Skip to content

v1.4.1

Latest

Choose a tag to compare

@github-actions github-actions released this 04 Oct 20:30

unslop-windows v1.4.1

Fixed

  • UCPD Kernel Driver Policy Interception (AllowNewsAndInterests): Neutralized the User Choice Protection Driver (UCPD.sys) in Stage 1 Services (Set-SvcState "UCPD" ... "Manual") and disabled the companion \Microsoft\Windows\AppxDeploymentClient\UCPD velocity scheduled task in Stage 11. In Set-RegDwordSafe, if a registry write to HKLM:\SOFTWARE\Policies\Microsoft\Dsh\AllowNewsAndInterests or TaskbarDa is intercepted by the active in-memory UCPD kernel filter driver before reboot, the policy is staged seamlessly via HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\unslop_<name> for automatic post-restart application, eliminating UnauthorizedAccessException and false failure alerts.
  • WindowsAI SYSTEM-Only Scheduled Tasks Access Denied: Filtered out internal Click to Do, Recall, and Settings Agent tasks (ModelCachingLimit, ModelCachingUpdate, PolicyConfiguration, Settings\InitialConfiguration) from \Microsoft\Windows\WindowsAI\* dynamic scans. These tasks have hardened Security Descriptors granting write access exclusively to NT AUTHORITY\SYSTEM ((A;;FRFX;;;BA)(A;;GA;;;SY)) and are already fully inert due to GPO policies and WSAIFabricSvc service neutralization.
  • Defensive ACL & Driver Service Handling: Hardened Set-SvcState to set service startup type to Disabled first and gracefully catch stop errors on non-unloadable kernel filter drivers. Hardened Set-TaskState to detect tasks with SYSTEM-only SDDLs and skip them with informative logging rather than raising unhandled exceptions. Symmetrically aligned unslop-win10.ps1 helper functions.

Added

  • Machine-Wide Search Highlights (WSB), Location & Cloud Search GPOs: Enforced EnableDynamicContentInWSB = 0 (disabling Bing dynamic search highlights and doodles machine-wide), AllowSearchToUseLocation = 0 (blocking location harvesting by SearchHost/Cortana), and AllowCloudSearch = 0 (disabling cloud account integration in search results) under HKLM:\SOFTWARE\Policies\Microsoft\Windows\Windows Search across both unslop-win11.ps1 and unslop-win10.ps1 with 100% symmetrical -Undo restoration.
  • Unit & AST Invariant Tests: Added automated tests to tests/unslop-win11.Tests.ps1 and tests/unslop-win10.Tests.ps1 verifying symmetrical UCPD management, SYSTEM-only AI task exclusion, and search machine GPO enforcement.
  • Architectural Decision Records (ADR-033 & ADR-034): Documented UCPD driver behavior, RunOnce staging mechanics, WindowsAI task security descriptor defenses, and machine-wide search policy hardening in docs/decisions.md.

Quick Installation & Usage

  1. Download unslop-windows-v1.4.1.zip from Assets below.
  2. Extract the archive to any directory.
  3. Right-click unslop.bat and choose Run as administrator (or double-click and accept the UAC elevation prompt).
  4. Select your operating system from the selection menu:
    • [1] Windows 11: Targets 26H2, 26H1, 25H2, 24H2, 23H2, 22H2, 21H2 (runs unslop-win11.ps1).
    • [2] Windows 10: Targets 22H2, 21H2, 20H2, Enterprise LTSC, Builds 10240-19045 (runs unslop-win10.ps1).
    • [0] Exit: Close the launcher.
  5. Choose an option from the OS feature menu:
    • [1] Full Debloat: Remove OneDrive, telemetry and provisioned bloatware.
    • [2] Gamer Preset: Debloat, keep Xbox & Gaming Services (-KeepXbox).
    • [3] Productivity Preset: Debloat, keep OneDrive & Microsoft To-Do (-KeepOneDrive -KeepTodos).
    • [4] Interactive Toggles: Configure custom feature combinations with visual toggle states.
    • [5] Safe Dry-Run Audit: Inspect all changes safely with zero system modifications (-DryRun).
    • [6] Full Restore / Undo: Symmetrically revert all tweaks back to defaults (-Undo).
    • [7] Custom CLI Flags: Manually enter parameter switches (e.g. -KeepTodos -KeepXbox -NoRestart).
    • [8] Back to OS Selection: Return to the main OS choice screen.
    • [0] Exit: Close the launcher.

Verification & Integrity

Verify archive integrity using the published SHA256SUMS.txt:

Get-FileHash .\unslop-windows-v1.4.1.zip -Algorithm SHA256