[REPO] Windows 10 TELEMETRY REPOSITORY

Discussion in 'Windows 10' started by Yen, Aug 4, 2015.

  1. Shayne

    Shayne MDL Addicted

    Jul 31, 2009
    752
    181
    30
    Thanks for the tip on peerblock, interesting program, still exploring and liking how it works. Will the list that is being worked on be posted?

    Regards
     
  2. Boops

    Boops MDL Addicted

    Jan 5, 2008
    922
    1,217
    30
    Include xBox x86: Microsoft-Windows-Client-Features-Package-AutoMerged-xbox~31bf3856ad364e35~amd64~~10.0.10240.16384
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. LiteOS

    LiteOS Windowizer

    Mar 7, 2014
    2,343
    1,048
    90
    related to netsh winsock show catalog ?
     
  4. E*L*I*X

    E*L*I*X MDL Novice

    Aug 1, 2015
    27
    18
    0
    #464 E*L*I*X, Aug 23, 2015
    Last edited: Aug 23, 2015
    @lite8

    ProviderKey related to netsh wfp show filters (Windows Filtering Platform},
    file filters.xml

    Find ProviderKey in regedit.
     
  5. tolanri

    tolanri MDL Novice

    Aug 9, 2012
    30
    12
    0
    #465 tolanri, Aug 23, 2015
    Last edited by a moderator: Apr 20, 2017
    I've been playing a bit with Win10 on VMware Workstation and found out how to capture all traffic that happens on the NAT interface. It will capture everything even before Windows fully boot up. It is saved into PCAP file which can be loaded into Wireshark or similar tools. I prefer it to running some other sniffing tools within virtualized OS itself.

    Maybe it will be of some use to some of you who would like to inspect it all traffic thoroughly. You can try it for yourselves by running following command on host as admin:

    Code:
    "C:\Program Files (x86)\VMware\VMware Workstation\vnetsniffer.exe" /e /w C:\win10spy.pcap vmnet8
    vmnet8 is a default network interface for virtual NAT connectivity. You can check if it's yours as well in VMware workstation by going to Edit -> Virtual Network Editor Also make sure your virtual machine's network card is set to NAT (not bridged or anything).

    Then you can load the file (C:\win10.pcap in this example) in Wireshark on your host computer and analyze all traffic.

    I played with it just a while and my findings so far are:

    • When you set your Windows Firewall to block all incoming and outcoming connections, Windows Firewall will truly block everything except during boot time where some traffic unfortunately happens
    • When using above firewall setup (block all out/in connection by WinFirewall), whitelising Windows update services don't make updating work like it used to in pprevious Windows versions)
    • When installing updates (manually by .msu), some Firewall rules were created without permission, resulting in some traffic leaking out

    Takeaway I get what I found so far is, that if I were to use Win10 as main operating system I would set firewall to block everything and only whitelist to allow basic networking and features:

    • ICMP protocol for "System" process to allow pinging
    • UDP port 53 svchost (dnscache service) for DNS resolving
    • UDP local port 68 remote port 67 for svchost-dhcp service if using DHCP
    • UDP port 123 for svchost-w32time for time synchronization

    From there on I would only whitelist network applications like browser/torrent/online games etc.
    For updating Windows it would be best to only download and install .msu packages manually every now and then (which would be very easy in Win10 as they are cumulative, so only one .msu file), making sure to go offline during update and then ensuring no unwanted firewall rules were created by the update process.

    Doing all this should block all spying traffic. What do you think?
     
  6. LiteOS

    LiteOS Windowizer

    Mar 7, 2014
    2,343
    1,048
    90
    #466 LiteOS, Aug 23, 2015
    Last edited: Aug 23, 2015
    cant find this key

    WFPLWFS Microsoft Windows Filtering Platform Microsoft Corporation c:\windows\system32\drivers\wfplwfs.sys 7/10/2015 6:23 AM

    cant be disabled

    cant find in xml also
     
  7. E*L*I*X

    E*L*I*X MDL Novice

    Aug 1, 2015
    27
    18
    0
    File filters.xml is in folder system32.
     

    Attached Files:

  8. mrbbq

    mrbbq MDL Addicted

    Jul 18, 2015
    510
    277
    30
    Can someone remember which service it is that "checks" KMS activations in with Microsoft? Can't seem to find the tip about it again.
     
  9. LiteOS

    LiteOS Windowizer

    Mar 7, 2014
    2,343
    1,048
    90
    is also related to

    Windows Firewall Helper Class
     
  10. E*L*I*X

    E*L*I*X MDL Novice

    Aug 1, 2015
    27
    18
    0
    First run this command
     

    Attached Files:

    • wfp.PNG
      wfp.PNG
      File size:
      23 KB
      Views:
      176
  11. LiteOS

    LiteOS Windowizer

    Mar 7, 2014
    2,343
    1,048
    90
    yea already create the xml file
     
  12. E*L*I*X

    E*L*I*X MDL Novice

    Aug 1, 2015
    27
    18
    0
    Study this file!
     
  13. elzna

    elzna MDL Senior Member

    Aug 28, 2013
    434
    56
    10
    or stop talking bs and if you know anything just tell it. stop giving hints
     
  14. E*L*I*X

    E*L*I*X MDL Novice

    Aug 1, 2015
    27
    18
    0
    @elzna

    This is very secret.
     
  15. winbond

    winbond MDL Novice

    Oct 27, 2009
    44
    13
    0
    #475 winbond, Aug 23, 2015
    Last edited: Aug 27, 2015
    here is my hosts list, it has a couple of extra entries that i gathered from other sources on the net,
    it's also alphabetically sorted... i merged most of the OP entries, except the skype ones

    h.t.t.p://pastebin.com/T3pZe1P5

    remove http dots

    there are some ips on the list, you have to block them in a firewall,
    putting them in a hostfile doesn't block them
     
  16. mrbbq

    mrbbq MDL Addicted

    Jul 18, 2015
    510
    277
    30
    Ah secret knowledge that nobody can follow how this will ever lead to anything, given out piecemeal, by someone new. Well I'm sold this is definitely going to be more effective than actual known working factually based techniques. Somehow.
    /puts down his MASSIVE SARCASM quotes.
     
  17. mrbbq

    mrbbq MDL Addicted

    Jul 18, 2015
    510
    277
    30
    What I was referring to was something that sends out to Microsoft whenever a KMS activation is made. Cannot for the life of me find what it was called now.
     
  18. E*L*I*X

    E*L*I*X MDL Novice

    Aug 1, 2015
    27
    18
    0
    Solution is here.
     

    Attached Files:

  19. terrybleger

    terrybleger MDL Novice

    Mar 5, 2012
    3
    0
    0
    Thank you so much for the app :clap:

    But I'm just wondering why the app name is S.M.R.T? I thought it was for hard disk related thing. I thought that Win 10 Collector Edition Blaster would be better since people will google how to blast off the collecting feature of Windows 10 for good.
     
  20. mrbbq

    mrbbq MDL Addicted

    Jul 18, 2015
    510
    277
    30
    Has anyone looked into what exactly the Tile Data model server service (their random capitals, not mine...) is up to, and why even with "apps" removed it cannot seem to be killed?

    Personally, I really really want to kill that one if possible.:tea: