[Guide]Way to Disable Keylogger/ Telemetry v3.55

Discussion in 'Windows 10' started by LiteOS, Oct 9, 2014.

Thread Status:
Not open for further replies.
  1. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
  2. LiteOS

    LiteOS Windowizer

    Mar 7, 2014
    2,343
    1,048
    90
    #362 LiteOS, Oct 21, 2014
    Last edited: Oct 30, 2014
    (OP)
    -delete-


    1. The message you have entered is too short. Please lengthen your message to at least 10 characters.
     
  3. murphy78

    murphy78 MDL DISM Enthusiast

    Nov 18, 2012
    7,419
    11,688
    240
    I don't care who uses stuff in the script.
    You're welcome to use the various commands or even the menu system and stuff.
    I'm actually more interested in the various methods and whether or not they block the telemetry and/or keylogger stuff.
     
  4. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    We can fix that by doing a reg query aka if exist :p
     
  5. KnowledgeableNewbie

    KnowledgeableNewbie MDL Member

    Sep 30, 2014
    178
    28
    10
    i briefly ran the script yesterday and if i remember ( was tired ) the diagtrack service didn't stop, but i ran it on a VM that i was editing. so installed a fresh copy and will give it another stop. have to see what other evils lurk in the registry. also, a quick note. on the sysprepped administrator system. the upload task in task scheduler wasn't installed, and nothings being created in the C:\Users\All Users\Microsoft\Windows\Sqm folder. have to check if i disabled CEIP in my unnattend file.
     
  6. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    No, that will not be the main thread. It will just be the storage thread so I don't have to update multiple threads.
     
  7. theblackmage

    theblackmage MDL Novice

    Oct 20, 2014
    1
    0
    0
    The new build is downloadable look in "pc settings" "update and recovery" and "preview builds"
     
  8. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    I'll test it out the more builds we have the easier it will be.
     
  9. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    Ok I've synced up both the Powershell Script and Command line script.

    Also synced up the version numbering to reflect that. It makes it more obvious they are in the prototype phase. :)

    I uploaded 0.10 and 0.03 to media fire as well. Please note that the numbers are reflective of the current build they are on.
     
  10. xtreme 008

    xtreme 008 MDL Novice

    May 9, 2011
    9
    0
    0
    #372 xtreme 008, Oct 22, 2014
    Last edited: Oct 22, 2014
    I have deleted both dmwappushsvc, diagtrack files from System32. Now both services has stopped running :p. Now I wanna know whether I am free of tracking or not ?:busted_cop:

    here's the screenshot

    Capture.png
     
  11. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    17,223
    90,880
    340
  12. xtreme 008

    xtreme 008 MDL Novice

    May 9, 2011
    9
    0
    0
    then any other option to stop being tracked by keylogger
     
  13. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    17,223
    90,880
    340
    1) It's not keylogger
    2) Don't connect to network
    3) Don't use it
     
  14. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    You knew what to expect when you started Testing Windows 10. This is not about taking extreme actions on a product that is still being developed.

    It is about taking reasonable actions in order to explore what is being collected. While making an effort to do an analysis of how it is done in order to put something together to take care of it.
     
  15. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    #377 Smorgan, Oct 22, 2014
    Last edited: Oct 22, 2014
    O ya we should probably put a build number check in so that it only applies to builds greater than 9651 :p

    UPDATE:

    Scratch that I'm going to use the 6.4 statement. We can use the gmic for the power-shell which is done.
     
  16. KnowledgeableNewbie

    KnowledgeableNewbie MDL Member

    Sep 30, 2014
    178
    28
    10
    #378 KnowledgeableNewbie, Oct 23, 2014
    Last edited: Oct 24, 2014
    [Edit]

    Hoping somebody can help me with this.

    Does anyone know what controls the All Application Packages privilege. If you go into any of the permissions for any of these registry keys and delete it, it rewrites itself. Not sure but i believe that's the only one that does that.

    Since what i'm doing has to do with the "keylogger" that's why i'm asking here.
    i wrote a script to disable dmwappushsvc without a restart. Since SMorgan is more knowledgeable i'm gonna use his script, but i started on mine just because i hate when anyone ( MS ) says it can't be done, and i figured why not try it.

    Anyways, i run the script, and everything works as planned ( the service stops ), but then it restarts. Go into regedit ( HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dmwappushsvc ) and delete the All Applications Packages privilege, and it rewrites itself. Kill the service, it restarts, and go back to regedit, delete the privilege, it restarts. blah blah blah. On the fourth attempt ( always the fourth ) killing the service sticks.

    My question, if anyone knows, is why the fourth attempt and not the the third, or sixth, or whatever. I think it might be because dmwappushsvc is part of a grouped service in svchost, but i'm not sure. I've got to play around some more. If anyone could shed some light on this it would be greatly appreciated.
     
  17. Smorgan

    Smorgan Glitcher

    Mar 25, 2010
    1,855
    1,051
    60
    Actually now that you mention it I have heard of this happening. When I was playing around with the licensing for various Microsoft Products some of them actually do what you mentioned. A perfect example of this is actually the WPA registry keys. If you try to delete them they are rewritten over and over again. The fun part is that most of the time Microsoft's Beta products have a bunch of loop holes in them in terms of stopping the stuff that does this.

    MY advise would be to kill the dmwappushsvc then additionally write into the start entry the number 4. This will effectively tinker with the Service start information making it disabled. I would not worry about the service host all that much as its just the man that makes it all run. I imagine if you kill the service while modifying the start settings immediately there after it will not start again.

    I actually like tinkering with the registry as its funny how many settings are stored there.
     
  18. Mr Jinje

    Mr Jinje MDL Expert

    Aug 19, 2009
    1,769
    1,106
    60
    Dumb question. Which packages do we remove with Install_Wim_Tweak to fix your install.wim.