This is crazy. The IP list can be endless. Is not enough uninstall the packages affected? Does anyone know what steps or options are necessary or complementary to them? Is there a guide to what to do and why is it done? To remove records ?, remove packages ?, block IPs?
The list is endless because they use a dns server and ranges. It's more effective to trace the path and block the server that points to them all or just use a firewall setting.
You could, but it would cause problems down the line inevitably. If not during updates, probably during upgrades. Removing packages is not a good way to fight system problems. How many times have we argued against hacktivation for the same reason?
The best would be to go through every task, service, ip address, and categorize them all and calculate the best way to block the privacy issues. The problem is that it's very difficult to do everything that we need to do to figure out the best approach. This is why you see tons of people doing extreme stuff like removing packages and such. When I get more time I'll start with LTSB and do the basics (disable telemetry and app toast) then go through what's left and start sniffing out things. It will probably end up being a telemetry and firewall rule solution. Once I get all the LTSB stuff blocking as intended (except for intentional web stuff) I'll move on to Enterprise. home thru enterprise should have the same traffic problems with apps phoning home, so it will end up being a search and firewall situation for most of them. There are some apps, tho, that are defined by their ability to use the internet, such as the Windows store, Cortana, Email, Edge, etc. Those apps are more difficult to handle. They need internet access, but they also phone home. So on those, we'll have to snoop and see if there's any way to block the phone home, but if not, figure out some way to block said traffic. That will not be the easiest thing. Hosts file will likely not work as MS often whitelists their domains to bypass it. So we'll likely have to set some sort of routing rules or something. All of this stuff we need to be able to reverse on demand if someone needs to fix something. That's the last challenge. It's easy to set something. It's harder to make it reversible and easy to do. Ideally, you will have a script that will both enable and disable the privacy blocking stuff. It should also not do too much. I.E. shouldn't dictate taste. Just because a lot of ppl don't like connecting to update peers doesn't mean it's evil, etc.
Thank you very much for your clarification. I agree with you, it will not be easy to eradicate all traffic.
Windows 10 IP Range Block List I made this today for you all who are taking the IP Range and/or Router Block route. It's not perfect solution, but every bit helps. Maybe if we have several layers/methods of protection, we will get to the desired end result. Please note: If you are using a VPN, depending on your setup, your router won't be able to block these addresses when you use Route Add (see point 3 for possible solution) If you are using a VPN and use Route Add, it won't "stick" once you reconnect. (See next point for possible solution) If you are using a VPN, consider adding the address ranges in your VPN config file instead. (Possible even in the router >> vpn config if your router supports that.) Microsoft's Hostnames IP Addresses IP Range Route Add – Block Command bing.com 204.79.197.200 204.79.197.* route ADD 204.79.197.0 MASK 255.255.255.0 0.0.0.0 settings-sandbox.data.glbdns2.microsoft.com 111.221.29.177 111.221.29.* route ADD 111.221.29.0 MASK 255.255.255.0 0.0.0.0 onesettings-hk2.metron.live.com.nsatc.net 111.221.29.253 vortex-hk2.metron.live.com.nsatc.net 111.221.29.254 bs.eyeblaster.akadns.net 12.129.210.71 12.129.210.* route ADD 12.129.210.0 MASK 255.255.255.0 0.0.0.0 dns.msftncsi.com 131.107.255.255 131.107.255.* route ADD 131.107.255.0 MASK 255.255.255.0 0.0.0.0 fesweb1.ch1d.binginternal.com 131.253.14.76 131.253.14.* route ADD 131.253.14.0 MASK 255.255.255.0 0.0.0.0 bn2wns1.wns.windows.com 131.253.34.230 131.253.34.* route ADD 131.253.34.0 MASK 255.255.255.0 0.0.0.0 flex.msn.com.nsatc.net 131.253.40.47 131.253.40.* route ADD 131.253.40.0 MASK 255.255.255.0 0.0.0.0 login.live.com.nsatc.net 131.253.61.100 131.253.61.* route ADD 131.253.61.0 MASK 255.255.255.0 0.0.0.0 login.live.com.nsatc.net 131.253.61.66 login.live.com.nsatc.net 131.253.61.68 login.live.com.nsatc.net 131.253.61.80 login.live.com.nsatc.net 131.253.61.82 login.live.com.nsatc.net 131.253.61.84 login.live.com.nsatc.net 131.253.61.96 skyapi.skyprod.akadns.net 134.170.104.152 134.170.104.* route ADD 134.170.104.0 MASK 255.255.255.0 0.0.0.0 skyapi.skyprod.akadns.net 134.170.104.160 skyapi.skyprod.akadns.net 134.170.104.168 skyapi.skyprod.akadns.net 134.170.104.176 bl3302.storage.skyprod.akadns.net 134.170.107.224 134.710.107.* route ADD 134.710.107.0 MASK 255.255.255.0 0.0.0.0 skyapi.skyprod.akadns.net 134.170.111.24 skyapi.skyprod.akadns.net 134.170.111.48 skyapi.skyprod.akadns.net 134.170.111.72 skyapi.skyprod.akadns.net 134.170.111.96 134.170.111.* route ADD 134.170.111.0 MASK 255.255.255.0 0.0.0.0 statsfe2.ws.microsoft.com.nsatc.net 134.170.115.60 134.170.115.* route ADD 134.170.115.0 MASK 255.255.255.0 0.0.0.0 statsfe1.ws.microsoft.com.nsatc.net 134.170.115.60 fe2.update.microsoft.com.akadns.net 134.170.165.249 fe2.update.microsoft.com.akadns.net 134.170.165.253 134.170.165.* route ADD 134.170.165.0 MASK 255.255.255.0 0.0.0.0 siweb.microsoft.akadns.net 134.170.185.70 134.170.185.* route ADD 134.170.185.0 MASK 255.255.255.0 0.0.0.0 legacy-redirection-eastus-prod-hp.cloudapp.net 137.117.100.176 137.117.100.* route ADD 137.117.100.0 MASK 255.255.255.0 0.0.0.0 support.msn.microsoft.akadns.net 157.55.129.21 157.55.129.* route ADD 157.55.129.0 MASK 255.255.255.0 0.0.0.0 BN1WNS2011508.wns.windows.com 157.56.100.83 157.56.100.* route ADD 157.55.100.0 MASK 255.255.255.0 0.0.0.0 bn1.skype.msnmessenger.msn.com.akadns.net 157.56.108.82 157.56.108.* route ADD 157.56.108.0 MASK 255.255.255.0 0.0.0.0 ui.skype.akadns.net 157.56.109.8 157.56.109.* route ADD 157.56.109.0 MASK 255.255.255.0 0.0.0.0 win10.ipv6.microsoft.com.nsatc.net 157.56.144.215 157.56.144.* route ADD 157.56.144.0 MASK 255.255.255.0 0.0.0.0 activesync.glbdns2.microsoft.com 157.56.17.248 157.56.17.* route ADD 157.56.17.0 MASK 255.255.255.0 0.0.0.0 ads.msn.com.nsatc.net 157.56.23.91 157.56.23.* route ADD 157.56.23.0 MASK 255.255.255.0 0.0.0.0 diagnostics.support.microsoft.akadns.net 157.56.57.5 157.56.57.* route ADD 157.56.57.0 MASK 255.255.255.0 0.0.0.0 sls.update.microsoft.com.akadns.net 157.56.77.139 157.56.77.* route ADD 157.56.77.0 MASK 255.255.255.0 0.0.0.0 choice.microsoft.com.nsatc.net 157.56.91.77 157.56.91.* route ADD 157.56.91.0 MASK 255.255.255.0 0.0.0.0 bn1-2cd.wns.windows.com 157.56.96.208 bn1cd.wns.windows.com 157.56.96.80 157.56.96.* route ADD 157.56.96.0 MASK 255.255.255.0 0.0.0.0 telemetry.appex.search.prod.ms.akadns.net 168.61.24.141 168.61.24.* route ADD 168.61.24.0 MASK 255.255.255.0 0.0.0.0 onesettings-db5.metron.live.com.nsatc.net 191.232.139.253 191.232.139.* route ADD 191.232.139.0 MASK 255.255.255.0 0.0.0.0 fe2.update.microsoft.com.akadns.net 191.232.80.58 191.232.80.* route ADD 191.232.80.0 MASK 255.255.255.0 0.0.0.0 msedge.net 204.79.197.197 any.edge.bing.com 204.79.197.200 a-0001.a-msedge.net 204.79.197.200 a-0002.a-msedge.net 204.79.197.201 a-0003.a-msedge.net 204.79.197.203 a-0005.a-msedge.net 204.79.197.204 a-0004.a-msedge.net 204.79.197.206 a-0006.a-msedge.net 204.79.197.208 a-0007.a-msedge.net 204.79.197.209 a-0008.a-msedge.net 204.79.197.210 a-0009.a-msedge.net 204.79.197.211 204.79.197.* route ADD 204.79.197.0 MASK 255.255.255.0 0.0.0.0 ads2.msn.com.c.footprint.net 205.128.73.252 global.msads.net.c.footprint.net 205.128.73.252 205.128.73.* route ADD 205.128.73.0 MASK 255.255.255.0 0.0.0.0 ssw.live.com.nsatc.net 207.46.101.29 207.46.101.* route ADD 207.46.101.0 MASK 255.255.255.0 0.0.0.0 fe2.update.microsoft.com.akadns.net 207.46.114.58 207.46.114.* route ADD 207.46.114.0 MASK 255.255.255.0 0.0.0.0 watson.live.com 207.46.223.94 207.46.223.* route ADD 207.46.223.0 MASK 255.255.255.0 0.0.0.0 ssw.live.com.nsatc.net 207.46.7.252 207.46.7.* route ADD 207.46.7.0 MASK 255.255.255.0 0.0.0.0 survey.watson.microsoft.com 207.68.166.254 207.68.166.* route ADD 207.68.166.0 MASK 255.255.255.0 0.0.0.0 w3.b.cap-mii.net 216.38.172.128 216.38.172.* route ADD 216.38.172.0 MASK 255.255.255.0 0.0.0.0 dart.l.doubleclick.net 216.58.217.198 static-2mdn-net.l.google.com 216.58.217.198 216.58.217.* route ADD 216.58.217.0 MASK 255.255.255.0 0.0.0.0 legacy-redirection-westus-prod-hp.cloudapp.net 23.101.196.141 23.101.196.* route ADD 23.101.196.0 MASK 255.255.255.0 0.0.0.0 fe2.update.microsoft.com.akadns.net 23.103.189.158 23.103.189.* route ADD 23.103.189.0 MASK 255.255.255.0 0.0.0.0 e4593.g.akamaiedge.net 23.211.228.52 23.211.228.* route ADD 23.211.228.0 MASK 255.255.255.0 0.0.0.0 e9946.g.akamaiedge.net 23.222.166.121 23.222.166.* route ADD 23.222.166.0 MASK 255.255.255.0 0.0.0.0 e7173.g.akamaiedge.net 23.222.169.232 23.222.169.* route ADD 23.222.169.0 MASK 255.255.255.0 0.0.0.0 e8011.g.akamaiedge.net 23.222.170.100 23.222.170.* route ADD 23.222.170.0 MASK 255.255.255.0 0.0.0.0 compatexchange.cloudapp.net 23.99.10.11 23.99.10.* route ADD 23.99.10.0 MASK 255.255.255.0 0.0.0.0 atlas.c10r.facebook.com 31.13.74.2 31.13.74.* route ADD 31.13.74.0 MASK 255.255.255.0 0.0.0.0 fe3.delivery.dsp.mp.microsoft.com.nsatc.net 64.4.54.18 65.4.54.* route ADD 65.4.54.0 MASK 255.255.255.0 0.0.0.0 statsfe2.update.microsoft.com.akadns.net 64.4.54.22 onesettings-cy2.metron.live.com.nsatc.net 64.4.54.253 vortex-cy2.metron.live.com.nsatc.net 64.4.54.254 vortex-sandbox.data.glbdns2.microsoft.com 64.4.54.32 microsoft-hohm.com 64.4.6.100 64.4.6.* route ADD 64.4.6.0 MASK 255.255.255.0 0.0.0.0 watson.ppe.telemetry.microsoft.com 65.52.100.11 65.52.100.* route ADD 65.52.100.0 MASK 255.255.255.0 0.0.0.0 df.telemetry.microsoft.com 65.52.100.7 telemetry.microsoft.com 65.52.100.9 reports.wes.df.telemetry.microsoft.com 65.52.100.91 services.wes.df.telemetry.microsoft.com 65.52.100.92 wes.df.telemetry.microsoft.com 65.52.100.93 sqm.df.telemetry.microsoft.com 65.52.100.94 c.msn.com.nsatc.net 65.52.108.11 c.atdmt.com.nsatc.net 65.52.108.11 rad.msn.com.nsatc.net 65.52.108.251 bn2wns1b.wns.windows.com 65.52.108.254 g.msn.com.nsatc.net 65.52.108.27 aidps.msn.com.nsatc.net 65.52.108.3 fe3.delivery.dsp.mp.microsoft.com.nsatc.net 65.52.108.90 65.52.108.* route ADD 64.52.108.0 MASK 255.255.255.0 0.0.0.0 schemas.microsoft.akadns.net 65.54.226.187 65.54.226.* route ADD 65.54.226.0 MASK 255.255.255.0 0.0.0.0 msnbot-65-55-108-23.search.msn.com 65.55.108.23 65.55.108.* route ADD 65.55.108.0 MASK 255.255.255.0 0.0.0.0 fe2.update.microsoft.com.akadns.net 65.55.138.112 65.55.138.* route ADD 65.55.138.0 MASK 255.255.255.0 0.0.0.0 fe2.update.microsoft.com.akadns.net 65.55.138.114 fe2.update.microsoft.com.akadns.net 65.55.138.126 t.urs.microsoft.com.nsatc.net 65.55.176.90 65.55.176.* route ADD 65.55.176.0 MASK 255.255.255.0 0.0.0.0 act-3-blu.mesh.com 65.55.194.241 65.55.194.* route ADD 65.55.194.0 MASK 255.255.255.0 0.0.0.0 watson.telemetry.microsoft.com.nsatc.net 65.55.252.43 oca.telemetry.microsoft.com.nsatc.net 65.55.252.63 watson.microsoft.com.nsatc.net 65.55.252.71 telecommand.telemetry.microsoft.com.nsatc.net 65.55.252.92 sqm.telemetry.microsoft.com.nsatc.net 65.55.252.93 65.55.252.* route ADD 65.55.252.0 MASK 255.255.255.0 0.0.0.0 corpext.msitadfs.glbdns2.microsoft.com 65.55.29.238 65.55.29.* route ADD 65.55.29.0 MASK 255.255.255.0 0.0.0.0 microsoft-hohm.com 65.55.39.10 65.55.39.* route ADD 65.55.39.0 MASK 255.255.255.0 0.0.0.0 onesettings-bn2.metron.live.com.nsatc.net 65.55.44.108 vortex-bn2.metron.live.com.nsatc.net 65.55.44.109 65.55.44.* route ADD 65.55.44.0 MASK 255.255.255.0 0.0.0.0 directory.services.live.com.akadns.net 65.55.52.23 directory.services.live.com.akadns.net 65.55.52.56 65.55.52.* route ADD 65.55.52.0 MASK 255.255.255.0 0.0.0.0 secure.anycast.adnxs.com 68.67.128.215 68.67.128.* route ADD 68.67.128.0 MASK 255.255.255.0 0.0.0.0 secure.anycast.adnxs.com 68.67.128.231 secure.anycast.adnxs.com 68.67.128.234 secure.anycast.adnxs.com 68.67.128.235 secure.anycast.adnxs.com 68.67.129.45 secure.anycast.adnxs.com 68.67.129.47 secure.anycast.adnxs.com 68.67.129.53 secure.anycast.adnxs.com 68.67.129.61 68.67.129.* route ADD 68.67.129.0 MASK 255.255.255.0 0.0.0.0 m.anycast.adnxs.com 68.67.152.110 68.67.152.* route ADD 68.67.152.0 MASK 255.255.255.0 0.0.0.0 m.anycast.adnxs.com 68.67.152.120 m.anycast.adnxs.com 68.67.152.172 m.anycast.adnxs.com 68.67.152.173 m.anycast.adnxs.com 68.67.152.174 m.anycast.adnxs.com 68.67.152.94 m.anycast.adnxs.com 68.67.153.37 m.anycast.adnxs.com 68.67.153.87 68.67.153.* route ADD 68.67.153.0 MASK 255.255.255.0 0.0.0.0 global.msads.net.c.footprint.net 8.253.38.126 8.253.38.* route ADD 8.253.38.0 MASK 255.255.255.0 0.0.0.0 ads2.msn.com.c.footprint.net 8.254.11.126 global.msads.net.c.footprint.net 8.254.11.126 8.254.11.* route ADD 8.254.11.0 MASK 255.255.255.0 0.0.0.0 ads2.msn.com.c.footprint.net 8.254.172.254 8.254.172.* route ADD 8.254.172.0 MASK 255.255.255.0 0.0.0.0 global.msads.net.c.footprint.net 8.254.172.254 global.msads.net.c.footprint.net 8.27.243.253 8.27.243.* route ADD 8.27.243.0 MASK 255.255.255.0 0.0.0.0 cs1.wpc.v0cdn.net 93.184.215.200 93.184.215.* route ADD 93.184.215.0 MASK 255.255.255.0 0.0.0.0 db3aqu.atdmt.com 94.245.121.176 94.245.121.* route ADD 94.254.121.0 MASK 255.255.255.0 0.0.0.0 db3aqu.atdmt.com 94.245.121.177 db3aqu.atdmt.com 94.245.121.178 db3aqu.atdmt.com 94.245.121.179 win10.ipv6.microsoft.com.nsatc.net 94.245.121.251 a569.g.akamai.net 96.6.122.144 96.6.122.* route ADD 96.6.122.0 MASK 255.255.255.0 0.0.0.0 a1961.g.akamai.net 96.6.122.169 a973.g.akamai.net 96.6.122.184 a569.g.akamai.net 96.6.122.216 a973.g.akamai.net 96.6.122.218 a1961.g.akamai.net 96.6.122.224 a1095.g2.akamai.net 96.6.122.67 a1856.g2.akamai.net 96.6.122.67 a1095.g2.akamai.net 96.6.122.73 a1856.g2.akamai.net 96.6.122.74
Offline Removal of ALL Apps is working : Code: ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ POWERSHELL PROVISIONED APPS OFFLINE REMOVAL ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ Removing from Index 1 ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ Path : c:\Win\mount\1 Online : False RestartNeeded : False Path : c:\Win\mount\1 Online : False RestartNeeded : False Path : c:\Win\mount\1 Online : False RestartNeeded : False . . . . . . Path : c:\Win\mount\1 Online : False RestartNeeded : False Path : c:\Win\mount\1 Online : False RestartNeeded : False Path : c:\Win\mount\1 Online : False RestartNeeded : False Removed from Index 1 successfully. ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ Drücken Sie eine beliebige Taste . . .
Manual offline App Removal is working likewise: Code: ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ POWERSHELL PROVISIONED APPS OFFLINE REMOVAL ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ Enter PackageName for Removal. Can be a list like Name1, Name2, NameN ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ Enter PackageName for Removal : >Microsoft.WindowsPhone_2015.620.10.0_neutral_~_8wekyb3d8bbwe, microsoft.windowscommunicationsapps_2015.6002.42251.0_neutral_~_8wekyb3d8bbwe, Microsoft.WindowsCamera_2015.612.1501.0_neutral_~_8wekyb3d8bbwe ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ Path : c:\Win\mount\1 Online : False RestartNeeded : False Path : c:\Win\mount\1 Online : False RestartNeeded : False Path : c:\Win\mount\1 Online : False RestartNeeded : False Removed from Index 1 successfully. ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬ Drücken Sie eine beliebige Taste . . . New version will be released very soon .
BGD PRODUCTION PRESENTS: Win 10 S-M-R-T Enable Disable v0.07.77 Changelog v0.07.77 --changed behaviour of Package Auto Removal to remove WOW64 entries on x64 systems only --added [P] POWERSHELL PROVISIONED APPS ON/OFFLINE REMOVAL to remove all or choose what to remove --fixed little flaw in lists
did someone knows how disable telemetry and the data who send on windows 10 for phones i install the w10 ver 10.0.10512.1000 and have the same settings with windows 10 for pcs thanks!