Skip to content

OEM Endpoint Cleanup 2.2.0

Choose a tag to compare

@ithealthtech ithealthtech released this 20 Jul 01:49
265a157

OEM Endpoint Cleanup 2.2.0

This release turns PreloadedAVRemover into an audit-first OEM antivirus and bloatware cleanup utility for MSP onboarding and controlled endpoint deployment.

Highlights

  • Catalog-driven inventory across 63 entries covering major PC manufacturers, bundled security trials, support utilities, telemetry, promotional apps, AppX packages, services, tasks, and registry artifacts.
  • Conservative, Balanced, and Aggressive policy profiles with dry-run enabled by default.
  • Confidence scoring and evidence for catalog matches; ambiguous or low-confidence matches fail closed.
  • Independent safeguards for Microsoft Defender, active endpoint protection, RMM agents, VPNs, backup tools, firmware, drivers, hotkeys, recovery, and warranty-critical software.
  • Strict MSI, EXE, AppX/MSIX, and winget command validation with no shell execution of registry uninstall strings.
  • Process timeouts, exit-code capture, reboot reporting, before/after inventory, and hash-chained JSONL audit logs.
  • MSP-ready JSON and HTML reports plus a responsive WinForms interface.

Validation

  • 57 tests passed with 0 failures.
  • Release build and WinForms layout self-test passed.
  • Direct and transitive NuGet vulnerability audits reported no known vulnerable packages.
  • Windows x64 self-contained single-file publish passed.
  • Microsoft Defender found no threats in the release executable.

Important

  • The executable is not code-signed and may trigger Microsoft SmartScreen. Verify the published SHA-256 checksum before running it.
  • Vendor uninstallers vary and may require passwords, vendor cleanup tools, or manual intervention.
  • Uninstallation is not transactional; review the generated rollback guidance and test against representative hardware before broad deployment.
  • Endpoint protection removal remains disabled unless separately authorized and policy-approved.