• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

[GUIDE] Make Windows10 Private / Performance Optimization

Joined
Feb 24, 2024
Messages
35 (0.48/day)
Yes you can make windows completely 100% private as if it was linux.
Ofcourse privacy doesn’t fix zero day security exploits, this guide is about privacy not security.
For a first impression of what a truely optimized windows system looks like check the screenshots below.

Make a backup of your data is always the first thing to do.

➤ (1) Download the official windows iso from microsofts website (The iso, NOT the mediacreationtool !!)
If you can’t download the iso, install the useragentswitcher browser extension and switch to linux (microsoft's website detects your operatingsystem and doesn't let you download the iso if you are on windows...)
Links:


➤ (2) Download rufus and use it to create a bootable usb drive with the windows iso file you downloaded.
Rufus - Create bootable USB drives the easy way
Links:

➤ (3) Use the bootable usb drive to install windows 10 pro offline
Plug the bootable usb drive in the mainboard and boot into BIOS mode, then change the primary boot device to the usb drive.
Next time you start your pc it will boot from the usb, proceed to install windows offline.


➤ (4) Use the performance-privacy-script website to generate a script that will rip the guts of microsoft out of windows, effectively optimizing performance and boosting privacy.
On the website use either one of the predefined settings (standard, strict, all) or create your own script with the options menu.
Be careful when creating your own script, you can break functionality like windows search, to keep functionality only standard and strict are recommended.
If you are creating a custom script i advise against disabling windows defender antivirus, turning this feature of causes some issues.
Links:

➤ (5) Install Device Drivers
If you have an nvidia GPU use NVCleanstall for the graphics driver installation, this tool will remove most of the integrated driver spyware and telemetry.
Uf using an nvidia GPU, use the store-rg-adguard website to download the nvidia controlpanel without the microsoftstore.
Install your CPU chipset, if using an intel CPU... DO NOT install intel management engine, these are known backdoors so the us-government can remotely access your device.
Additionally, remember to also install software to control fanspeeds.
Links:

➤ (6) Install Netframework Offline
Some programs (certain videogames for example) require old netframework version to work, the good part is you don't need windows update for that.
To install offline without using windowsupdate you need a copy of the windows iso you previously downloaded.
First mount the windows iso to your pc (via rightklick), then open powershell as administrator.
Use this command to install netframework:
Dism /online /enable-feature /featurename:NetFX3 /All /Source:X:\sources\sxs /LimitAccess
Replace Source:X: with whatever the location of your mounted iso is, for example:
To find out where your iso is mounted, open the windows explorer, rightklick on the mounted iso and select open file location.


➤ (7) Install Visual Studio Redistributables
Links:


➤ (8) Install Librewolf or Mullvad Webbrowser (no extensions required, ublockorigin is already preinstalled)
Librewolf is a modified version of firefox for increased privacy and security protection, while google chrome, microsoft edge and opera collect your entire browsing history and every website you visited, including content...
Mullvad is based on the tor browser but doesn't connect to tor, instead the preffered usage method is mullvadvpn.
Duckduckgo cannot be trusted anymore because they had a secret tracking agreement with microsoft.
Don't use startpage or waterfox either, both have been acquired by an adversting company called System1.
Links:
Private Search Engines:

➤ (9) Use ShutUp10 to modify windows privacy settings
Recommended: Klick on “actions” select “activate all privacy settings”, then manually uncheck what you need.
Examples: microphone, camera, bluetooth, notifications.
Links:

➤ (10) Go Online for the first time, instantly install the Portmaster privacy firewall.
In the portmaster setup process, select quad9 as your dns server, they are non-profit, unlike most other providers like your internetservicepovider (ISP) are commerical and spy on everything you do on the internet.
Configure portmaster to block all connections by default and only allow what you need. (must have for privacy)
Unlock the systemdnsclient in portmaster otherwise you cannot connect to the internet. (all other windows services can be fully blocked)
Klick on systemdnsclient and block any remaining microsoft-windows connections that you don't trust, for example:
go.microsoft.com
ctldl.windowsupdate.com
services.gfe.nvidia.com (block this if using an nvidia GPU, even if you used nvcleanstall)
There should not be many connections to block if you used to privacy-script linked above to cleanup windows.
In portmaster klick on the settings icon and scroll down until you reach the filterlists section, klick on bigtech and block companies you don't trust. (example, google, microsoft, facebook, apple, amazon)
Links:

➤ (11) Install a trusthworthy VPN to boost your privacy and prevent your internet provider to log all your traffic.
Mullvad is one of the most trusted vpn's, for privacy this is your choice. They charge 5 euro for 30 days.
There is also protonvpn, they offer a free plan and are based in switzerland.
If you are currently using one of these, nordvpn, expressvpn, surfshark, you're making a great mistake...
These providers are known to collect and share your data with advertising companys and law enforcement, hey also use google trackers, analytics, tracking, profiling...
Links:

➤ (12) Additional Useful Software
Obviously as you will do almost all of these steps offline you will have to downloaded all the software beforehand and copy it to an offline drive which you can access without any internet connection.
A usbdrive would be enough.
Additional useful software that you might need:

If you wish to delete certain parts of windows (bloatware) or take ownership of them which by default your administratoraccount has no access to,
use NSudo which is an extremely powerfull windows admin-tool that lets you take full control over windows.
Examples of what you might want to delete with nsudo:
OneDriveSetup.exe
CompatTelRunner.exe
CompPkgSrv.exe
upfc.exe
mobsync.exe
smartscreen.exe
MicrosoftEdgeUpdate.exe
ScreenClippingHost.exe
TextInputHost.exe
LocalBridge.exe
Microsoft.Photos.exe
WinStore.App.exe
SkypeApp.exe
SkypeBridge.exe
SkypeBackgroundHost.exe
NcsiUwpApp.exe
backgroundTaskHost.exe
taskhostw.exe
ctfmon.exe
HxTsr.exe
HxOutlook.exe
HxCalendarAppImm.exe
HxAccounts.exe
GameBarPresenceWriter.exe
Links:

➤ (12) You should know
• Website to find Privacy Tools https://privacytools.io/
• Website for Privacy Webbrowsers https://privacytests.org/
• Website for Privacy Alternatives https://alternativeto.net/
• Privacy Money Cash - Monero

• The Hated One https://yewtu.be/channel/UCjr2bPAyPV7t35MvcgT3W8Q
• Naomi Brockwell: NBTV https://yewtu.be/channel/UCSuHzQ3GrHSzoBbwrIq3LLA
• Mental Outlaw https://yewtu.be/channel/UC7YOGHUfC1Tb6E4pudI9STA
• Eric Murphy https://yewtu.be/channel/UC5KDiSAFxrDWhmysBcNqtMA
 
Joined
Nov 7, 2017
Messages
1,507 (0.64/day)
Location
Ibiza, Spain.
System Name Main
Processor R7 5950x
Motherboard MSI x570S Unify-X Max
Cooling D5 clone, 280 rad, two F14 + three F12S bottom/intake, two P14S + F14S (Rad) + two F14 (top)
Memory 2x8 GB Corsair Vengeance bdie 3600@CL16 1.35v
Video Card(s) GB 2080S WaterForce WB
Storage six M.2 pcie gen 4
Display(s) Sony 50X90J
Case Tt Level 20 HT
Audio Device(s) Asus Xonar AE, modded Sennheiser HD 558, Klipsch 2.1 THX
Power Supply Corsair RMx 750w
Mouse Logitech G903
Keyboard GSKILL Ripjaws
VR HMD NA
Software win 10 pro x64
Benchmark Scores TimeSpy score Fire Strike Ultra SuperPosition CB20
Good guide on how to do stuff,
but as long as those users are on any social platforms, it wont matter much.

ignoring some stuff isnt needed (i never installed Nvcp thru the store),
and even nvcleanstall wont be able to remove much, if you want to use GFE.

i cant figure a reason for going thru all this, maybe reduce "experience", instead of just staying offline :rolleyes:
 
Top