Kill services in Windows 10 for offline machine?

Discussion in 'PC' started by ArticStorm, Feb 24, 2022.

  1. AudioMixing22

    AudioMixing22 Member

    Joined:
    Jul 17, 2020
    Messages:
    48
    Likes Received:
    16
    I don't just manually cleaning !
     
  2. saccamano

    saccamano Audiosexual

    Joined:
    Mar 26, 2023
    Messages:
    1,483
    Likes Received:
    604
    Location:
    CBGB omfug
    REVISED for current win10 version:

    GhostSpectre win10Pro LITE 21H2 - 22H2 == Recommended image to use for new builds. The w10privacy tool is not as effective the higher you go in version because they can't keep up with mickeysoft re-securing all the reverse engineering that the tool does. The same goes for most other "optimizing tools" to date. The good part is a lot of the crap is simply not there in the LITE version which makes the post install optimization job much less tedious. Also, LITE does not pooch the staple services needed for running offline or online like printing, LAN, SMB, etc...

    A list of services able to be disengaged are thus;

    Adobe Genuine Software Integrity Service
    Adobe SwitchBoard
    Assigned Access Manager Service
    Auto Time Zone Updater
    BitLocker Drive Encryption Service
    Block Level Backup Engine Service
    BranchCache
    Cellular Time
    Connected User Experiences and Telemetry
    Data Usage
    Diagnostic Execution Service
    Diagnostic Policy Service
    Dialog Blocking Service
    Downloaded Maps Manager
    -- anything to do with Google Chrome --
    -- anything to do with Hyper-V --
    Intel(R) Content Protection HECI Service
    Language Experience Service
    Microsoft (R) Diagnostics Hub Standard Collector Service
    Microsoft App-V Client
    Microsoft Cloud Identity Service
    Microsoft iSCSI Initiator Service
    Microsoft Keyboard Filter
    Microsoft Storage Spaces SMP
    Microsoft Store Install Service
    Microsoft Windows SMS Router Service
    Net.Tcp Port Sharing Service
    Offline Files
    OpenSSH Authentication Agent
    Parental Controls
    Payments and NFC/SE Manager
    Peer Name Resolution Protocol
    Peer Networking Grouping
    Peer Networking Identity Manager
    Phone Service
    PNRP Machine Name Publication Service
    Program Compatibility Assistant Service
    Quality Windows Audio Video Experience
    Radio Management Service
    Remote Registry
    Retail Demo Service
    Routing and Remote Access
    Secondary Logon
    Shared PC Account Manager
    SysMain
    System Guard Runtime Monitor Broker
    Touch Keyboard and Handwriting Panel Service
    User Experience Virtualization Service
    Wallet Service
    Windows Biometric Service
    Windows Connect Now - Config Registrar
    Windows Defender Firewall
    Windows Insider Service
    Windows License Manager Service
    Windows PushToInstall Service
    Windows Remote Management (WS-Management)
    Windows Security Service
    * Windows Time (if you use a alternate NTS client/server)

    +++++++++++++++++++++++++++++++++++++++

    There's also a crap-load of scheduled tasks that need to be disabled or removed:

    -- All MS Office --
    AD RMS Rights Policy Template Management (Automated)
    -- AppID - All except "EDP Policy Manager"
    -- Application Experience - disable all
    Appx Deployment Client - disable all
    Autochk - disable all
    BitLocker - disable all
    CLIP - disable all
    Cloud Experience Host - disable all
    Customer Experience Improvement - disable all
    * Defrag - - disable all (I run it myself. dont need a task to fire off in the middle of something)
    DiskDiagnostic - disable all
    DUSM - disable all
    File Classification Infrastructure -
    Flighting - disable all
    HelloFace - disable all
    Install Service - disable everything except smart retry
    Language Components Installer - disable all
    License Manager - disable all
    Live - disable all
    Location - disable all
    Management - disable all
    Maps - disable all
    Mobile Broadband - disable all
    NlaSvc - disable all
    Offline Files - disable all
    PLA - disable all
    Power Efficiency Diagnostics - disable all
    Push To Install - disable all
    Recovery Environment - disable all
    Remote app/Desktop connex - disable all
    Remote assistance - disable all
    Setup - disable all
    SharedPC - disable all
    Shell - disable all
    Software Protection Platform - disable all
    SpacePort - disable all
    Speech - disable
    Subscription - disable
    Sync Center - disable
    Sysmain - disable
    TPM - disable all
    UNP - disable all
    Update Orchestrator - disable all
    User Profile Service - disable
    Windows activation - delete all
    Win Defender - disable all
    Windows Error Reporting - disable all
    Windows Media Sharing - disable all
    Win Backup - disable

    ----------------

    Remove Edge browser, Defender anti-vir, defender firewall, win update (either disable or render impotent for 50 + years), all MS store apps, MS Store, wallet app, etc...

    * Some of the above tasks and services may not want to be disabled. If you run into one that doesn't want to comply you must adjust security and properties on the object until it does comply.

    ** If the build is for an internet machine install netlimiter and 3rd party FireWall of choice. Also install 3rd party a/v of choice. Spybot & SpywareBlaster for remediation of active/passive browser exploits.
     
    Last edited: Mar 7, 2025 at 3:20 AM
  3. orbitbooster

    orbitbooster Audiosexual

    Joined:
    Jan 8, 2018
    Messages:
    1,187
    Likes Received:
    663
    Could you specify the remaining sht to remove after install?
    Just in case.
     
Loading...
Loading...