OEM Endpoint Cleanup 2.2.0
OEM Endpoint Cleanup 2.2.0
This release turns PreloadedAVRemover into an audit-first OEM antivirus and bloatware cleanup utility for MSP onboarding and controlled endpoint deployment.
Highlights
- Catalog-driven inventory across 63 entries covering major PC manufacturers, bundled security trials, support utilities, telemetry, promotional apps, AppX packages, services, tasks, and registry artifacts.
- Conservative, Balanced, and Aggressive policy profiles with dry-run enabled by default.
- Confidence scoring and evidence for catalog matches; ambiguous or low-confidence matches fail closed.
- Independent safeguards for Microsoft Defender, active endpoint protection, RMM agents, VPNs, backup tools, firmware, drivers, hotkeys, recovery, and warranty-critical software.
- Strict MSI, EXE, AppX/MSIX, and winget command validation with no shell execution of registry uninstall strings.
- Process timeouts, exit-code capture, reboot reporting, before/after inventory, and hash-chained JSONL audit logs.
- MSP-ready JSON and HTML reports plus a responsive WinForms interface.
Validation
- 57 tests passed with 0 failures.
- Release build and WinForms layout self-test passed.
- Direct and transitive NuGet vulnerability audits reported no known vulnerable packages.
- Windows x64 self-contained single-file publish passed.
- Microsoft Defender found no threats in the release executable.
Important
- The executable is not code-signed and may trigger Microsoft SmartScreen. Verify the published SHA-256 checksum before running it.
- Vendor uninstallers vary and may require passwords, vendor cleanup tools, or manual intervention.
- Uninstallation is not transactional; review the generated rollback guidance and test against representative hardware before broad deployment.
- Endpoint protection removal remains disabled unless separately authorized and policy-approved.