplayName"="SecDrv" +"WOW64"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SecDrv\Security] +"Security"=hex:01,00,14,80,8c,00,00,00,98,00,00,00,14,00,00,00,30,00,00,00,02,\ + 00,1c,00,01,00,00,00,02,80,14,00,ff,01,0f,00,01,01,00,00,00,00,00,01,00,00,\ + 00,00,02,00,5c,00,04,00,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,\ + 05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,20,00,00,00,\ + 20,02,00,00,00,00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,04,00,00,00,00,\ + 00,14,00,fd,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,01,00,00,00,00,\ + 00,05,12,00,00,00,01,01,00,00,00,00,00,05,12,00,00,00 + +;028.Resource Management + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\I/O System] +"PassiveIntRealTimeWorkerPriority"=dword:00000018 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\KernelVelocity] +"DisableFGBoostDecay"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\HardCap0] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\Paused] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapFull] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapFullAboveNormal] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapLow] +"CapPercentage"=dword:00000000 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\SoftCapLowBackgroundBegin] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\CPU\UnmanagedAboveNormal] +"CapPercentage"=dword:00000000 +"PriorityClass"=dword:00000020 +"SchedulingType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\BackgroundDefault] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Frozen] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenDNCS] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenDNK] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\FrozenPPLE] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Paused] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\PausedDNK] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\Pausing] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\PrelaunchForeground] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Flags\ThrottleGPUInterference] +"IsLowPriority"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Critical] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\CriticalNoUi] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\EmptyHostPPLE] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\High] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Low] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Lowest] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\Medium] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\MediumHigh] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\StartHost] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\VeryHigh] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Importance\VeryLow] +"BasePriority"=dword:00000082 +"OverTargetPriority"=dword:00000050 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\IO\NoCap] +"IOBandwidth"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ResourcePolicyStore\ResourceSets\Policies\Memory\NoCap] +"CommitLimit"=dword:ffffffff +"CommitTarget"=dword:ffffffff + +;029. Services + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\amdpsp] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpbus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CDPUserSvc] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\acpitime] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AcpiPmi] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AcpiDev] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\acpipagr] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GpuEnergyDrv] +"Start"=dword:00000004 + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\AMDLOG] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus_25D3A396F7F029EE] +"Start"=dword:00000004 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\ImmersiveShell] +"ConvertibleSlateModePromptPreference"=dword:00000000 +"TabletMode"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\perceptionsimulation] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PenService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edgeupdate] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\edgeupdatem] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\GoogleChromeElevationService] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Credssp] +"DebugLogLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] +"RestrictReceivingNTLMTraffic"=dword:00000002 +"RestrictSendingNTLMTraffic"=dword:00000002 +"SCENoApplyLegacyAuditPolicy"=dword:00000000 +"RestrictAnonymousSAM"=dword:00000001 +"RestrictAnonymous"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Throttle] +"PerfEnablePackageIdle"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Processor] +"CPPCEnable"=dword:00000000 +"AllowPepPerfStates"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Edge] +"SitePerProcess"=dword:00000001 + + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.devicemetadata-ms] + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\MicrosoftEdge\PhishingFilter] +"EnabledV9"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\hola_updater] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CaptureService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSSystemAnalysis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSSystemDiagnosis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSLinkNear] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ASUSLinkRemote] + +[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\BcastDVRUserService] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\gameflt] +"Start"=dword:00000004 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WerSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndu] + + + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiSystemHost] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GpuEnergyDrv] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\storqosflt] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\hvcmon] + + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FontCache3.0.0.0] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GraphicsPerfSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PcaSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DiagTrack] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmwappushservice] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\diagsvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DPS] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\diagnosticshub.standardcollector.service] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdiServiceHost] + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WacomPen] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PktMon] +"Start"=dword:00000004 +"Type"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\QWAVEdrv] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Beep] +"Start"=dword:00000004 + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysMain] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WSearch] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AMD External Events Utility] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSLinkNear] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSLinkRemote] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSSystemAnalysis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ASUSSystemDiagnosis] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BcastDVRUserService] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_64] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v4.0.30319_32] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_64] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\clr_optimization_v2.0.50727_32] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdate] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdatem] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PimIndexMaintenanceSvc] + +[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\gupdatem] + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisVirtualBus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Vid] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\umbus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CompositeBus] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\rdpbus] +"Start"=dword:00000004 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ndu] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NdisCap] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SystemUsageReportSvc_QUEENCREEK] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Intel(R) SUR QC SAM] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LMS] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MEIx64] +"Start"=dword:00000004 +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GraphicsPerfSvc] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dam] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\bam] +"Start"=dword:00000004 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Audiosrv] +"ErrorControl"=dword:00000002 + + + +;030. File System Efficency + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FileSystem] +"DisableDeleteNotification"=dword:00000001 +"RefsDisableLastAccessUpdate"=dword:00000001 +"Win31FileSystem"=dword:00000000 +"Win95TruncatedExtensions"=dword:00000000 +"LongPathsEnabled"=dword:00000001 +"NtfsDisableLastAccessUpdate"=dword:00000001 +"NtfsMemoryUsage"=dword:00000000 +"NtfsMftZoneReservation"=dword:00000004 +"NtfsDisableSpotCorruptionHandling"=dword:00000001 +"RefsDisableLastAccessUpdate"=dword:00000001 +"NtfsBugcheckOnCorrupt"=dword:00000000 +"LongPathsEnabled"=dword:00000001 +"NTFSDisable8dot3NameCreation"=dword:00000001 +"LongPathsEnabled"=dword:00000001 + + +;031. Delay & Timeout + +[HKEY_CURRENT_USER\Control Panel\Desktop] +"AutoEndTasks"="1" +"MenuShowDelay"="0" +"AutoEndTasks"="1" +"ScreenSaveTimeOut"=- +"SCRNSAVE.EXE"=- +"ForegroundLockTimeout"=dword:00000000 +"MouseWheelRouting"=dword:00000000 +"WaitToKillAppTimeout"="1" +"WaitToKillServiceTimeout"=dword:00000002 +"HungAppTimeout"="2000" +"LowLevelHooksTimeout"=dword:00000005 +"Win8DpiScaling"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\kernel] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Executive] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] +"CoalescingTimerInterval"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\ModernSleep] +"CoalescingTimerInterval"=dword:00000000 + + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control] +"CoalescingTimerInterval"=dword:00000000 +"WaitToKillServiceTimeout"="1" +"DisableRemoteScmEndpoints"dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control] +"WaitToKillServiceTimeout"="1" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\PnP] +"PollBootPartitionTimeout"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfNet\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfOS\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfDisk\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PerfProc\Performance] +"Collect Supports Metadata"=dword:00000000 +"Collect Timeout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\BackgroundModel\BackgroundAudioPolicy] +"AllowHeadlessExecution"=dword:00000001 +"AllowMultipleBackgroundTasks"=dword:00000001 +"InactivityTimeoutMs"=dword:FFFFFFFF + +;032. Google Chrome + +[HEKY_CURRENT_USER\SOFTWARE\Policies\Google\Chrome] +"TranslateEnabled"=dword:00000001 +"TaskManagerEndProcessEnabled"=dword:00000001 +"UserFeedbackAllowed"=dword:00000000 +"SpellCheckServiceEnabled"=dword:00000000 +"SpellcheckEnabled"=dword:00000000 +"MediaRouterCastAllowAllIPs"=dword:00000001 +"AllowDinosaurEasterEgg"=dword:00000001 +"DefaultGeolocationSetting"=dword:00000002 +"DefaultCookiesSetting"=dword:00000001 +"DefaultFileHandlingGuardSetting"=dword:00000003 +"DefaultFileSystemReadGuardSetting"=dword:00000003 +"DefaultFileSystemWriteGuardSetting"=dword:00000003 +"DefaultPopupsSetting"=dword:00000002 +"DefaultSensorsSetting"=dword:00000002 +"DefaultSerialGuardSetting"=dword:00000002 +"DefaultWebBluetoothGuardSetting"=dword:00000002 +"DefaultWebUsbGuardSetting"=dword:00000002 +"EnableMediaRouter"=dword:00000001 +"ShowCastIconInToolbar"=dword:00000001 +"CloudPrintProxyEnabled"=dword:00000000 +"PrintRasterizationMode"=dword:00000000 +"PrintingEnabled"=dword:00000001 +"DefaultPluginsSetting"=dword:00000001 +"SafeBrowsingProtectionLevel"=dword:00000000 +"SafeBrowsingExtendedReportingEnabled"=dword:00000000 +"HomepageIsNewTabPage"=dword:00000000 +"HomepageLocation"="google.com" +"NewTabPageLocation"="google.com" +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 +"ChromeCleanupEnabled"=dword:00000000 +"ChromeCleanupReportingEnabled"=dword:00000000 +"DefaultSearchProviderName"="sGoogle Encrypted" +"DefaultSearchProviderSearchURL"="https://www.google.com/#q={searchTerms}" +"DefaultSearchProviderEnabled"=dword:01000000 +"AllowCrossOriginAuthPrompt"=dword:00000000 +"AlwaysOpenPdfExternally"=dword:00000001 +"AmbientAuthenticationInPrivateModesEnabled"=dword:00000000 +"AudioCaptureAllowed"=dword:00000001 +"AudioSandboxEnabled"=dword:00000000 +"DnsOverHttpsMode"="off" +"ScreenCaptureAllowed"=dword:00000001 +"SitePerProcess"=dword:00000001 +"TLS13HardeningForLocalAnchorsEnabled"=dword:00000001 +"VideoCaptureAllowed"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome] +"TranslateEnabled"=dword:00000001 +"TaskManagerEndProcessEnabled"=dword:00000001 +"UserFeedbackAllowed"=dword:00000000 +"SpellCheckServiceEnabled"=dword:00000000 +"SpellcheckEnabled"=dword:00000000 +"MediaRouterCastAllowAllIPs"=dword:00000001 +"AllowDinosaurEasterEgg"=dword:00000001 +"DefaultGeolocationSetting"=dword:00000002 +"DefaultCookiesSetting"=dword:00000001 +"DefaultFileHandlingGuardSetting"=dword:00000003 +"DefaultFileSystemReadGuardSetting"=dword:00000003 +"DefaultFileSystemWriteGuardSetting"=dword:00000003 +"DefaultPopupsSetting"=dword:00000002 +"DefaultSensorsSetting"=dword:00000002 +"DefaultSerialGuardSetting"=dword:00000002 +"DefaultWebBluetoothGuardSetting"=dword:00000002 +"DefaultWebUsbGuardSetting"=dword:00000002 +"EnableMediaRouter"=dword:00000001 +"ShowCastIconInToolbar"=dword:00000001 +"CloudPrintProxyEnabled"=dword:00000000 +"PrintRasterizationMode"=dword:00000000 +"PrintingEnabled"=dword:00000001 +"DefaultPluginsSetting"=dword:00000001 +"SafeBrowsingProtectionLevel"=dword:00000000 +"SafeBrowsingExtendedReportingEnabled"=dword:00000000 +"HomepageIsNewTabPage"=dword:00000000 +"HomepageLocation"="google.com" +"NewTabPageLocation"="google.com" +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 +"ChromeCleanupEnabled"=dword:00000000 +"ChromeCleanupReportingEnabled"=dword:00000000 +"DefaultSearchProviderName"="sGoogle Encrypted" +"DefaultSearchProviderSearchURL"="https://www.google.com/#q={searchTerms}" +"DefaultSearchProviderEnabled"=dword:01000000 +"AllowCrossOriginAuthPrompt"=dword:00000000 +"AlwaysOpenPdfExternally"=dword:00000001 +"AmbientAuthenticationInPrivateModesEnabled"=dword:00000000 +"AudioCaptureAllowed"=dword:00000001 +"AudioSandboxEnabled"=dword:00000000 +"DnsOverHttpsMode"="off" +"ScreenCaptureAllowed"=dword:00000001 +"SitePerProcess"=dword:00000001 +"TLS13HardeningForLocalAnchorsEnabled"=dword:00000001 +"VideoCaptureAllowed"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\3rdparty\Extensions\djflhoibgkdhkhhcedjiklpkjnoahfmg\policy\OtherSettings] +"send_errors"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\ExtensionInstallForcelist] +"1"="cjpalhdlnbpafiamejdnhcphjbkeiagm" +"2"="fihnjjcciajhdojfnbdddfaoknhalnja" +"3"="bnomihfieiccainjcjblhegjgglakjdd" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\Recommended] +"MetricsReportingEnabled"=dword:00000000 +"DeviceMetricsReportingEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Chrome\URLBlacklist] +"1"="javascript://*" + + + +;033. Virtualization +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity] +"Enabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard] +"DeployConfigCIPolicy"=dword:00000000 +"EnableVirtualizationBasedSecurity"=dword:00000000 +"HVCIMATRequired"=dword:00000000 +"RequirePlatformSecurityFeature"=dword:00000000 +"CachedDrtmAuthIndex"=dword:00000000 +"RequireMicrosoftSignedBootChain"=dword:00000000 +"RequirePlatformSecurityFeatures"=dword:00000000 +"Locked"=dword:00000000 + +;034. Input Tweaks + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\TabletTip\1.7] +"HideIPTIPTarget"=dword:00000001 +"HideIPTIPTouchTarget"=dword:00000001 +"IncludeRareChar"=dword:00000000 +"DisableEdgeTarget"=dword:00000001 +"DisableACIntegration"=dword:00000001 +"EnableAutocorrection"=dword:00000000 +"EnableSpellchecking"=dword:00000000 +"EnableTextPrediction"=dword:00000000 +"EnablePredictionSpaceInsertion"=dword:00000000 +"EnableDoubleTapSpace"=dword:00000000 +"EnableInkingWithTouch"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\TabletTip\1.7] +"HideIPTIPTarget"=dword:00000001 +"HideIPTIPTouchTarget"=dword:00000001 +"IncludeRareChar"=dword:00000000 +"DisableEdgeTarget"=dword:00000001 +"DisableACIntegration"=dword:00000001 +"EnableAutocorrection"=dword:00000000 +"EnableSpellchecking"=dword:00000000 +"EnableTextPrediction"=dword:00000000 +"EnablePredictionSpaceInsertion"=dword:00000000 +"EnableDoubleTapSpace"=dword:00000000 +"EnableInkingWithTouch"=dword:00000000 + + + +[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings] +"EnableExpressiveInputShellHotkey"=dword:00000001 +"EnableExpressiveInputEmojiMultipleSelection"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\PenWorkspace] +"PenWorkspaceAppSuggestionsEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Diagnostics\DiagTrack\EventTranscriptKey] +"EnableEventTranscript"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorSpeed] +"CursorSensitivity"=dword:00002710 +"CursorUpdateInterval"=dword:00000001 +"IRRemoteNavigationDelta"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorMagnetism] +"AttractionRectInsetInDIPS"=dword:00000005 +"DistanceThresholdInDIPS"=dword:00000028 +"MagnetismDelayInMilliseconds"=dword:00000002 +"MagnetismUpdateIntervalInMilliseconds"=dword:00000001 +"VelocityInDIPSPerSecond"=dword:00000168 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] +"EnableCursorSuppression"=dword:00000000 +"DelayedDesktopSwitchTimemout"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\SystemCertificates\ChainEngine\Config] +"ChainRevAccumulativeUrlRetrievalTimeoutMilliseconds"=dword:0000000e +"ChainUrlRetrievalTimeoutMilliseconds"=dword:0000000e +"CrossCertDownloadIntervalHours"=dword:000000a8 +"Options"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings] +"AutoAccent"=dword:00000000 +"AutoApostrophe"=dword:00000000 +"AutoCap"=dword:00000000 +"AutoCapAllTokens"=dword:00000000 +"AutoCorrectFirstWord"=dword:00000000 +"AutoCorrection"=dword:00000000 +"AutoCorrectVisualDelay"=dword:00000000 +"AutoswitchAfterEmoji"=dword:00000000 +"ContactPenalty"=dword:00000000 +"DictationEnabled"=dword:00000001 +"DictationSupportedLanguages"="en-US;fr-FR;en-GB;de-DE;it-IT;zh-hans-CN;es-ES;en-IN;pt-BR;en-AU;en-CA;fr-CA;es-MX;ro-RO" +"DisablePersonalization"=dword:00000001 +"EmojiSuggestion"=dword:00000001 +"EmojiTranslation"=dword:00000001 +"EnableHwkbAutocorrection"=dword:00000000 +"EnableHwkbMode"=dword:00000000 +"EnableHwkbTextPrediction"=dword:00000000 +"HarvestContacts"=dword:00000000 +"HasTrailer"=dword:00000000 +"HTREnabled"=dword:00000000 +"HwkbAutocorrectionAlwaysOffList"=-" +"InsightsEnabled"=dword:00000000 +"IsVoiceTypingKeyEnabled"=dword:00000001 +"KeyboardMode"=dword:00000000 +"LMDataLoggerEnabled"=dword:00000000 +"MaxCorrections"=dword:00000000 +"MultilingualEnabled"=dword:00000000 +"NotActiveLanguagePenalty"=dword:00000000 +"NotPredictedLanguagePenalty"=dword:00000000 +"PeriodShortcut"=dword:00000000 +"Prediction"=dword:00000000 +"Private"=dword:00000000 +"ProofDataSources"=dword:00000000 +"SearchDataSources"=dword:00000000 +"Spellcheck"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\InputPersonalization\TrainedDataStore] +"HarvestContacts"=dword:00000000 +"InsightsEnabled"=dword:00000000 +"LMDataLoggerEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Speech] +"AllowSpeechModelUpdate"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Privacy] +"TailoredExperiencesWithDiagnosticDataEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MSDeploy\3] +"EnableTelemetry"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CPSS\UserPolicy\ImproveInkingAndTyping] +"DefaultValue"=dword:00000000 +"InheritsFromDevice"=dword:00000000 +"LegacyKeyName"="Enabled" +"LegacyKeyType"=dword:00000000 +"LegacyProjection"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Diagnostics\Performance] +"DisableDiagnosticTracing"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CPSS\UserPolicy\InkingAndTypingPersonalization] +"DefaultValue"=dword:00000000 +"InheritsFromDevice"=dword:00000000 +"LegacyKeyType"=dword:00000000 +"LegacyProjection"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Input\Settings] +"EnableHwkbAutocorrection2"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TabletPC] +"PreventHandwritingDataSharing"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\HandwritingErrorReports] +"PreventHandwritingErrorReports"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PenTraining] +"DisablePenTraining"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsInkWorkspace] +"AllowWindowsInkWorkspace"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Input\Settings\ControllerProcessor\CursorSpeed] +"CursorUpdateInterval"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mouclass\Parameters] +"MouseDataQueueSize"=dword:00000032 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdclass\Parameters] +"KeyboardDataQueueSize"=dword:00000032 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MMCSS] +"Start"=dword:00000004 + +[HKEY_USERS\.DEFAULT\Control Panel\Mouse] +"MouseSpeed"="0" +"MouseThreshold1"="0" +"MouseThreshold2"="0" + + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseSpeed"="0" +"MouseThreshold1"="0" +"MouseThreshold2"="0" + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"Beep"="No" +"ExtendedSounds"="No" + +[HKEY_USERS\.DEFAULT\Control Panel\Sound] +"Beep"="no" +"ExtendedSounds"="no" + +[HKEY_CURRENT_USER\Control Panel\Sound] +"Beep"="no" +"ExtendedSounds"="no" + +[HKEY_CURRENT_USER\Control Panel\Keyboard] +"KeyboardDelay"="0" +"KeyboardSpeed"="10" +"InitialKeyboardIndicators"="2" + +[HKEY_USERS\.DEFAULT\Control Panel\Keyboard] +"InitialKeyboardIndicators"="2" +"KeyboardDelay"="0" +"KeyboardSpeed"="10" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AFD\Parameters] +"DefaultReceiveWindow"=dword:00004000 +"DefaultSendWindow"=dword:00004000 +"FastCopyReceiveThreshold"=dword:00004000 +"FastSendDatagramThreshold"=dword:00004000 +"DynamicSendBufferDisable"=dword:00000000 +"IgnorePushBitOnReceives"=dword:00000001 +"NonBlockingSendSpecialBuffering"=dword:00000001 +"DisableRawSecurity"=dword:00000001 +"DoNotHoldNicBuffers"=dword:00000001 +"DisableAddressSharing"=dword:00000001 + +;035. Office Tweaks + + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Lync] +"disableautomaticsendtracking"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common] +"QMEnable"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common\Feedback] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\15.0\osm] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\ClientTelemetry] +"MotherboardUUID"="-" +"DisableTelemetry"=dword:00000001 +"VerboseLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common] +"sentcostumerdata"=dword:00000000 +"qmenable"=dword:00000000 +"updaterealiabilitydata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\Feedback] +"enabled"=dword:00000000 +"includescreenshot"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Office\17.0\osm] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\OSM] +"enablelogging"=dword:00000000 +"enablefileobfuscation"=dword:00000000 +"enableupload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\Calendar] +"EnableCalendarLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Outlook\Security] +"InitEncrypt"=dword:00000002 +"InitSign"=dword:00000002 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\Common\Graphics] +"DisableAnimations"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common] +"sendcustomerdata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common\Feedback] +"enabled"=dword:00000000 +"includescreenshot"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common] +"qmenable"=dword:00000000 +"updatereliabilitydata"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\General] +"shownfirstrunoptin"=dword:00000000 +"skydrivesigninoption"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Common\ptwatson] +"ptwoptin"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\Firstrun] +"disablemovie"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\16.0\OSM] +"Enablelogging"=dword:00000000 +"EnableUpload"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Options\Calendar] +"EnableCalendarLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Options\Mail] +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options] +"EnableLogging"=dword:00000000 +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Word\Options\WordMail] +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options] +"EnableLogging"=dword:00000000 +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Word\Options\WordMail] +"DontUpdateLinks"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Common] +"sendcustomerdata"=dword:00000000 +"SendCustomerDataOptInReason"=dword:00000000 +"SendCustomerDataOptIn"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Options\Mail] +"BlockExtContent"=dword:00000000 +"UnblockSpecificSenders"=dword:00000000 +"EnableLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Common] +"QMEnable"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\International\User Profile] +"HttpAcceptLanguageOptOut"=dword:00000001 + + +;036. Google Update + +:: Google Update + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Google\Update] +"Install{8A69D345-D564-463C-AFF1-A69D9E530F96}"=dword:00000005 +"TargetChannel{8A69D345-D564-463C-AFF1-A69D9E530F96}"="stable" +"Update{8A69D345-D564-463C-AFF1-A69D9E530F96}"=dword:00000003 +"Install{4CCED17F-7852-4AFC-9E9E-C89D8795BDD2}"=dword:00000000 +"AutoUpdateCheckPeriodMinutes"=dword:0000a8c0 +"DownloadPreference"="cacheable" +"UpdatesSuppressedStartHour"=dword:00000017 +"UpdatesSuppressedStartMin"=dword:00000030 +"UpdatesSuppressedDurationMin"=dword:00000037 + + + +;037. Windows Update + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate] +"BranchReadinessLevel"=dword:00000010 +"DeferFeatureUpdates"=dword:00000001 +"DeferFeatureUpdatesPeriodInDays"=dword:00000000 +"ManagePreviewBuilds"=dword:00000001 +"ManagePreviewBuildsPolicyValue"=dword:00000000 +"PauseFeatureUpdatesStartTime"="" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] +"DetectionFrequency"=dword:00000014 +"DetectionFrequencyEnabled"=dword:00000001 +"EnableFeaturedSoftware"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsUpdate\UpdatePolicy\PolicyState] +"DeferQualityUpdates"=dword:00000001 +"DeferFeatureUpdates"=dword:00000001 +"BranchReadinessLevel"="CB" +"IsDeferralIsActive"=dword:00000001 +"IsWUfBConfigured"=dword:00000000 +"IsWUfBDualScanActive"=dword:00000000 +"FeatureUpdatesDeferralInDays"=dword:00000000 +"ExcludeWUDrivers"=dword:00000001 +"PolicySources"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FVE] +"DisableExternalDMAUnderLock"=dword:00000001 + +;038. XBOX + +[-HKEY_CURRENT_USER\System\GameConfigStore\Children] + +[-HKEY_CURRENT_USER\System\GameConfigStore\Parents] + +[HKEY_USERS\.DEFAULT\Software\Microsoft\GameBar] +"AutoGameModeEnabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\GameBar] +"AutoGameModeEnabled"=dword:00000000 + + +[HKEY_CURRENT_USER\Software\Microsoft\Games] +"EnableXBGM"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\GameDVR] +"KGLRevision"=- +"KGLToGCSUpdatedRevision"=- +"LastGameActivity"=- +"AppCaptureEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\GameDVR] +"AllowgameDVR"=dword:00000000 + +[HKEY_CURRENT_USER\System\GameConfigStore] +"GameDVR_FSEBehavior"=dword:00000002 + +[HKEY_CURRENT_USER\Software\Microsoft\GameBar] +"AllowAutoGameMode"=dword:00000000 +"AutoGameModeEnabled"=dword:00000000 +"ShowStartupPanel"=dword:00000000 +"ShowGameModeNotifications"=dword:00000000 + +[HKEY_CURRENT_USER\System\GameConfigStore] +"GameDVR_Enabled"=dword:00000000 +"GameDVR_FSEBehaviorMode"=dword:00000002 +"Win32_AutoGameModeDefaultProfile"=- +"Win32_GameModeRelatedProcesses"=- +"GameDVR_HonorUserFSEBehaviorMode"=dword:00000001 +"GameDVR_DXGIHonorFSEWindowsCompatible"=dword:00000001 +"GameDVR_EFSEFeatureFlags"=dword:00000000 +"GameDVR_FSEBehavior"=dword:00000002 + +[-HKEY_CURRENT_USER\System\GameConfigStore\Children] + +[-HKEY_CURRENT_USER\System\GameConfigStore\Parents] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\TWinUI\FilePicker\LastVisitedPidlMRU] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FeatureUsage] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Diagnostics] + +[-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Census] + +[-HKEY_CURRENT_USER\Briefcase\ShellNew] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.GameBar.PresenceServer.Internal.PresenceWriter] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameBar] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameChatOverlay] +"ActivationType"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsRuntime\ActivatableClassId\Windows.Gaming.UI.GameChatOverlayMessageSource] +"ActivationType"=dword:00000000 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\GameUX\Games\{FC96B68C-09EF-4251-A598-19E4BE1B76A9}] + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\PolicyManager\default\ApplicationManagement\AllowGameDVR] +"value"=dword:00000000 + +;039. Power Tweaks + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\2a737441-1930-4402-8d77-b2bebba308a3\d4e98f31-5ffe-4ce1-be31-1b38b384c009] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\d639518a-e56d-4345-8af2-b9f32fb26109] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\dab60367-53fe-4fbc-825e-521d069d2456] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\0b2d69d7-a2a1-449c-9680-f91c70521c60] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\54533251-82be-4824-96c1-47b60b740d00\12a0ab44-fe28-4fa9-b3bd-4b64f44960a6] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerSettings\0012ee47-9041-4b5d-9b77-535fba8b1442\6b013a00-f775-4d61-9036-a62f7e7a6a5b] +"Attributes"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"AcPolicy"=hex:01,00,00,00,00,00,00,00,03,00,00,00,10,00,00,00,02,00,00,00,03,\ + 00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,1a,88,\ + 41,7e,00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,32,00,00,00,02,00,00,\ + 00,02,00,00,00,02,00,00,00,01,00,00,00,96,88,41,7e,00,00,00,00,03,00,00,00,\ + 01,00,00,00,03,00,00,00,03,00,00,00,04,00,00,c0,01,00,00,00,05,00,00,00,01,\ + 00,00,00,0a,00,00,00,00,00,00,00,03,00,00,00,01,00,01,00,01,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,00,00,00,00,\ + 00,d0,09,00,08,00,00,00,3c,13,00,00,30,31,09,00,00,00,00,00,01,64,64,00,02,\ + 00,00,00,04,00,00,c0,00,00,00,00 +"DcPolicy"=hex:01,00,00,00,00,00,00,00,03,00,00,00,10,00,00,00,02,00,00,00,03,\ + 00,00,00,00,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,01,00,00,00,0d,00,\ + 00,00,02,00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,03,09,00,02,00,00,\ + 00,02,00,00,00,02,00,00,00,01,00,00,00,00,00,00,00,84,03,00,00,03,00,00,00,\ + 01,00,00,00,03,00,00,00,03,00,00,00,04,00,00,c0,01,00,00,00,05,00,00,00,01,\ + 00,00,00,0a,00,00,00,00,00,00,00,03,00,00,00,01,00,01,00,01,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,03,00,00,00,00,00,2c,01,00,00,\ + 01,88,41,7e,99,01,00,00,d0,7f,54,00,e4,7f,54,00,58,02,00,00,01,64,64,00,02,\ + 00,00,00,04,00,00,c0,00,00,00,00 + +[HKEY_CURRENT_USER\Control Panel\PowerCfg\PowerPolicies\0] +"Policies"=hex:01,00,00,00,00,00,00,00,01,00,00,00,00,00,00,00,02,00,00,00,00,\ + 00,00,00,00,00,00,00,00,00,00,00,2c,01,00,00,32,32,00,03,02,00,00,00,02,00,\ + 00,00,00,00,3d,77,2e,f2,07,00,00,00,00,00,2c,01,00,00,00,00,00,00,58,02,00,\ + 00,01,01,64,64,64,64,91,7c + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\PowerThrottling] +"PowerThrottlingOff"=dword:00000001 + + +;040. Control Panel Items (only Windows 10) + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Account Manager" +"InfoTip"="Opens Account Manager" +"System.ControlPanel.Category"="9" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\DefaultIcon] +@="%SystemRoot%\\System32\\netplwiz.exe" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\Shell\Open\command] +@="netplwiz.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Add Advanced User Accounts to Control Panel" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@=" Account Manager" +"InfoTip"="Opens Account Manager" +"System.ControlPanel.Category"="9" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\DefaultIcon] +@="%SystemRoot%\\System32\\netplwiz.exe" + +[HKEY_CLASSES_ROOT\CLSID\{98641F47-8C25-4936-BEE4-C2CE1298969D}\Shell\Open\command] +@="netplwiz.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{98641F47-8C25-4936-BEE4-C2CE1298969D}] +@="Add Advanced User Accounts to Control Panel" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}] +@="WinColor" +"InfoTip"="Change the color of your taskbar, window borders, and Start menu" +"System.ApplicationName"="Microsoft.Personalization" +"System.ControlPanel.Category"=dword:00000001 +"System.Software.TasksFileUrl"="Internal" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}\DefaultIcon] +@="%SystemRoot%\\System32\\imageres.dll,-197" + +[HKEY_CLASSES_ROOT\CLSID\{106ee807-9e5d-451b-a9c5-74908630cefb}\Shell\Open\command] +@="explorer shell:::{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921} -Microsoft.Personalization\\pageColorization" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{106ee807-9e5d-451b-a9c5-74908630cefb}] +@="Color and Appearance" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}] +@=" Disk Manager" +"InfoTip"="Create and format hard disk partitions" +"System.ControlPanel.Category"="2" +"System.ControlPanel.EnableInSafeMode"="3" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}\DefaultIcon] +@="%WinDir%\\System32\\dmdskres.dll,-344" + +[HKEY_CLASSES_ROOT\CLSID\{403ac161-c813-4819-b37f-3aacf0e12e0e}\Shell\Open\command] + @="mmc.exe diskmgmt.msc" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{403ac161-c813-4819-b37f-3aacf0e12e0e}] +@="Disk Management" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}] +@="GOD Module" +"InfoTip"="All Control Panel items in a single view" +"System.ControlPanel.Category"="5" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}\DefaultIcon] +@="%SystemRoot%\\System32\\imageres.dll,-27" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E91B00A7-97F2-4934-B06A-101C194D2333}\Shell\Open\Command] +@="explorer.exe shell:::{ED7BA470-8E54-465E-825C-99712043E01C}" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{E91B00A7-97F2-4934-B06A-101C194D2333}] +@="All Tasks" + + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}] +@="GroupPolicy" +"InfoTip"="Starts the Local Group Policy Editor" +"System.ControlPanel.Category"="5" + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}\DefaultIcon] +@="%SYSTEMROOT%\\System32\\gpedit.dll" + +[HKEY_CLASSES_ROOT\CLSID\{1695E87D-8BC9-4803-A701-D812E7C55223}\Shell\Open\Command] +@=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\ + 00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,6d,00,6d,00,\ + 63,00,2e,00,65,00,78,00,65,00,20,00,25,00,53,00,79,00,73,00,74,00,65,00,6d,\ + 00,52,00,6f,00,6f,00,74,00,25,00,5c,00,73,00,79,00,73,00,74,00,65,00,6d,00,\ + 33,00,32,00,5c,00,67,00,70,00,65,00,64,00,69,00,74,00,2e,00,6d,00,73,00,63,\ + 00,00,00 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{1695E87D-8BC9-4803-A701-D812E7C55223}] +@="Local Group Policy Editor" + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}] +@="System Configuration" +"InfoTip"="Perform advanced troubleshooting and system configuration" +"System.ControlPanel.Category"="5" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}\DefaultIcon] +@="msconfig.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}\Shell\Open\Command] +@="msconfig.exe" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel\NameSpace\{134797C7-95FB-4FD7-A8C7-067C1B1A2C71}] +@="System Configuration" + +;041. Windows Error Reporting + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"DoReport"=dword:00000000 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 +"OobeCompleted"=dword:00000001 + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\Windows Error Reporting] +"Disabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"DoReport"=dword:00000000 +"AutoApproveOSDumps"=dword:00000000 +"ConfigureArchive"=dword:00000000 +"DisableArchive"=dword:00000001 +"DontSendAdditionalData"=dword:00000001 +"LoggingDisabled"=dword:00000001 +"DontShowUI"=dword:00000001 +"BypassDataThrottling"=dword:00000000 +"OobeCompleted"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\Software\WOW6432Node\Microsoft\PCHealth\ErrorReporting] +"ShowUI"=dword:00000000 +"DoReport"=dword:00000000 + + + +;042. AppCompat + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\AppCompat] +"VDMDisallowed"=dword:00000001 +"DisableEngine"=dword:00000001 +"AITEnable"=dword:00000000 +"DisableInventory"=dword:00000001 +"DisablePCA"=dword:00000001 +"DisableUAR"=dword:00000001 +"SbEnable"=dword:00000000 +"AllowTelemetry"=dword:00000000 + +;043. Codecs + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows Media Foundation] +"EnableFrameServerMode"=dword:00000000 + +;044. More Optimization + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\AppHost] +"EnableWebContentEvaluation"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Avalon.Graphics] +"DisableHWAcceleration"=dword:00000000 +"MaxMultisampleSize"=dword:00000000 +"UseReferenceRasterizer"=dword:00000000 + + +[HKEY_CURRENT_USER\Control Panel\PowerCfg] +"CurrentPowerPolicy"="4" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters] +"IRPStackSize"=dword:00000032 +"AutoShareWks"=dword:00000000 +"DisableCompression"=dword:00000001 +"EnableAuthenticateUserSharing"=dword:00000000 +"ServiceDllUnloadOnStop"=dword:00000001 +"autodisconnect"=dword:0000000f +"enablesecuritysignature"=dword:00000000 +"requiresecuritysignature"=dword:00000000 +"restrictnullsessaccess"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\MicrosoftEdge\Main] +"AllowPrelaunch"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nsi\{eb004a03-9b1a-11d4-9123-0050047759bc}\0] +"0200"=hex:00,00,00,00,01,00,00,07,00,00,00,00,00,00,00,00,1e,00,00,00,00,00,\ + 00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,ff,\ + 00,ff,00,ff,ff,00,00,00,00,00,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00,\ + ff,ff,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 +"1700"=hex:00,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,00,00,00,00,00,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + 00,ff,00,ff,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ + ff,00,00,00,ff,ff,ff,ff,00,00,00,00,00,00,00,00 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB] +"AllowIdleIrpInD3"=dword:00000000 +"EnhancedPowerManagementEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\USBXHCI\Parameters\Wdf] +"NoExtraBufferRoom"=dword:00000001 + + +;045. PSCHED + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched] +"TimerResolution"=dword:00000001 +"MaxOutstandingSends"=dword:00000000 +"NonBestEffortLimit"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\DiffservByteMappingConforming] +"ServiceTypeGuaranteed"=dword:0000002e +"ServiceTypeNetworkControl"=dword:00000038 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\DiffservByteMappingNonConforming] +"ServiceTypeGuaranteed"=dword:0000002e +"ServiceTypeNetworkControl"=dword:00000038 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Psched\UserPriorityMapping] +"ServiceTypeGuaranteed"=dword:00000005 +"ServiceTypeNetworkControl"=dword:00000007 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Power] +"SleepStudyDisabled"=dword:00000001 + + + +;046. Notification Setting + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WpnUserService] +"Start"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ModuleLogging] +"EnableModuleLogging"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\PowerShell\ScriptBlockLogging] +"EnableScriptBlockLogging"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings] +"NOC_GLOBAL_SETTING_ALLOW_CRITICAL_TOASTS_ABOVE_LOCK"=dword:00000000 +"NOC_GLOBAL_SETTING_ALLOW_NOTIFICATION_SOUND"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\windows.immersivecontrolpanel_cw5n1h2txyewy!microsoft.windows.immersivecontrolpanel] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.AutoPlay] +"Enabled"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.SecurityAndMaintenance] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.StartupApp] +"Enabled"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\PushNotifications] +"NoToastApplicationNotification"=dword:00000000 +"NoToastApplicationNotificationOnLockScreen"=dword:00000001 + +;047. Search Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Search] +"CortanaEnabled"=dword:00000000 +"AnyAboveLockAppsActive"=dword:00000000 +"BingSearchEnabled"=dword:00000000 +"CortanaCapabilities"=dword:00000000 +"CortanaCapabilityFlags"=dword:00000000 +"CortanaConsent"=dword:00000000 +"CortanaInAmbientMode"=dword:00000000 +"DeviceHistoryEnabled"=dword:00000000 +"HasAboveLockTips"=dword:00000000 +"IsAssignedAccess"=dword:00000000 +"IsMicrophoneAvailable"=dword:00000000 +"IsWindowsHelloActive"=dword:00000000 +"Start_TrackDocs"=dword:00000000 +"Start_TrackProgs"=dword:00000000 +"CanCortanaBeEnabled"=dword:00000000 +"DisableSearchBoxSuggestions"=dword:00000001 +"SearchboxTaskbarMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search] +"PreventIndexOnBattery"=dword:00000001 +"PreventIndex"=dword:00000001 +"DisableRemovableDriveIndexing"=dword:00000001 +"DisableWebSearch"=dword:00000001 +"ConnectedSearchUseWeb"=dword:00000000 +"ConnectedSearchUseWebOverMeteredConnections"=dword:00000000 +"AllowCortana"=dword:00000000 +"BingSearchEnabled"=dword:00000000 +"AllowCloudSearch"=dword:00000000 +"BackgroundAppGlobalToggle"=dword:00000000 + +;048. Cloud Content.. + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CloudContent] +"ConfigureWindowsSpotlight"=dword:00000002 +"IncludeEnterpriseSpotlight"=dword:00000000 +"DisableWindowsSpotlightFeatures"=dword:00000001 +"DisableWindowsSpotlightWindowsWelcomeExperience"=dword:00000001 +"DisableWindowsSpotlightOnActionCenter"=dword:00000001 +"DisableWindowsSpotlightOnSettings"=dword:00000001 +"DisableThirdPartySuggestions"=dword:00000001 +"DisableTailoredExperiencesWithDiagnosticData"=dword:00000001 +"DisableWindowsConsumerFeatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\PushNotifications] +"NoCloudApplicationNotification"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History] +"DaysToKeep"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] +"LowRiskFileTypes"=".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.msu;.wav;" + +;049. Crash on Ctrl+Scroll + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\i8042prt\Parameters] +"CrashOnCtrlScroll"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kbdhid\Parameters] +"CrashOnCtrlScroll"=dword:00000001 + +;050. Touch Latency + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\TouchPrediction] +"Latency"=dword:00000001 +"SampleTime"=dword:00000001 +"UseHWTimeStamp"=dword:00000001 + + +;051. Windows Explorer + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Feeds] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DataSharing] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing] + + +[HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"GreyMSIAds"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System] +"AllowCrossDeviceClipboard"=dword:00000000 +"DisableAcrylicBackgroundOnLogon"=dword:00000001 +"AllowClipboardHistory"=dword:00000000 +"EnableSmartScreen"=dword:00000000 +"EnableFontProviders"=dword:00000001 +"DisableHHDEP"=dword:00000001 +"DisableForceUnload"=dword:00000001 +"SlowLinkDetectEnabled"=dword:00000000 +"DeleteRoamingCache"=dword:00000001 +"CompatibleRUPSecurity"=dword:00000001 +"AllowBlockingAppsAtShutdown"=dword:00000001 +"AllowClipboardHistory"=dword:00000000 +"EnableActivityFeed"=dword:00000000 +"PublishUserActivities"=dword:00000000 +"UploadUserActivities"=dword:00000000 +"DisableLockScreenAppNotifications"=dword:00000001 +"RSoPLogging"=dword:00000000 +"DisableForceUnload"=dword:00000001 +"EnableSmartScreen"=dword:00000000 +"EnableMmx"=dword:00000000 +"EnableCdp"=dword:00000000 +"AllowBlockingAppsAtShutdown"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes] +"ThemeChangesMousePointers"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU] +"NoAutoUpdate"=dword:00000001 +"EnableFeaturedSoftware"=dword:00000000 +"IncludeRecommendedUpdates"=dword:00000000 +"UseUpdateClassPolicySource"=dword:00000001 +"NoAUShutdownOption"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\Local] +"WCMPresent"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WcmSvc\GroupPolicy] +"fDisablePowerManagement"=dword:00000001 +"fSoftDisconnectConnections"=dword:00000000 +"fMinimizeConnections"=dword:00000000 + +[HKEY_CURRENT_USER\Control Panel\Mouse] +"MouseHoverTime"="1" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\FindMyDevice] +"AllowFindMyDevice"=dword:00000000 +"LocationSyncEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NvCache] +"OptimizeBootAndResume"=dword:00000000 +"EnablePowerModeState"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{0DA965DC-8FCF-4c0b-8EFE-8DD5E7BC959A}\{7E01ADEF-81E6-4e1b-8075-56F373584694}\{F6CC25DF-6E8F-4cf8-A242-B1343F565884}\{BDB3AF7A-F67E-4d1e-945D-E2790352BE0A}] +@="{db57eb61-1aa2-4906-9396-23e8b8024c32}" +"Operator"=dword:00000002 +"Type"=dword:0000103d +"Value"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Power\Profile\Events\{54533251-82be-4824-96c1-47b60b740d00}\{0DA965DC-8FCF-4c0b-8EFE-8DD5E7BC959A}\{7E01ADEF-81E6-4e1b-8075-56F373584694}\{F6CC25DF-6E8F-4cf8-A242-B1343F565884}\{CD9230EE-218E-44b9-8AE5-EE7AA5DAD08F}] +@="{db57eb61-1aa2-4906-9396-23e8b8024c32}" +"Operator"=dword:00000002 +"Type"=dword:0000100a +"Value"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\EdgeUI] +"DisableMFUTracking"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule] +"DisableRpcOverTcp"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client] +"ShowShutdownDialog"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WlanSvc\AnqpCache] +"OsuRegistrationStatus"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Control Panel\Desktop] +"ScreenSaveActive"="0" +"EnablePerProcessSystemDPI"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EnhancedStorageDevices] +"TCGSecurityActivationDisabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\PreviousVersions] +"DisableLocalPage"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] +"SystemRestorePointCreationFrequency"=dword:00000000 + +[HKEY_CLASSES_ROOT\SystemFileAssociations\image] +"Treatment"=dword:00000000 + +[HKEY_CLASSES_ROOT\SystemFileAssociations\video] +"Treatment"=dword:00000000 + +;052. Windows Store Apps + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsStore] +"AutoDownload"=dword:00000002 + + +;053. IE + + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Security] +"DisableSecuritySettingsCheck"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Security] +"DisableSecuritySettingsCheck"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\SQM] +"DisableCustomerImprovementProgram"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions] +"NoHelpItemSendFeedback"=dword:00000001 +"NoHelpItemTipOfTheDay"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"HideNewEdgeButton"=dword:00000001 + + +;054. Realtek Bluetooth Latency + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\BTHLEDevice\{00001812-0000-1000-8000-00805f9b34fb}_Dev_VID&02046d_PID&b34f_REV&0021_ff773a4381ed\9&1d91d97b&0&0021\Device Parameters] +"RetainWWIrpWhenDeviceAbsent"=dword:00000001 +"HighDutyCycleScanWindow"=dword:00000012 +"HighDutyCycleScanInterval"=dword:00000024 +"LowDutyCycleScanWindow"=dword:00000012 +"LowDutyCycleScanInterval"=dword:00000400 +"LinkSupervisionTimeout"=dword:0000000c +"ConnectionLatency"=dword:00000001 +"ConnectionIntervalMin"=dword:00000001 +"ConnectionIntervalMax"=dword:00000001 + +;055. UAC + Virtualization 2 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System] +"ConsentPromptBehaviorAdmin"=dword:00000000 +"ConsentPromptBehaviorUser"=dword:00000000 +"DSCAutomationHostEnabled"=dword:00000000 +"EnableCursorSuppression"=dword:00000000 +"EnableInstallerDetection"=dword:00000000 +"EnableLUA"=dword:00000000 +"EnableSecureUIAPaths"=dword:00000000 +"EnableUIADesktopToggle"=dword:00000000 +"EnableUwpStartupTasks"=dword:00000000 +"EnableVirtualization"=dword:00000000 +"PromptOnSecureDesktop"=dword:00000000 +"scforceoption"=dword:00000000 +"shutdownwithoutlogon"=dword:00000001 +"undockwithoutlogon"=dword:00000001 +"NoInternetOpenWith"=dword:00000001 +"EnableFirstLogonAnimation"=dword:00000000 + + +;056.Notepad Tweaks + +[HKEY_CURRENT_USER\Software\Microsoft\Notepad] +"StatusBar"=dword:00000001 +"fWrap"=dword:00000001 +"fSavePageSettings"=dword:00000001 +"fSaveWindowPositions"=dword:00000001 +"fWindowsOnlyEOL"=dword:00000000 +"fPasteOriginalEOL"=dword:00000001 + +[HKEY_CLASSES_ROOT\*\shell\Open with Notepad] +"Icon"="notepad.exe,-2" + +[HKEY_CLASSES_ROOT\*\shell\Open with Notepad\command] +@="notepad.exe %1" + + +;057. MRT Tool + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\MRT] +"DontOfferThroughWUAU"=dword:00000001 +"DontReportInfectionInformation"=dword:00000001 +"DoNotShowFeedbackNotifications"=dword:00000001 + + +;058. USB Flags + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\usbflags] +"fid_D1Latency"=dword:00000001 +"fid_D2Latency"=dword:00000001 +"fid_D3Latency"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced] +"UseOLEDTaskbarTransparency"=- +"EncryptionContextMenu"=dword:00000000 +"HideFileExt"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Explorer] +"HidePeopleBar"=dword:00000001 +"NoUseStoreOpenWith"=dword:00000001 +"DisableSearchBoxSuggestions"=dword:00000001 +"NoPinningStoreToTaskbar"=dword:00000000 +"NoWindowMinimizingShortcuts"=dword:00000001 +"NoDataExecutionPrevention"=dword:00000001 +"NoHeapTerminationOnCorruption"=dword:00000001 +"NoNewAppAlert"=dword:00000001 +"DisableContextMenusInStart"=dword:00000000 +"HideRecentlyAddedApps"=dword:00000001 +"ShowOrHideMostUsedApps"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\IPMI] +"BusyWaitPeriod"=dword:000000001 +"BusyWaitTimeoutPeriod"=dword:00000001 +"CommandWaitTimeoutPeriod"=dword:00000001 +"IpmbWaitTimeoutPeriod"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF] +"LogEnable"=dword:00000000 +"LogLevel"=dword:00000000 + +;059. Windows Installer Service in Safe Mode + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer] +@="Service" + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer] +@="Service" + +[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings] +"SyncMode5"=dword:00000003 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings] +"SyncMode5"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"DEPOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\QoS] +"Tcp Autotuning Level"="Experimental" +"Application DSCP Marking Request"="Allowed" + +;060.Icon Set + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Icons] +"29"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 +"77"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 +"179"=hex(2):22,00,43,00,3a,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,73,00,\ + 5c,00,42,00,6c,00,61,00,6e,00,6b,00,2e,00,69,00,63,00,6f,00,22,00,00,00 + +;061. iSCSI Optimization + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\iSCSI] +"ChangeIQNName"=dword:00000001 +"RestrictAdditionalLogins"=dword:00000001 +"ChangeCHAPSecret"=dword:00000001 +"RequireIPSec"=dword:00000001 +"RequireMutualCHAP"=dword:00000001 +"RequireOneWayCHAP"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Policies\Microsoft\WindowsMediaPlayer] +"PreventCodecDownload"=dword:00000001 + +;062.File History + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\FileHistory] +"Disabled"=dword:00000001 + + +;063. End + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\MobilityCenter] +"NoMobilityCenter"=dword:00000001 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Themes] +"ThemeChangesMousePointers"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RasMan\Parameters\Config\VpnCostedNetworkSettings] +"NoRoamingNetwork"=dword:00000001 +"NoCostedNetwork"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\Maintenance] +"MaintenanceDisabled"=dword:00000001 +"WakeUp"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\StorageHealth] +"AllowDiskHealthModelUpdates"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\StorageSense] +"AllowStorageSenseGlobal"=dword:00000000 +"AllowStorageSenseTemporaryFilesCleanup"=dword:00000000 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Maps] +"AutoDownloadAndUpdateMapData"=dword:00000000 +"AllowUntriggeredNetworkTrafficOnSettingsPage"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Messaging] +"AllowMessageSync"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\NetCache] +"SyncAtLogon"=dword:00000000 +"SyncAtLogoff"=dword:00000000 +"SyncEnabledForCostedNetwork"=dword:00000000 +"EconomicalAdminPinning"=dword:00000000 +"NoReminders"=dword:00000001 +"NoMakeAvailableOffline"=dword:00000001 +"NoCacheViewer"=dword:00000001 +"NoConfigCache"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Network Connections] +"NC_PersonalFirewallConfig"=dword:00000000 +"NC_DoNotShowLocalOnlyIcon"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NDIS\Parameters] +"TrackNblOwner"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Installer] +"DisableLoggingFromPackage"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate] +"DoNotUpdateToEdgeWithChromium"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\OOBE] +"DisablePrivacyExperience"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HomeGroup] +"DisableHomeGroup"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\HotspotAuthentication] +"Enabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole] +"DefaultLaunchPermission"=- +"EnableDCOM"="N" +"LegacyImpersonationLevel"=dword:00000002 +"MachineAccessRestriction"=- +"MachineLaunchRestriction"=- + +;064. WCN Registrator + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WCN\UI] +"DisableWcnUi"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WCN\Registrars] +"EnableRegistrars"=dword:00000000 +"DisableUPnPRegistrar"=dword:00000000 +"DisableInBand802DOT11Registrar"=dword:00000000 +"DisableFlashConfigRegistrar"=dword:00000000 +"DisableWPDRegistrar"=dword:00000000 + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Attachments] +"SaveZoneInformation"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\Terminal Services] +"fAllowToGetHelp"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service] +"AllowUnencryptedTraffic"=dword:00000000 + +;065. Sandbox Tweaks + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Sandbox] +"AllowVideoInput"=dword:00000001 +"AllowVGPU"=dword:00000000 +"AllowPrinterRedirection"=dword:00000000 +"AllowNetworking"=dword:00000000 +"AllowClipboardRedirection"=dword:00000001 +"AllowAudioInput"=dword:00000001 + + +;066. Event log + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest] +"UseLogonCredential"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\Kerberos\Parameters] +"SupportedEncryptionTypes"=dword:7ffffff8 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EdgeUI] +"DisableMFUTracking"=dword:00000001 +"DisableHelpSticker"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EventLog\ProtectedEventLogging] +"EnableProtectedEventLogging"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\EventLog\Setup] +"Enabled"="0" + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\fssProv] +"EncryptProtocol"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WDI\{affc81e2-612a-4f70-6fb2-916ff5c7e3f8}] +"ScenarioExecutionEnabled"=dword:00000000 +"EnabledScenarioExecutionLevel"=dword:00000000 + +;067. Your Phone API + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Messenger\Client] +"PreventAutoRun"=dword:00000001 +"CEIP"=dword:00000002 + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\ms-phone-api] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\tbauth] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\windows.tbauth] + +[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\AppServiceProtocols\windows.yourphone.api] + + +;068 ! (reveu 063, 065 si 067) + + +[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download] +"CheckExeSignatures"="no" +"RunInvalidSignatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MdmCommon\SettingValues] +"LocationSyncEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\LanmanWorkstation] +"AllowOfflineFilesforCAShares"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\Maps] +"AutoUpdateEnabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge] +"TrackingPrevention"=dword:00000003 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\ScheduledDiagnostics] +"EnabledExecution"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\usbhub\hubg] +"DisableOnSoftRemove"=dword:00000001 + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers] +"authenticodeenabled"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\SettingSync] +"DisableSettingSync"=dword:00000002 +"DisableSettingSyncUserOverride"=dword:00000001 + +[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\BackgroundAccessApplications] +"GlobalUserDisabled"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppPrivacy] +"LetAppsRunInBackground"=dword:00000002 + +;070. Delivery Optimization Disable + + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Settings] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\DeliveryOptimization] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DeliveryOptimization\Config] +"DownloadMode"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Main] +"DEPOff"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\NVDisplay.ContainerLocalSystem\LocalSystem\NvcDispCorePlugin] +"DisableLoad"=dword:00000001 +"LogFile"="-" +"LogLevel"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Reliability Analysis\WMI] +"WMIEnable"=dword:00000000 + +;070. Remove ControlPanel and Settings Applets + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] +"NoRemoteRecursiveEvents"=dword:00000001 +"DisableThumbnails"=- +"MemCheckBoxInRunDlg"=dword:00000001 +"NoInstrumentation"=dword:00000001 +"ConfirmFileDelete"=dword:00000000 +"AllowOnlineTips"=dword:00000000 +"NoRemoteRecursiveEvents"=dword:00000001 +"StartMenuFavorites"=dword:00000000 +"Start_ShowHelp"=dword:00000000 +"Start_ShowMyComputer"=dword:00000001 +"Start_ShowRun"=dword:00000001 +"SettingsPageVisibility"="hide:quiethours;tabletmode;multitasking;project;crossdevice;clipboard;remotedesktop;typing;pen;autoplay;;mobile-devices;network-dialup;network-directaccess;maps;appsforwebsites;videoplayback;startupapps;sync;speech;gaming-gamebar;gaming-gamedvr;gaming-broadcasting;gaming-gamemode;;search-permissions;cortana-windowssearch;search-moredetails;privacy;privacy-speech;privacy-speechtyping;privacy-feedback;privacy-activityhistory;privacy-location;privacy-voiceactivation;privacy-notifications;privacy-accountinfo;privacy-contacts;privacy-calendar;privacy-callhistory;privacy-email;privacy-eyetracker;privacy-tasks;privacy-messaging;privacy-radios;privacy-customdevices;privacy-backgroundapps;privacy-appdiagnostics;privacy-automaticfiledownloads;privacy-documents;privacy-pictures;privacy-documents;privacy-broadfilesystemaccess;delivery-optimization;windowsdefender;backup;troubleshoot;findmydevice;;holographic-audio;privacy-holographic-environment;holographic-headset;holographic-management;" + + +[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl] +"1"="Microsoft.ProgramsAndFeatures" +"2"="Microsoft.DefaultPrograms" +"3"="Microsoft.StorageSpaces" +"4"="Microsoft.FileHistory" +"5"="Microsoft.ActionCenter" +"6"="Microsoft.DateAndTime" +"7"="Microsoft.SpeechRecognition" +"8"="Microsoft.EaseOfAccessCenter" +"9"="Microsoft.DevicesAndPrinters" +"10"="Microsoft.PenAndTouch" +"11"="Microsoft.AutoPlay" +"12"="Microsoft.MobilityCenter" +"13"="Microsoft.Taskbar" +"14"="Microsoft.TextToSpeech" +"15"="Microsoft.Troubleshooting" +"16"="Microsoft.SyncCenter" +"17"="Microsoft.Keyboard" +"18"="Microsoft.Mouse" +"19"="Microsoft.Personalization" +"20"="Microsoft.TabletPCSettings" +"21"="Microsoft.System" +"22"="Microsoft.AdministrativeTools" +"23"="Microsoft.CredentialManager" +"24"="Microsoft.PhoneAndModem" +"25"="Microsoft.RemoteAppAndDesktopConnections" + +;071. Adobe Acrobat Reader + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown] +"bAcroSuppressUpsell"=dword:00000001 +"bDisablePDFHandlerSwitching"=dword:00000001 +"bDisableTrustedFolders"=dword:00000001 +"bDisableTrustedSites"=dword:00000001 +"bEnableFlash"=dword:00000000 +"bEnhancedSecurityInBrowser"=dword:00000001 +"bEnhancedSecurityStandalone"=dword:00000001 +"bProtectedMode"=dword:00000001 +"iFileAttachmentPerms"=dword:00000001 +"iProtectedView"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cCloud] +"bAdobeSendPluginToggle"=dword:00000001 + +[HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\DC\Installer] +"DisableMaintenance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cDefaultLaunchURLPerms] +"iURLPerms"=dword:00000003 +"iUnknownURLPerms"=dword:00000002 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cServices] +"bToggleAdobeDocumentServices"=dword:00000001 +"bToggleAdobeSign"=dword:00000001 +"bTogglePrefsSync"=dword:00000001 +"bToggleWebConnectors"=dword:00000001 +"bUpdater"=dword:00000000 + +[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Adobe\Acrobat Reader\DC\Installer] +"DisableMaintenance"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cSharePoint] +"bDisableSharePointFeatures"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWebmailProfiles] +"bDisableWebmail"=dword:00000001 + +[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\DC\FeatureLockDown\cWelcomeScreen] +"bShowWelcomeScreen"=dword:00000000 + +;072. intel CPU Tweak + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\intelppm\Parameters] +"AcpiFirmwareWatchDog"=dword:00000000 +"AmliWatchdogAction"=dword:00000000 +"AmliWatchdogTimeout"=dword:00000001 +"WatchdogTimeout"=dword:00000001 + + + +;073. WinLogon + +[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] +"EnableFirstLogonAnimation"=dword:00000000 +"AutoRestartShell"=dword:00000001 + + +;074. Firewall Rules + + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] +"{1A6BFAD8-BA8C-4474-8E25-C9DB3D46523F}"="v2.31|Action=Allow|Active=TRUE|Dir=In|Protocol=6|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow TCP IN|EmbedCtxt=Fingerprint Unlock Module|" +"{A2D1CA01-D51F-4E64-9229-3D56A29D0D5C}"="v2.31|Action=Allow|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow TCP OUT|EmbedCtxt=Fingerprint Unlock Module|" +"{64C4F529-DB31-425A-BA71-FBA3C881ADDC}"="v2.31|Action=Allow|Active=TRUE|Dir=In|Protocol=17|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow UDP IN|EmbedCtxt=Fingerprint Unlock Module|" +"{AA2CBA97-F20A-4A2B-98D0-6D1F84A6984D}"="v2.31|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|App=C:\\Windows\\system32\\LogonUI.exe|Name=Logon UI - Allow UDP OUT|EmbedCtxt=Fingerprint Unlock Module|" +"{ADEDD497-D9EB-4573-B73F-86C68AA3F377}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{6139A3AA-99A5-491F-843C-E343C83226F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{8DFBCF37-3975-4054-939D-280B80AC6E86}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{E4D61D8A-D28E-43BC-BA9F-B5E0138266AB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{E7763690-64E1-4AE6-92F6-2A0D87D372A0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{6AEC363C-0E0E-4041-ADC8-0B47ED7EF74E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{1ABEA816-DF00-4EC6-897D-D6BCB81779F8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{FBBDCD38-3A64-4C43-B4A6-C1F40A2AC511}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{D3BA6B7E-E614-49A5-AFE9-454EAD516B02}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{1FB7E5CC-1994-459D-BB57-C8CEA982B76C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{26FEAEAE-8808-4FCC-B50B-CA02A1F047C7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{25344817-661E-4748-932A-118CA38A025D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{7E32EF31-E1D6-4E7E-8D58-5035C9C491CB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{6DA9BD19-8492-4D26-A7AF-4B860CA20C61}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{3651797E-8F96-4813-AD2E-460ADF002D00}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D0C84C00-07C1-4D6D-9B55-CA2BD5DF88EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{05029DD4-6EF0-49FE-A265-C513E5A7DF9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{37D599B3-186C-40CB-B5C8-571F21AA33A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{A0CBF3AC-8C34-49AB-B202-35B0B22FEF88}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{1E803FB5-8410-42E3-843A-81C9874C7F16}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{3C642422-BC3E-4ACD-B7F0-873BACFE49B3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{2BCD3201-BC30-4F7F-81B2-45F59FCE9E52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F9AF067C-4A5E-4E27-886B-7BA01D57288C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{C89EFE6C-D514-483F-8608-799F1D11A309}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{2B50A864-E362-413F-B5FE-968D1D245132}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{2B58C6EB-1517-4EBB-BEA1-5E6B73FB7CF2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{451DCB00-92D3-4E01-8887-C462B74403B8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{57A0B1B2-EF30-4D6C-9FB7-D00CA393076A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{5691EAC0-5F14-4408-8652-46DD343F9238}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{F9B9EC52-6807-4987-988F-498859D5DFE7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{385551D0-2252-4C36-A349-0F6EA655235D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{F84AC383-9EEA-416A-8DC8-F3B62A46F92F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{29184E50-2741-444E-91DA-CF486FA362A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{52105157-D0B0-4863-BA19-D0DFD3054F32}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{EF7399D0-D073-4059-9717-D7F70605DBEE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{4AD5E10F-12E7-4875-9397-2205503D6255}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{3EB9C4E5-BF5C-4E42-8EBE-D88BCBB59FC5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{1B714C6D-DAA5-4277-93EC-092C2AF6D3F0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{CE039632-AD10-4BC5-A7C2-04EEB8F1970B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{75785327-A85E-422E-960A-823B6043C8A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{00F392E1-684A-4B57-8D28-AFD1AF3A33D6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{BD4B74D4-3CC4-46A7-B2CC-CD786CBE2408}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{58A67B88-585B-4E41-B914-140E95345797}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4A97C06B-7032-40B2-BA73-B05CB9B89624}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{82F59B86-B68D-4AF6-A05A-5DB6CBCFCFDD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{EF8FB5D4-A7B0-4642-81C7-AE744D4CB526}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D8463C28-4598-4C25-94C4-7E91E059411B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{94742D91-C3AB-4EFB-A3CF-3E9001D09065}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{0B5EA8E4-2904-4397-9062-B2E62D18D94F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{7EEA5128-2E77-429A-AAA0-1DCE104EA2CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{B5222588-9C53-4CA5-ADB1-5463F5BB381A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{EED9D903-BE0E-49E1-9063-58DD50FE876B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{9BA3B229-DBAA-46C7-B6A0-9C83F159DF70}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{B8CB1011-3DA3-4608-8386-DE12D17669CC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{8791D9AD-53E3-4633-B1A0-7E5433CA2875}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{F9D7DD31-D683-4DE6-A800-A123A39C4BC7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{A41CE4B9-FF56-4D7E-B7BD-124CF5A8A3F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{97A9560C-CED7-449F-B079-08E62B51BD6F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{913BA024-8698-4F60-8C7E-8F5D064242C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{AD537B18-7F52-441C-9D66-CE40DD60DD60}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{9F6C7D64-5F24-40BF-878E-5457D7D7FBCC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{BCE469CF-5FE3-402A-B5B2-3F5D3F312E05}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{F5583B4E-B7F0-4067-8482-998393C95021}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{9B963A37-0068-4A90-8C95-795DBA0D7A16}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{1D787C2A-20A0-4BB6-83D4-2B608D44A651}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{1CE30DC2-EF9A-4249-8421-E74F20FBEAE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{EB3728FE-D673-4B46-9C92-EB1753836C78}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{C8579BB8-4A1B-4D38-95A8-10B2DDBAD0AA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{A5443D36-6407-4A5C-9C26-F849B53800D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D283E223-E9FC-425E-8AD6-A33BAA9478E0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{3541E389-7992-4DB5-ABB1-A28F480FEFAA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{D9A3D2C6-1C0E-48A2-80D7-9282DDEED833}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{F3226711-34BE-411C-8EB6-1B53F1335D12}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{F9C956B0-5D4D-4761-BE5B-9331F57103A6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{5618F44B-E606-4B5E-B4E6-B5DF4F7A39E4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{221B7B28-499B-4113-865A-023E629A2665}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{477E4F55-3DBA-443A-8E26-1BF01CAE6F10}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{E98A936E-FD56-43FB-B4AF-515C9DC49E28}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{F8292803-C899-46F1-B956-820F89B28717}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A9C34DC6-36A9-4A24-84EC-8E2ED3F10E78}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{47706A1F-014E-4567-93B2-07B6D78974C5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{04B25DAB-31BD-42A2-9110-F98202619486}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{65C7F1F9-6F89-4DF8-A853-DBE7F4494939}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{92013DA1-B7F2-4885-A334-402A12D1EB21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{3D7E67B0-BA2E-462A-9760-AE229FC4E1AF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{8E53E989-28F3-44D2-9837-4CBEA1EAD7FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{77C6580C-A3B4-42E4-8D1C-05B0FB6D788B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{D6144267-D624-45FC-B279-B13E49F47901}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{F87E0087-CF47-4310-B96D-83AC94DCAA21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{6046898F-4B34-4C7B-A2E9-7309DB33AFF9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{8A47685B-2CE1-4997-9010-842F5D9E4C10}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{ECB0F8CC-D20D-4E40-AF06-62794E084FBD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{956A255A-0A14-442E-B0E3-671852BB5F20}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{3B75B607-EE3A-47FD-9AE0-1989F2A1E9EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{96EA7030-070C-4A29-AF9F-5A9115A043C3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{5B553C76-0D9C-48C7-A659-DF0765FA33BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{7338396A-D104-45F7-807C-3F882D47394F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{9956434E-7003-4C4B-BCBA-ED7C3585E569}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{B1820254-717D-4011-ABEA-15BA6C578580}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{586048D2-3A85-4436-909D-6CD61404EA84}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{ED0F819A-1E21-49C5-AFB6-763E73B3751C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{E823ABA8-9DD5-4016-A405-02E863B3493D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{994B0AAA-69F0-45C3-B999-EB57F185FAF5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{B529D897-AA88-423A-B57B-5749F062679B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{44D615DF-EA26-45A2-8EA1-04903F524600}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{1D03F092-29D6-4025-8233-1F73692665B0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{0BC5A9C7-6AD2-491F-B34D-8012D59AB9C4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{74A8D3D8-5B4A-4285-8E67-BC79EDB5E22E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{76F33769-EE9C-41E4-A76A-99C0DF92FA28}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{923C619F-AF59-4DE2-AD90-60393B4FC253}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{5A55BE7A-ED8F-46F0-8E4E-F9818499EF6E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{C3580C2E-88A2-419C-A4BD-AF902E919376}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{CCAE9171-B2BF-487F-BFCE-E7C58021D327}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{9604DB6A-5F98-43FE-A57D-E02496D84F0B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{840110FD-C296-49DC-9E8C-F0FF7CF8D338}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{D816EF80-C794-4C32-A738-51454E094BE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{FFE5515C-A5A8-4601-AD1D-1BEC708655A0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{0D08E371-8CD1-4985-89CB-C3F532539931}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{84825376-38FF-43D7-80A6-5E137AE5A569}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{882909F6-40EC-41CF-944C-5EEBA66C9100}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{237C330E-8CA5-4886-83E4-E52F9250D777}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{602B88F3-EF51-41D7-A29A-D440509E4D2C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{54C24BC7-9347-4492-828F-7CF404D50E97}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{444806C9-54E0-4EB3-B29F-7CA1B7F76C17}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{1167EBFA-9095-46E4-B8F0-F4521B2A8D3F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{9A51CF52-8B27-4AFF-8D77-559637CEDC8B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{BB3B0896-276B-44A5-A601-1758E0D47278}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{B32F1CD4-AFB1-4634-9865-05BC344D728E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{98724BDF-7A04-4D5E-AB20-D5B290615B77}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{C800A94C-CF93-44C0-AE32-2A7B0DC9F2EC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{88524DF2-C0DE-4907-B8CC-294928A5EB44}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{18C7302B-58FC-4BAD-94E8-5E4FE08F514A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{BA617ECF-4367-4A99-A370-8F30618CB761}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{1F6BC906-CED4-4232-9A56-51DF78997488}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{5868933A-5A35-4F2F-95D1-7C1F63D311C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{419905C1-4BBB-4D38-84DA-68A6E4431DC1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{7BB8293E-1B33-4377-9AD7-CED99DF04A55}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{3DDEF07C-3614-4C97-8C3B-C4B63D732800}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{8321D4B2-FC5D-4A41-9B11-4E31C993623B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{396CD532-1AB6-462E-80E0-2360B128B998}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{445FC3F9-1647-498E-B89D-D0517369B313}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{18762016-25DA-480E-A31A-BE251DE4A663}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{830CA81E-AEE4-4F7A-BE20-1DD702F42E48}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{6350333A-2A8A-412A-B92B-4EEA2D7B15CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{F6A6EF37-7CAB-4772-8465-C824E049F228}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{4E5BCAEE-1D6A-44D5-9910-FCA06EB4D419}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{4CE2AF1D-897E-424A-AADB-A8F7F3E15D0D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{62EEAD21-7B97-4573-A842-901358A87FCA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{73C961E5-5B42-4D5F-8090-2D520503AC2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4C9597A8-ED5B-4FEE-AF1A-D5B7ACB556DF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{41C9FA3D-AFB3-4C4F-8172-E01D0E1F292F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{996040C7-C60C-471A-A3E9-9F402BB54DE5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{AD125FB1-2F9D-413D-AE8D-E3AA7B7D9C92}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{2A189D20-C0CE-4C3E-8BAD-40A0ABE593DB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{66282D57-7671-4E26-92AB-FBE05D599B0D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{4B333796-5ECE-427A-A270-A94A29D45D7B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{A49BFFBF-6B22-4CBB-905D-9388D0D8E853}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{51BCE67A-6A52-41D5-B819-17CF3E7A7FF9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{2F6D6151-F9B7-4A00-88FE-A6D7AF70DD33}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{970D64EB-EB84-41B1-912D-5B9492E048D2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{2292CC30-3D4F-412A-A7DA-C59F30FD7BD7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{B753A166-5A60-4D15-A8D4-94A79E2D21E3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{2BF836ED-A5ED-4A8E-9106-9E5D3D02737F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{A24D220C-73FF-4DE5-AE4F-1F26CBB25433}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{27A43AEF-27E7-4965-A3CE-C0B309D818D4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{38FF9317-D383-4628-8B75-C2E35469F09E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0D6131BC-DE8D-4B85-987F-56E0C7326CA7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{D42B1A61-42CB-4BA2-9009-DA96CF9B4D39}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{C66DD24F-9F54-4D64-8ABD-DC2C76FC35E2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{1FC41BD3-A102-4484-8567-82C5D99C618D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{D7158814-C472-4F55-B1E1-E783706EB61D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{0A2BA905-07F7-4E41-8C31-2BFF1ACC9818}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{F31B4288-3C78-44F7-BE6A-2C15B30CE308}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{1225F521-B194-4F12-85C7-B0850E58A4B5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{60DF971C-8FF1-4A26-B761-03DAAE2F9E23}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{5952EE95-EFA6-4CFA-BC4B-A3261668C66C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{DEED4512-FE7C-4DE1-B14A-CD122739C1AA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{3F16D408-79DE-4932-A23C-E915A6E2CC00}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{742E95EA-CC2C-43A4-8B8A-EB9E80B55FAE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{7E816C99-850F-426B-8022-EF18117F6D62}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{4EBCDADA-234A-47A2-B1CB-BC35BD16214B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{86C8D379-9E38-443C-8F51-0A0FA761FDAF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{8CD1C63A-3DE9-424D-BA6E-DE8A9494D340}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{C9A494A4-47C1-495A-8680-1AC853DF67B4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A76DC0F8-FCC7-4306-B39A-E177167D675A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{C2794317-6FD2-437C-A781-449C5400F19B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{1A62BFE4-2EB9-43D1-8D57-92A80AF054A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{9B12861A-54D3-4385-B12D-55AD087F80AC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{2CF3E5FB-3D2F-418B-B26E-C02D7D19C763}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{C1728706-D583-4CEF-A6D4-A4013FD07FD9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{85B7E324-FAAF-4846-914B-B1578FD2463D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{930E4CDF-0B9F-4A5B-851C-E9D22E92D0FF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{ED1333B0-A38D-4C62-BEC8-CB89847D40AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{84FDBCD6-0BF4-4557-8010-EA4954C3304D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{55567EBF-38CC-463F-A9C4-81ACEBB5AE3A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{4B897D2B-856C-4D4B-9BA6-421EE5DC6D87}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{087AF2AE-7159-46CD-95E7-DE3D8112EEE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{85F7EF93-965A-4D9A-AFEE-986EFBAD0D19}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{831447DC-C38B-4AB2-B09E-991556598ABC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{4970DDF1-D1EB-4450-B341-E4188360A9A2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{7ADFE507-30FB-42F0-8DB9-91D04E572DB6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{4B47C2E3-A030-42A4-B8A3-656A76355622}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{E3917AE8-6AD3-41C7-8E73-AA9E308D2E6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{806A68C9-159E-4800-A4F6-7E43157CAC7A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{25D05800-49CD-491F-A193-4F2B7904D5C2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D66BA010-3DCB-4213-89B3-0BCE4B9C31A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{E7A96B26-8C91-498F-99EA-4198C1AA3D5F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{06185A7C-CFCF-4F8B-A11E-A1A8C59241C6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{ADE50361-73ED-402A-BED0-D83CE73FE012}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{0720EDD9-C226-4619-9246-6ED175FE72E6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{45A6720C-90C8-4397-9822-D98E9DBC30F1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{DA92DE42-5811-470E-A116-336A0635EABE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{AB335667-3D21-4921-8524-61C58916A9AF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{59213E32-ABF6-4459-93AA-5B98576B4356}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{54115EBC-91E2-405B-AFAF-08FEF8C89ABD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{7BFA7B88-F361-47AB-82D8-0DC331D7A4C0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{32CB1C98-3F3F-4FB3-97AC-9C6C8052EB3A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{23FD16CF-C432-4158-BCB3-242368F23B01}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{24C576D0-C6AC-402E-A7B9-944EF9131666}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{62C8E5B2-0FBD-4B41-BED2-53CC4C915700}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{B9E323AF-A847-40A7-A2D2-E7E63181EDE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{ABEDF61E-B727-4090-8BFD-25B3F1E0B7FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{9975673F-813F-4503-97BB-E89AAD93C6BD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{7A5A3377-9F40-43C7-B7A3-C16CE651DD2D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{AC4151C0-BCA9-4800-85B0-46F9C3C0A5F7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{21315192-4267-490F-A99C-BE823B0CF38D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{2757E499-0A7A-41CB-BBF1-2F1ACF98CEA6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{A4ADAA4B-3BD7-4AA8-8446-5D3A3400F6A1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{AC3C0900-D66D-48CE-BD7C-0F8EBAAAB8E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{34C352A8-E57A-424C-8816-5C6D2C0A0FCC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{5EDF99BF-D5AB-49E3-B59C-C9CA40DA7049}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{E37D60EE-6DDC-4556-8A37-24C209E51A5F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{9BCEB768-1D44-47DC-8495-53480ECB1DC6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{0D0840F0-B77D-41D9-8C71-9DB86952D65E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{53D6BEE5-5883-489D-8E51-12AA49F727DE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{EB9D16ED-98FF-497D-B7CF-89E7EACDFD66}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{B9C32014-5270-4EBE-9570-FE54A3009FCA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{571CB96C-2F3E-4A3D-8EEE-BA85807E15A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{61B6B6BB-85E0-4FFE-B84F-4A7391CDA9E9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{44905744-600D-4B6B-92D3-B9E77CE55BF8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{836BA3D2-4B15-4961-8937-C6FA117DC1B3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{43E2C103-2856-4DAE-AFE6-F77E9BA662E7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{0A28D9A3-C1BF-407D-9EA5-46C23AB2561A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{63D99D74-FA6D-4DF4-BC49-B34D52C1DBC9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{4B946B93-E862-4975-9692-CD3E77F0B07B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{6AC91EFA-85B0-45B3-A51D-1F28461326AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{54453F96-53A4-4A0B-BAA5-ACE5F4685E80}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{5BB6228B-B0E1-41BE-8902-5124236D98D8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{09047D4A-9A01-416F-B7BA-681ABD5C785D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{6F5A9E1D-67D2-4709-BAB3-BC51DEAA0157}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{734F27DF-AF33-4083-9CE5-BE793E6ECD3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{877F399F-0DDF-4376-A079-401739E6E9B7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{736C5DED-45F3-43E7-BB0C-F3E675F0CC59}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{DA4EBA7E-84F6-4298-9351-AE6D3D71BF82}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{9110BA3B-2F0B-4518-8588-700443768238}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{6501C792-B8AA-40AE-89BB-4AF01CC698FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{EDF7CEC0-E4BE-4465-991A-52E5502E024C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{A716A6B1-F721-40A3-848B-2FDD326B3EE6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{039B198D-705E-49B3-9E3D-828B56FD59D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{F7162BAF-365F-4D5D-B271-5BD418F01975}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{7EAE5C3D-307B-462A-A858-EA0B594CE82B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{63B55664-E517-41AE-9F09-DFCBFF9AC504}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{CE52B9D1-5897-4F03-9018-5DCDC89EDC2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{BC8BFA97-1F9D-457A-BCF3-109534E78138}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{CB28C9A0-0A12-4F2D-83DC-72BF557F7FEF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{2B5B36AD-4AF6-434A-A1CF-416AFA0FA052}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{E8743456-58A6-48D5-A52E-403C70C6ECA2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{3D3774C7-82FD-4550-8234-E64978B556FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{0810CCDB-D870-4EF4-BDB3-389917F04E80}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{50A0D057-8D59-4043-826B-7B6EC25210C8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{7577A582-AD09-4B6D-B4B9-F15A8BE752DC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{428F75FB-A150-4C1F-9B88-C2AEFA2B3A84}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{AE1F4440-4039-4A5B-BA84-B33D3E67EAD0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0AEEE225-A289-48BE-B94E-BB445DF9A42E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{41D429AD-F908-4F95-BB4D-277783A8CC9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{A7DAD158-0F9E-4D00-9B49-A7B8BA331BF0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{DE9CE2F9-7A55-4500-909F-5BB366F374BF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{CEEEF407-DCDC-42EA-B6A4-264D4D4625E2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{0B98B4C7-39C1-4CF0-A4E5-6B372EBE071F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{911A2BBC-E15E-4222-8E23-466106BFB6A3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{2E0D7F15-6DBE-442E-881A-49EC18F614D9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{3FDD1303-5E7C-4402-8ACC-2ABDEED6E896}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{44869CA9-EB15-4A02-A008-D9DEE9567A3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{A329DBE3-8C51-4ECE-BCC3-BEA6B2E0EF97}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{85A7D7D1-4FFD-47C3-86C0-0F0EF2625C3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{27DA754C-5D39-4064-887E-88AA167F3260}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{34E149FD-E60A-4271-91E8-12D99BDB0976}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{CB781C8C-90EB-4DDE-8412-8536BC822384}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{023390C2-B321-43E9-8646-789858902107}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{2D85B4F9-2C3E-46EC-AF8A-FC3E1C862AD4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{BB1DA088-376C-4A7A-A5DA-B398F3E43CEB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{D8A6F997-5AA9-45AD-A3B5-57162AF354B4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{8D4FAF89-BCEC-4D7D-806F-D8638B75F26E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{4B269D81-79E5-470F-9567-1692900473BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{0E8FECED-2F14-4411-BD47-66D744198A07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{F1F6330E-A436-401C-9901-9366DFDBBBAA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{766BB2D7-2195-49FB-9A12-47217072423C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{613B658A-93ED-42DA-A805-4856BE8F09D7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{E8CC2A7E-B4A9-45C3-AC5E-4EA0B3D36DCF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{BF628C87-FFC6-41B3-914D-2F23FB3358BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{B3A2B215-AABD-42E3-A508-1D4D0FC77CCD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{48AF6C0E-92F6-44C3-ABCF-0299708BFCC0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{3D9F00A0-ED7B-46E9-B276-4E29971252A9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{15E652CB-3192-4815-862A-C638037BC8CF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{EBD18A9C-033C-4887-B2BD-CB460DB7B464}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{E2394666-7621-406A-86CD-15879139D22E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{BC4C1B01-03EA-4D93-B48A-A8ADACC4A5EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{13BF5504-C27F-46EA-9C52-415E342E2741}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{A900B289-6FD2-4833-A338-EB252FD7F16B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{0378E5CD-F0D4-4504-8A2D-6A825C04483A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{FF161DC3-5648-412C-80BF-9524551A9DBF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D94DDCEF-FF3E-4303-8F34-2ED2F926B712}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{3EC90262-3C8D-4E5F-8B48-33B579C6A2E1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{00A9B852-1B3B-4827-8A67-3FC043FEF4BA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{B64C51D2-17FF-4FAF-B9E1-E1023415406B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{8F3D470C-7132-4CEC-8308-0BB6745234A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{5123CE83-E233-49B6-989F-F4FDC19A090A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{672D504D-ADD9-4543-8A04-999325C53EDC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{B7335824-5F8D-4E3F-A5D2-FAEB3652B6F6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{E93E102F-08D0-424F-BDE4-2501D8B06630}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{05246B97-56B9-4EF3-A45F-CAB9234DD283}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{987E7F8C-FF0B-4331-872A-2F867D6B65A3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{8B08229B-38E4-4C00-BB4B-7C9A2809763C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{D1D54CB9-4FA2-44F4-B586-C5CCED80B5F4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{0E8EE5DA-A7E6-4DFC-A211-0E3826EBA949}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{0010D7F5-4065-4F68-9F81-5F9B83B56B52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{A471A1E9-EADA-449F-A126-EB56C9DE418C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{7EDFF1D1-6283-4E08-A3A2-47134A78B427}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{2A5982EE-EC73-4115-B344-A9448D92261C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{B5A6CF6A-72BB-4C39-9613-BC921768FFF5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{E8BF7E1A-E228-4B7D-AADF-EA022F64A255}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{FFCAC4AB-263F-4D27-8E1F-48685F20BAEC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{17FFCF9D-AD3B-4889-B049-048D167EB1AB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{11CAC8B9-494A-4C98-B177-72A7CB7642D8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{D30CFC0E-367A-430A-9EFD-2051E8ECB800}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{FEA81D5A-8D2C-46F9-AACD-102BE4F39A81}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{38C44A11-D9F0-4CEA-8C59-B224FC27920F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{B60744A3-3626-4327-BD82-285D4A745426}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{33EAE836-6546-4CB6-ABF1-4CB6A094D0CD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{883B687D-BA7F-4C43-B587-06715F39CEEF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{120CBB2C-EDC5-436F-BB0A-7DA7629C5929}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{9A946423-9CEF-4479-9EE9-EBF0CC2B7EC8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{7EA26CF7-AFDF-4195-8648-97890CA74DB0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{480AB8B6-ECC0-4FE2-AFE5-78D5F6A5BED2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{5E5967A5-FA55-48EB-B946-4533B93B84A5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{47C6CA3A-080B-44FD-A1D8-8C1062044C56}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{EC3F2033-CE4D-4AE1-9882-E5FC66E872A6}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{333DDC02-E7B3-436B-BB5D-113F000AA6E3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{63FBCF2C-3E7E-404C-8B9E-ADE0000F5834}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{052F30EC-4923-43A0-BD81-0997CCD110E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{A54A5799-50F6-4188-94DE-6F900B290C6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{1E2B04C4-8124-4182-A58A-5EEA6F06826A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{90261EB1-2221-4D5E-A676-3A53F36C40EF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{D87B24B6-98DC-462C-931E-8AB13E84B7D2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{F922DB43-EEB2-4DA4-86E9-C7722689084D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{FE0557F0-BB04-481C-A46B-8B469CB4DE95}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{2C860004-8BEC-443B-951C-D025192EB5BF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{85FD87E8-5C74-4670-AF47-BDCBE616CA07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{07D9D872-01A5-4F20-9ECF-555F0A2E0084}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{D755B785-6173-4B55-A993-793F5BF27928}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{2A339B18-F114-44A9-BB4C-E95A271600F5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{040B4775-3792-4287-995E-40E1ACED7F3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{081AD8EB-777B-4BC3-89B7-C5EA36CEB736}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{AB01407D-587C-4E9B-ACD8-DA05707E6811}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{FE0775D8-123A-4F81-9AED-8E7520EDC213}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{B2C3263E-F590-4338-9E8C-26ECE9313E95}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{CD46A599-9D05-468A-BE92-CA0B99EC4A47}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{69DFCE55-558C-4EED-A517-74BD1FD086AD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{902BC3B7-1199-4C96-9512-6A7A5B5436C1}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{5809923C-16F1-4E5F-94D0-78854FA5B892}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{2DEF269D-4A61-4067-98BA-4402D5E60146}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{2B25BA5B-FD5A-40DC-A7A8-E9646E618123}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{1A8D33B4-0B26-434D-BA22-22251825D207}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{287217C6-AA67-4B88-9D06-31F5CB5AD859}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{8225FCB1-1685-4867-A9B4-2BCA0EE9C898}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{26F855F5-C42E-4713-8685-69B1EB146ED3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{6C7103FE-84FA-4C63-A686-9D48E50364CE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{DC6C833E-7509-4640-98FD-6F66AE91A1D7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{56E744E0-60C4-43BF-8DE8-0C057255DEE9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{AE4152F0-A7DA-4193-B1F1-25B5C47893FE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{F7FAF980-6370-488D-A8D8-7B17FA8DBCF8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{7ADFE28C-5C1F-46F2-9A28-D90CEB38A316}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{A3DB897E-4D94-4A07-8177-92CE1F3AF903}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{222E7604-7380-45ED-9322-64238EF72023}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{7AD0E036-0226-4FD9-98EB-2913AD76CA83}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{3BE26C79-6809-4B3C-91EB-7048927D3339}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{454BEA0C-1BAC-469C-8B59-09D428EC8742}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{973C1E16-B2D6-4D1E-8305-E69341F2688E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{1422A4A9-5B64-4662-82E5-EA0396565B5A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{0D8B6231-D8CB-4136-BF35-0552FA8C0A68}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{B68BFDB9-54AB-4EC6-91BA-FBEF718947C8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{C41BDAAA-4B3C-409F-8BAB-28BB8617950E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{AA21AD32-08AE-44E1-AD92-3F84918AD561}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F7C51446-29DA-4871-BDB1-9E87366B5E9C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{3AFDDD61-9B21-442B-A2E5-A9569B9756EB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{28F3A9E8-5CB4-43E8-A420-F58A5E8E0215}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{6B2DB471-2705-4BEB-8726-0DE47F433BD0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{DD9EB22E-A092-44B1-8655-C06A17D07A07}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{E3160591-0CDB-43CA-B789-8B18FD06FF2A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{AE2EDABE-1FC9-4337-B4AB-FE5F30AF07BC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{5E3404AC-ADDC-4B94-8753-149D126B308A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{2629FCEA-6CEA-4B43-B105-4FCAA339FCAF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{29940186-D4F5-44B4-AF81-9D8B2B759F7D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{35B2994F-926A-414D-AB64-C7A9013A6D6E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{8EE992AD-2D64-416B-A11C-B21D601090E5}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{C4F877C6-CF47-4CF3-BB66-849D32736764}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{E7E5C226-AF28-4A19-A1A9-D3CC86741C6A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{65785401-F682-4656-97AF-6D1E77379270}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{D8BEA1C9-A641-463D-AB06-CC99858E9B6C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{F29072B1-DB28-4F11-A7CB-270A2F550E72}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{E5C4DAFF-1E42-4221-A456-17EC2E08DAF2}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{94910D5D-4577-4CAF-AB2C-2EB080370AE3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{A12DA46A-421D-4961-A892-34798003BF52}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{AFFC572B-8292-49AB-A966-A3A06344639C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{BC6E663D-A81A-477C-96DD-1C882B293857}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{4D74C129-09FD-49AA-B48B-B819358F9F5E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{36112616-2F62-4359-80B5-34952595A745}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{3F8F845A-577D-46E4-BCD8-54BB17E249CB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{D18699DD-3663-48C4-8287-15D0A6FE2D21}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{D166B5B9-A4BF-4068-947C-DBCC59783F4A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{62953C40-27B7-438B-BA1F-CDAFADD7BE81}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{48CD7CA4-0304-4691-B686-14BF64D2BF5B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{75095B6C-667E-49E4-91B2-73592D1ACE62}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{3025CB00-E332-46E2-9248-5B0632AA2458}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" +"{24FD90F4-BF41-4927-912B-71E98DC19DC4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files (x86)\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{D0A6EC14-C086-443A-B7F5-50A894FC2EC8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Program Files\\Microsoft Office\\root\\client\\AppVLP.exe|Name=Block appvlp.exe netconns|" +"{9B0C4577-A348-43D0-8409-4DFEB1DFAE3B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\calc.exe|Name=Block calc.exe netconns|" +"{6703587B-DDAD-46DF-8DD6-D1FED933D052}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\calc.exe|Name=Block calc.exe netconns|" +"{8515CE51-BDC8-4996-A4BB-768E5E6C5659}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\certutil.exe|Name=Block certutil.exe netconns|" +"{B9C070FC-B903-402E-8DB4-2FD986E4718A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\certutil.exe|Name=Block certutil.exe netconns|" +"{BBBE0D6E-946B-4A21-81B4-A6443D729A8D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{5B715575-CA69-4A17-9F59-A7A196599600}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cmstp.exe|Name=Block cmstp.exe netconns|" +"{85E12E7F-37FF-4CC2-9ADF-3865E303F363}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\cscript.exe|Name=Block cscript.exe netconns|" +"{B5C3E6EA-918E-4F2A-A7E0-DB6A522BA951}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\cscript.exe|Name=Block cscript.exe netconns|" +"{E866851B-4352-4F59-81C4-6438151BB509}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{A3AFF576-D01E-44C7-BB3F-6C9D31F562D0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\esentutl.exe|Name=Block esentutl.exe netconns|" +"{4CFC1407-9AF8-4FE7-86A1-49F33F2BB07F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\expand.exe|Name=Block expand.exe netconns|" +"{EDC9DC78-295F-4CBB-B2E2-1ACFFDD729D3}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\expand.exe|Name=Block expand.exe netconns|" +"{1787E7A8-2279-4268-AB2D-F8098D46C544}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{26A39019-CBB5-478A-A6BE-122A36FC018B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\extrac32.exe|Name=Block extrac32.exe netconns|" +"{CD4D109A-C561-45EC-B94C-349BC9DAE8DB}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\findstr.exe|Name=Block findstr.exe netconns|" +"{7A976567-874D-4412-8DAA-8D6C0284CA83}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\findstr.exe|Name=Block findstr.exe netconns|" +"{2B53B25B-4762-486C-9430-5B7A7450444E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\hh.exe|Name=Block hh.exe netconns|" +"{1DDBF75D-43B4-4A1A-AA30-9A181D90B05C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\hh.exe|Name=Block hh.exe netconns|" +"{4A8C81AA-FD97-4C07-85EF-3ACA05CE5691}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\makecab.exe|Name=Block makecab.exe netconns|" +"{D295F48C-16A2-4647-9245-5B817F4ACE15}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\makecab.exe|Name=Block makecab.exe netconns|" +"{F9493F86-ACB9-453E-89D4-470168F5573C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\mshta.exe|Name=Block mshta.exe netconns|" +"{193DBAAC-A44C-48FB-A243-05660F8E5E30}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\mshta.exe|Name=Block mshta.exe netconns|" +"{DFC4811F-8044-4ADD-8DA6-5F2A47F1D871}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{A12D27BE-1348-4DCC-8B62-837FA7E6CE1D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\msiexec.exe|Name=Block msiexec.exe netconns|" +"{17BB815E-338C-4518-8A5E-720D7E577817}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\nltest.exe|Name=Block nltest.exe netconns|" +"{E575AB30-9F18-4BCF-870B-DCDA16962D7B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\nltest.exe|Name=Block nltest.exe netconns|" +"{8A14BFB7-AEA0-48E2-BD72-7604675FC02C}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\notepad.exe|Name=Block Notepad.exe netconns|" +"{692D4DCE-F9A8-43DD-A66D-B5CEC589309F}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\notepad.exe|Name=Block Notepad.exe netconns|" +"{88E9FC39-00D1-404A-A0F3-AA8BA90C438D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{2571D842-A014-406E-A20B-256F482631B9}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\odbcconf.exe|Name=Block odbcconf.exe netconns|" +"{4903107A-61A1-4916-82F6-962FCAD7AE2B}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{F8B79A87-1813-4A77-BB19-A05FAC3007BD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\pcalua.exe|Name=Block pcalua.exe netconns|" +"{F4723629-809F-42EB-8676-C8FCA8082C38}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regasm.exe|Name=Block regasm.exe netconns|" +"{03687CAA-26F8-454C-846E-EB87CBDEF554}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regasm.exe|Name=Block regasm.exe netconns|" +"{CDD4FD86-5B1B-4805-BFE1-4C34D0CF46EC}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{7D96C65A-19E6-4B65-BBE9-FFF7E2BFC9FF}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\regsvr32.exe|Name=Block regsvr32.exe netconns|" +"{B534C0BE-9719-468B-94F4-EBAC0849B3C7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\replace.exe|Name=Block replace.exe netconns|" +"{5C87CE16-1B9A-46C9-9082-C2C2B44BE54D}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\replace.exe|Name=Block replace.exe netconns|" +"{2CAD68CE-0024-4E6D-9A84-95BA3C65CAFE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rpcping.exe|Name=Block rpcping.exe netconns|" +"{3F1F39BD-6F42-4137-B0EC-42A3E62FC3E0}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{5D607F7A-6B19-472C-AF51-3BC959512E8A}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\rundll32.exe|Name=Block rundll32.exe netconns|" +"{1CD3ABE9-B6D6-4742-B22F-669CE1192DE7}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{74D85154-2A03-4121-B752-08B480A174FD}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\runscripthelper.exe|Name=Block runscripthelper.exe netconns|" +"{4DF37154-D997-4A05-9B64-DD1BF9A1C8A8}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{8BD0774E-477A-474A-9B6B-2C74B7A6AF35}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\scriptrunner.exe|Name=Block scriptrunner.exe netconns|" +"{5310066A-AEE3-4CFF-97FE-A27F829C4ED4}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{410031EB-900A-426E-BFE4-A51DD7E218BE}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\SyncAppvPublishingServer.exe|Name=Block SyncAppvPublishingServer.exe netconns|" +"{5C90C829-D035-4FB2-9C35-8F560A22737E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{23FB6F20-8E80-4274-B2CE-5310A4543D7E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wbem\\wmic.exe|Name=Block wmic.exe netconns|" +"{CB3E27CB-7567-440E-A224-2F5F55F180FA}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\system32\\wscript.exe|Name=Block wscript.exe netconns|" +"{D577FBC1-ACD1-4D2C-BBB7-BC9753C0725E}"="v2.31|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=C:\\Windows\\SysWOW64\\wscript.exe|Name=Block wscript.exe netconns|" + +;075. ViveTool Manipulation + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\105243275] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1084486795] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1105025673] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1111440523] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1140553355] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1167405706] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1254311563] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1286552203] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\129315978] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1323362443] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\133772938] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1431914635] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1497709195] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\151073418] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\152522890] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1570325131] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1593135754] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1604982409] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1707173514] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1711504522] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1740062347] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1826306186] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\1879800970] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2061326475] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2080885386] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2098554507] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\210965642] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2122649227] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2141004426] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2159103626] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\221325962] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\230377099] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2475784331] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2528327818] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2536843915] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2553628810] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\261698187] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2628859531] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2674077835] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\269563531] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2736994955] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2778935433] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2845256331] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2866624651] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2888518282] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2891254923] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2940954250] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\2954081930] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\296246922] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3054451851] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3073583755] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3135060107] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3298293899] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\345723018] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3535874698] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3543217290] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3655416971] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3665657483] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3784116360] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3793829003] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3928046731] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\3928239754] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\395859593] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4045366411] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4095660171] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4122855562] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4134351499] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\4145095306] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\463973000] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\469712011] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\479401098] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\523318411] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\525560971] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\553726602] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\581515914] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\589803146] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\641901194] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\644487817] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\653733002] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\65394315] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\783108235] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\814945418] +"EnabledState"=dword:00000001 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\892417163] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\FeatureManagement\Overrides\4\957700746] +"EnabledState"=dword:00000002 +"EnabledStateOptions"=dword:00000001 +"Variant"=dword:00000000 +"VariantPayload"=dword:00000000 +"VariantPayloadKind"=dword:00000000 + +;076. Service Removal + diff --git a/Melody 12.01 (Script for Windows Insider Preview)/ma.ps1 b/Melody 12.01 (Script for Windows Insider Preview)/ma.ps1 new file mode 100644 index 0000000..6112035 --- /dev/null +++ b/Melody 12.01 (Script for Windows Insider Preview)/ma.ps1 @@ -0,0 +1,38 @@ +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "WOL & Shutdown Link Speed" -DisplayValue "Not Speed Down" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Power Saving Mode" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "NS Offload" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Jumbo Frame" -DisplayValue "9014 bytes" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Green Ethernet" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Gigabit Lite" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Energy-Efficient Ethernet" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Flow Control" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Interrupt Moderation" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Interrupt Moderation Rate" -DisplayValue "Off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Enable PME" -DisplayValue "disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Maximum Number of RSS Queues" -DisplayValue "4 Queues" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Transmit Buffers" -DisplayValue "128" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Receive Buffers" -DisplayValue "512" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Large Send Offload V2 (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Large Send Offload V2 (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "TCP Checksum Offload (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "TCP Checksum Offload (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "UDP Checksum Offload (IPv4)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "UDP Checksum Offload (IPv6)" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "IPv4 Checksum Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Speed & Duplex" -DisplayValue "1.0 Gbps Full Duplex" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Gigabit Master Slave Mode" -DisplayValue "Force Slave Mode" For two NICs +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Maximum Number of RSS Processors" -DisplayValue "4 Processors" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "RSS load balancing profile" -DisplayValue "NUMAScaling" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Protocol ARP Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Protocol NS Offload" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Ultra Low Power Mode" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Jumbo Packet" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Magic Packet" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Pattern Match" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wake on Link Settings" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Wait for Link" -DisplayValue "off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Energy Efficient Ethernet" -DisplayValue "Off" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Reduce Speed On Power Down" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "System Idle Power Saver" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Log Link State Event" -DisplayValue "Disabled" +Set-NetAdapterAdvancedProperty -Name "*" -DisplayName "Packet Priority & VLAN" -DisplayValue "Packet Priority & VLAN Disabled" \ No newline at end of file diff --git a/Melody 12.01 (Script for Windows Insider Preview)/nircmd.exe b/Melody 12.01 (Script for Windows Insider Preview)/nircmd.exe new file mode 100644 index 0000000..e606a83 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/nircmd.exe differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/nircmdc.exe b/Melody 12.01 (Script for Windows Insider Preview)/nircmdc.exe new file mode 100644 index 0000000..6e7fe18 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/nircmdc.exe differ diff --git a/Melody 12.01 (Script for Windows Insider Preview)/secdrv.sys b/Melody 12.01 (Script for Windows Insider Preview)/secdrv.sys new file mode 100644 index 0000000..fd2fe65 Binary files /dev/null and b/Melody 12.01 (Script for Windows Insider Preview)/secdrv.sys differ