From f0a96c7eb3210e9a57f25de88e11e11f222fe0e1 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 20 Apr 2024 23:44:00 +0300 Subject: [PATCH 01/63] Delete tiny11 creator 22621.525.bat Legacy - replaced by the PowerShell script --- tiny11 creator 22621.525.bat | 234 ----------------------------------- 1 file changed, 234 deletions(-) delete mode 100644 tiny11 creator 22621.525.bat diff --git a/tiny11 creator 22621.525.bat b/tiny11 creator 22621.525.bat deleted file mode 100644 index 2fce1ebf..00000000 --- a/tiny11 creator 22621.525.bat +++ /dev/null @@ -1,234 +0,0 @@ -@echo off -setlocal EnableExtensions EnableDelayedExpansion - -title tiny11 builder alpha -echo Welcome to the tiny11 image creator! -timeout /t 3 /nobreak > nul -cls - -set DriveLetter= -set /p DriveLetter=Please enter the drive letter for the Windows 11 image: -set "DriveLetter=%DriveLetter%:" -echo. -if not exist "%DriveLetter%\sources\boot.wim" ( - echo.Can't find Windows OS Installation files in the specified Drive Letter.. - echo. - echo.Please enter the correct DVD Drive Letter.. - goto :Stop -) - -if not exist "%DriveLetter%\sources\install.wim" ( - echo.Can't find Windows OS Installation files in the specified Drive Letter.. - echo. - echo.Please enter the correct DVD Drive Letter.. - goto :Stop -) -md c:\tiny11 -echo Copying Windows image... -xcopy.exe /E /I /H /R /Y /J %DriveLetter% c:\tiny11 >nul -echo Copy complete! -sleep 2 -cls -echo Getting image information: -dism /Get-WimInfo /wimfile:c:\tiny11\sources\install.wim -set index= -set /p index=Please enter the image index: -set "index=%index%" -echo Mounting Windows image. This may take a while. -echo. -md c:\scratchdir -dism /mount-image /imagefile:c:\tiny11\sources\install.wim /index:%index% /mountdir:c:\scratchdir -echo Mounting complete! Performing removal of applications... -echo Removing Clipchamp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Clipchamp.Clipchamp_2.2.8.0_neutral_~_yxz26nhyzhsrt -echo Removing News... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.BingNews_4.2.27001.0_neutral_~_8wekyb3d8bbwe -echo Removing Weather... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.BingWeather_4.53.33420.0_neutral_~_8wekyb3d8bbwe -echo Removing Xbox... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.GamingApp_2021.427.138.0_neutral_~_8wekyb3d8bbwe -echo Removing GetHelp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.GetHelp_10.2201.421.0_neutral_~_8wekyb3d8bbwe -echo Removing GetStarted... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Getstarted_2021.2204.1.0_neutral_~_8wekyb3d8bbwe -echo Removing Office Hub... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.MicrosoftOfficeHub_18.2204.1141.0_neutral_~_8wekyb3d8bbwe -echo Removing Solitaire... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.MicrosoftSolitaireCollection_4.12.3171.0_neutral_~_8wekyb3d8bbwe -echo Removing PeopleApp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.People_2020.901.1724.0_neutral_~_8wekyb3d8bbwe -echo Removing PowerAutomate... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.PowerAutomateDesktop_10.0.3735.0_neutral_~_8wekyb3d8bbwe -echo Removing ToDo... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Todos_2.54.42772.0_neutral_~_8wekyb3d8bbwe -echo Removing Alarms... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsAlarms_2022.2202.24.0_neutral_~_8wekyb3d8bbwe -echo Removing Mail... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:microsoft.windowscommunicationsapps_16005.14326.20544.0_neutral_~_8wekyb3d8bbwe -echo Removing Feedback Hub... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsFeedbackHub_2022.106.2230.0_neutral_~_8wekyb3d8bbwe -echo Removing Maps... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsMaps_2022.2202.6.0_neutral_~_8wekyb3d8bbwe -echo Removing Sound Recorder... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsSoundRecorder_2021.2103.28.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxTCUI... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Xbox.TCUI_1.23.28004.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxGamingOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxGamingOverlay_2.622.3232.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxGameOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxGameOverlay_1.47.2385.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxSpeechToTextOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxSpeechToTextOverlay_1.17.29001.0_neutral_~_8wekyb3d8bbwe -echo Removing Your Phone... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.YourPhone_1.22022.147.0_neutral_~_8wekyb3d8bbwe -echo Removing Music... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.ZuneMusic_11.2202.46.0_neutral_~_8wekyb3d8bbwe -echo Removing Video... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.ZuneVideo_2019.22020.10021.0_neutral_~_8wekyb3d8bbwe -echo Removing Family... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftCorporationII.MicrosoftFamily_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing QuickAssist... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftCorporationII.QuickAssist_2022.414.1758.0_neutral_~_8wekyb3d8bbwe -echo Removing Teams... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftTeams_23002.403.1788.1930_x64__8wekyb3d8bbwe -echo Removing Cortana... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.549981C3F5F10_4.2204.13303.0_neutral_~_8wekyb3d8bbwe - -echo Removing of system apps complete! Now proceeding to removal of system packages... -timeout /t 1 /nobreak > nul -cls -echo Removing Internet Explorer... -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~11.0.22621.1 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.0.22621.525 > nul -echo Removing LA57: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-Kernel-LA57-FoD-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -echo Removing Handwriting: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -echo Removing OCR: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -echo Removing Speech: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -echo Removing TTS: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -echo Removing Media Player Legacy: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~wow64~en-US~10.0.22621.1 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~wow64~~10.0.22621.1 > nul -echo Removing Tablet PC Math: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-TabletPCMath-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul -echo Removing Wallpapers: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-Wallpaper-Content-Extended-FoD-Package~31bf3856ad364e35~amd64~~10.0.22621.525 > nul - -echo Removing Edge: -rd "C:\scratchdir\Program Files (x86)\Microsoft\Edge" /s /q -rd "C:\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" /s /q -echo Removing OneDrive: -takeown /f C:\scratchdir\Windows\System32\OneDriveSetup.exe -icacls C:\scratchdir\Windows\System32\OneDriveSetup.exe /grant Administrators:F /T /C -del /f /q /s "C:\scratchdir\Windows\System32\OneDriveSetup.exe" -echo Removal complete! -timeout /t 2 /nobreak > nul -cls -echo Loading registry... -reg load HKLM\zCOMPONENTS "c:\scratchdir\Windows\System32\config\COMPONENTS" >nul -reg load HKLM\zDEFAULT "c:\scratchdir\Windows\System32\config\default" >nul -reg load HKLM\zNTUSER "c:\scratchdir\Users\Default\ntuser.dat" >nul -reg load HKLM\zSOFTWARE "c:\scratchdir\Windows\System32\config\SOFTWARE" >nul -reg load HKLM\zSYSTEM "c:\scratchdir\Windows\System32\config\SYSTEM" >nul -echo Bypassing system requirements(on the system image): - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassCPUCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassRAMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassSecureBootCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassStorageCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassTPMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\MoSetup" /v "AllowUpgradesWithUnsupportedTPMOrCPU" /t REG_DWORD /d "1" /f >nul 2>&1 -echo Disabling Teams: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\Communications" /v "ConfigureChatAutoInstall" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Disabling Sponsored Apps: -Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OemPreInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start" /v "ConfigureStartPins" /t REG_SZ /d "{\"pinnedList\": [{}]}" /f >nul 2>&1 -echo Enabling Local Accounts on OOBE: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v "BypassNRO" /t REG_DWORD /d "1" /f >nul 2>&1 -copy /y %~dp0autounattend.xml c:\scratchdir\Windows\System32\Sysprep\autounattend.xml -echo Disabling Reserved Storage: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager" /v "ShippedWithReserves" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Disabling Chat icon: -Reg add "HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat" /v "ChatIcon" /t REG_DWORD /d "3" /f >nul 2>&1 -Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "TaskbarMn" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Tweaking complete! -echo Unmounting Registry... -reg unload HKLM\zCOMPONENTS >nul 2>&1 -reg unload HKLM\zDRIVERS >nul 2>&1 -reg unload HKLM\zDEFAULT >nul 2>&1 -reg unload HKLM\zNTUSER >nul 2>&1 -reg unload HKLM\zSCHEMA >nul 2>&1 -reg unload HKLM\zSOFTWARE >nul 2>&1 -reg unload HKLM\zSYSTEM >nul 2>&1 -echo Cleaning up image... -dism /image:c:\scratchdir /Cleanup-Image /StartComponentCleanup /ResetBase -echo Cleanup complete. -echo Unmounting image... -dism /unmount-image /mountdir:c:\scratchdir /commit -echo Exporting image... -Dism /Export-Image /SourceImageFile:c:\tiny11\sources\install.wim /SourceIndex:%index% /DestinationImageFile:c:\tiny11\sources\install2.wim /compress:max -del c:\tiny11\sources\install.wim -ren c:\tiny11\sources\install2.wim install.wim -echo Windows image completed. Continuing with boot.wim. -timeout /t 2 /nobreak > nul -cls -echo Mounting boot image: -dism /mount-image /imagefile:c:\tiny11\sources\boot.wim /index:2 /mountdir:c:\scratchdir -echo Loading registry... -reg load HKLM\zCOMPONENTS "c:\scratchdir\Windows\System32\config\COMPONENTS" >nul -reg load HKLM\zDEFAULT "c:\scratchdir\Windows\System32\config\default" >nul -reg load HKLM\zNTUSER "c:\scratchdir\Users\Default\ntuser.dat" >nul -reg load HKLM\zSOFTWARE "c:\scratchdir\Windows\System32\config\SOFTWARE" >nul -reg load HKLM\zSYSTEM "c:\scratchdir\Windows\System32\config\SYSTEM" >nul -echo Bypassing system requirements(on the setup image): - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassCPUCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassRAMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassSecureBootCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassStorageCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassTPMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\MoSetup" /v "AllowUpgradesWithUnsupportedTPMOrCPU" /t REG_DWORD /d "1" /f >nul 2>&1 -echo Tweaking complete! -echo Unmounting Registry... -reg unload HKLM\zCOMPONENTS >nul 2>&1 -reg unload HKLM\zDRIVERS >nul 2>&1 -reg unload HKLM\zDEFAULT >nul 2>&1 -reg unload HKLM\zNTUSER >nul 2>&1 -reg unload HKLM\zSCHEMA >nul 2>&1 -reg unload HKLM\zSOFTWARE >nul 2>&1 -reg unload HKLM\zSYSTEM >nul 2>&1 -echo Unmounting image... -dism /unmount-image /mountdir:c:\scratchdir /commit -cls -echo the tiny11 image is now completed. Proceeding with the making of the ISO... -echo Copying unattended file for bypassing MS account on OOBE... -copy /y %~dp0autounattend.xml c:\tiny11\autounattend.xml -echo. -echo Creating ISO image... -%~dp0oscdimg.exe -m -o -u2 -udfver102 -bootdata:2#p0,e,bc:\tiny11\boot\etfsboot.com#pEF,e,bc:\tiny11\efi\microsoft\boot\efisys.bin c:\tiny11 %~dp0tiny11.iso -echo Creation completed! Press any key to exit the script... -pause -echo Performing Cleanup... -rd c:\tiny11 /s /q -rd c:\scratchdir /s /q -exit - - - - - From 78efe85975c2fdaf4b85210182604eeb9207177e Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 20 Apr 2024 23:44:22 +0300 Subject: [PATCH 02/63] Delete tiny11 creator 25300.bat Legacy - replaced by the PowerShell script --- tiny11 creator 25300.bat | 233 --------------------------------------- 1 file changed, 233 deletions(-) delete mode 100644 tiny11 creator 25300.bat diff --git a/tiny11 creator 25300.bat b/tiny11 creator 25300.bat deleted file mode 100644 index e5806ff9..00000000 --- a/tiny11 creator 25300.bat +++ /dev/null @@ -1,233 +0,0 @@ -@echo off -setlocal EnableExtensions EnableDelayedExpansion - -title tiny11 builder alpha -echo Welcome to the tiny11 image creator! -timeout /t 3 /nobreak > nul -cls - -set DriveLetter= -set /p DriveLetter=Please enter the drive letter for the Windows 11 image: -set "DriveLetter=%DriveLetter%:" -echo. -if not exist "%DriveLetter%\sources\boot.wim" ( - echo.Can't find Windows OS Installation files in the specified Drive Letter.. - echo. - echo.Please enter the correct DVD Drive Letter.. - goto :Stop -) - -if not exist "%DriveLetter%\sources\install.wim" ( - echo.Can't find Windows OS Installation files in the specified Drive Letter.. - echo. - echo.Please enter the correct DVD Drive Letter.. - goto :Stop -) -md c:\tiny11 -echo Copying Windows image... -xcopy.exe /E /I /H /R /Y /J %DriveLetter% c:\tiny11 >nul -echo Copy complete! -sleep 2 -cls -echo Getting image information: -dism /Get-WimInfo /wimfile:c:\tiny11\sources\install.wim -set index= -set /p index=Please enter the image index: -set "index=%index%" -echo Mounting Windows image. This may take a while. -echo. -md c:\scratchdir -dism /mount-image /imagefile:c:\tiny11\sources\install.wim /index:%index% /mountdir:c:\scratchdir -echo Mounting complete! Performing removal of applications... -echo Removing Clipchamp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Clipchamp.Clipchamp_2.5.15.0_neutral_~_yxz26nhyzhsrt -echo Removing News... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.BingNews_4.12.21001.0_neutral_~_8wekyb3d8bbwe -echo Removing Weather... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.BingWeather_4.53.50023.0_neutral_~_8wekyb3d8bbwe -echo Removing Xbox... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.GamingApp_2021.427.138.0_neutral_~_8wekyb3d8bbwe -echo Removing GetHelp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.GetHelp_10.2206.2011.0_neutral_~_8wekyb3d8bbwe -echo Removing GetStarted... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Getstarted_2021.2204.1.0_neutral_~_8wekyb3d8bbwe -echo Removing Office Hub... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.MicrosoftOfficeHub_18.2204.1141.0_neutral_~_8wekyb3d8bbwe -echo Removing Solitaire... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.MicrosoftSolitaireCollection_4.12.3171.0_neutral_~_8wekyb3d8bbwe -echo Removing PeopleApp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.People_2020.901.1724.0_neutral_~_8wekyb3d8bbwe -echo Removing PowerAutomate... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.PowerAutomateDesktop_10.0.3735.0_neutral_~_8wekyb3d8bbwe -echo Removing ToDo... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Todos_2.54.42772.0_neutral_~_8wekyb3d8bbwe -echo Removing Alarms... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsAlarms_2022.2210.9.0_neutral_~_8wekyb3d8bbwe -echo Removing Mail... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:microsoft.windowscommunicationsapps_16005.14326.20544.0_neutral_~_8wekyb3d8bbwe -echo Removing Feedback Hub... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsFeedbackHub_2022.106.2230.0_neutral_~_8wekyb3d8bbwe -echo Removing Maps... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsMaps_2022.2208.6.0_neutral_~_8wekyb3d8bbwe -echo Removing Sound Recorder... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsSoundRecorder_2021.2208.27.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxTCUI... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Xbox.TCUI_1.23.28004.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxGamingOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxGamingOverlay_2.622.3232.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxGameOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxGameOverlay_1.47.2385.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxSpeechToTextOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxSpeechToTextOverlay_1.17.29001.0_neutral_~_8wekyb3d8bbwe -echo Removing Your Phone... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.YourPhone_1.22022.147.0_neutral_~_8wekyb3d8bbwe -echo Removing Music... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.ZuneMusic_11.2210.33.0_neutral_~_8wekyb3d8bbwe -echo Removing Video... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.ZuneVideo_2019.22120.10031.0_neutral_~_8wekyb3d8bbwe -echo Removing Family... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftCorporationII.MicrosoftFamily_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing QuickAssist... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftCorporationII.QuickAssist_2022.825.2016.0_neutral_~_8wekyb3d8bbwe -echo Removing Teams... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftTeams_23002.403.1788.1930_x64__8wekyb3d8bbwe -echo Removing Cortana... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.549981C3F5F10_4.2204.13303.0_neutral_~_8wekyb3d8bbwe - -echo Removing of system apps complete! Now proceeding to removal of system packages... -timeout /t 1 /nobreak > nul -cls -echo Removing Internet Explorer... -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~11.0.25300.1000 > nul -echo Removing LA57: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-Kernel-LA57-FoD-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -echo Removing Handwriting: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -echo Removing OCR: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -echo Removing Speech: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -echo Removing TTS: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -echo Removing Media Player Legacy: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~wow64~en-US~10.0.25300.1000 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~wow64~~10.0.25300.1000 > nul -echo Removing Tablet PC Math: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-TabletPCMath-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul -echo Removing Wallpapers: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-Wallpaper-Content-Extended-FoD-Package~31bf3856ad364e35~amd64~~10.0.25300.1000 > nul - -echo Removing Edge: -rd "C:\scratchdir\Program Files (x86)\Microsoft\Edge" /s /q -rd "C:\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" /s /q -echo Removing OneDrive: -takeown /f C:\scratchdir\Windows\System32\OneDriveSetup.exe -icacls C:\scratchdir\Windows\System32\OneDriveSetup.exe /grant Administrators:F /T /C -del /f /q /s "C:\scratchdir\Windows\System32\OneDriveSetup.exe" -echo Removal complete! -timeout /t 2 /nobreak > nul -cls -echo Loading registry... -reg load HKLM\zCOMPONENTS "c:\scratchdir\Windows\System32\config\COMPONENTS" >nul -reg load HKLM\zDEFAULT "c:\scratchdir\Windows\System32\config\default" >nul -reg load HKLM\zNTUSER "c:\scratchdir\Users\Default\ntuser.dat" >nul -reg load HKLM\zSOFTWARE "c:\scratchdir\Windows\System32\config\SOFTWARE" >nul -reg load HKLM\zSYSTEM "c:\scratchdir\Windows\System32\config\SYSTEM" >nul -echo Bypassing system requirements(on the system image): - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassCPUCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassRAMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassSecureBootCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassStorageCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassTPMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\MoSetup" /v "AllowUpgradesWithUnsupportedTPMOrCPU" /t REG_DWORD /d "1" /f >nul 2>&1 -echo Disabling Teams: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\Communications" /v "ConfigureChatAutoInstall" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Disabling Sponsored Apps: -Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OemPreInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start" /v "ConfigureStartPins" /t REG_SZ /d "{\"pinnedList\": [{}]}" /f >nul 2>&1 -echo Enabling Local Accounts on OOBE: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v "BypassNRO" /t REG_DWORD /d "1" /f >nul 2>&1 -copy /y %~dp0autounattend.xml c:\scratchdir\Windows\System32\Sysprep\autounattend.xml -echo Disabling Reserved Storage: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager" /v "ShippedWithReserves" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Disabling Chat icon: -Reg add "HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat" /v "ChatIcon" /t REG_DWORD /d "3" /f >nul 2>&1 -Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "TaskbarMn" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Tweaking complete! -echo Unmounting Registry... -reg unload HKLM\zCOMPONENTS >nul 2>&1 -reg unload HKLM\zDRIVERS >nul 2>&1 -reg unload HKLM\zDEFAULT >nul 2>&1 -reg unload HKLM\zNTUSER >nul 2>&1 -reg unload HKLM\zSCHEMA >nul 2>&1 -reg unload HKLM\zSOFTWARE >nul 2>&1 -reg unload HKLM\zSYSTEM >nul 2>&1 -echo Cleaning up image... -dism /image:c:\scratchdir /Cleanup-Image /StartComponentCleanup /ResetBase -echo Cleanup complete. -echo Unmounting image... -dism /unmount-image /mountdir:c:\scratchdir /commit -echo Exporting image... -Dism /Export-Image /SourceImageFile:c:\tiny11\sources\install.wim /SourceIndex:%index% /DestinationImageFile:c:\tiny11\sources\install2.wim /compress:max -del c:\tiny11\sources\install.wim -ren c:\tiny11\sources\install2.wim install.wim -echo Windows image completed. Continuing with boot.wim. -timeout /t 2 /nobreak > nul -cls -echo Mounting boot image: -dism /mount-image /imagefile:c:\tiny11\sources\boot.wim /index:2 /mountdir:c:\scratchdir -echo Loading registry... -reg load HKLM\zCOMPONENTS "c:\scratchdir\Windows\System32\config\COMPONENTS" >nul -reg load HKLM\zDEFAULT "c:\scratchdir\Windows\System32\config\default" >nul -reg load HKLM\zNTUSER "c:\scratchdir\Users\Default\ntuser.dat" >nul -reg load HKLM\zSOFTWARE "c:\scratchdir\Windows\System32\config\SOFTWARE" >nul -reg load HKLM\zSYSTEM "c:\scratchdir\Windows\System32\config\SYSTEM" >nul -echo Bypassing system requirements(on the setup image): - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassCPUCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassRAMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassSecureBootCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassStorageCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassTPMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\MoSetup" /v "AllowUpgradesWithUnsupportedTPMOrCPU" /t REG_DWORD /d "1" /f >nul 2>&1 -echo Tweaking complete! -echo Unmounting Registry... -reg unload HKLM\zCOMPONENTS >nul 2>&1 -reg unload HKLM\zDRIVERS >nul 2>&1 -reg unload HKLM\zDEFAULT >nul 2>&1 -reg unload HKLM\zNTUSER >nul 2>&1 -reg unload HKLM\zSCHEMA >nul 2>&1 -reg unload HKLM\zSOFTWARE >nul 2>&1 -reg unload HKLM\zSYSTEM >nul 2>&1 -echo Unmounting image... -dism /unmount-image /mountdir:c:\scratchdir /commit -cls -echo the tiny11 image is now completed. Proceeding with the making of the ISO... -echo Copying unattended file for bypassing MS account on OOBE... -copy /y %~dp0autounattend.xml c:\tiny11\autounattend.xml -echo. -echo Creating ISO image... -%~dp0oscdimg.exe -m -o -u2 -udfver102 -bootdata:2#p0,e,bc:\tiny11\boot\etfsboot.com#pEF,e,bc:\tiny11\efi\microsoft\boot\efisys.bin c:\tiny11 %~dp0tiny11.iso -echo Creation completed! Press any key to exit the script... -pause -echo Performing Cleanup... -rd c:\tiny11 /s /q -rd c:\scratchdir /s /q -exit - - - - - From 6ce347e6f9eed5970bfb87a5092d951e9b04d5ab Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 20 Apr 2024 23:44:47 +0300 Subject: [PATCH 03/63] Delete tiny11 creator.bat Legacy - Replaced by the PowerShell script --- tiny11 creator.bat | 234 --------------------------------------------- 1 file changed, 234 deletions(-) delete mode 100644 tiny11 creator.bat diff --git a/tiny11 creator.bat b/tiny11 creator.bat deleted file mode 100644 index 227e24a1..00000000 --- a/tiny11 creator.bat +++ /dev/null @@ -1,234 +0,0 @@ -@echo off -setlocal EnableExtensions EnableDelayedExpansion - -title tiny11 builder alpha -echo Welcome to the tiny11 image creator! -timeout /t 3 /nobreak > nul -cls - -set DriveLetter= -set /p DriveLetter=Please enter the drive letter for the Windows 11 image: -set "DriveLetter=%DriveLetter%:" -echo. -if not exist "%DriveLetter%\sources\boot.wim" ( - echo.Can't find Windows OS Installation files in the specified Drive Letter.. - echo. - echo.Please enter the correct DVD Drive Letter.. - goto :Stop -) - -if not exist "%DriveLetter%\sources\install.wim" ( - echo.Can't find Windows OS Installation files in the specified Drive Letter.. - echo. - echo.Please enter the correct DVD Drive Letter.. - goto :Stop -) -md c:\tiny11 -echo Copying Windows image... -xcopy.exe /E /I /H /R /Y /J %DriveLetter% c:\tiny11 >nul -echo Copy complete! -sleep 2 -cls -echo Getting image information: -dism /Get-WimInfo /wimfile:c:\tiny11\sources\install.wim -set index= -set /p index=Please enter the image index: -set "index=%index%" -echo Mounting Windows image. This may take a while. -echo. -md c:\scratchdir -dism /mount-image /imagefile:c:\tiny11\sources\install.wim /index:%index% /mountdir:c:\scratchdir -echo Mounting complete! Performing removal of applications... -echo Removing Clipchamp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Clipchamp.Clipchamp_2.2.8.0_neutral_~_yxz26nhyzhsrt -echo Removing News... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.BingNews_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing Weather... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.BingWeather_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Xbox... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.GamingApp_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing GetHelp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.GetHelp_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing GetStarted... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Getstarted_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Office Hub... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.MicrosoftOfficeHub_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Solitaire... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.MicrosoftSolitaireCollection_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing PeopleApp... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.People_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing PowerAutomate... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.PowerAutomateDesktop_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing ToDo... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Todos_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Alarms... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsAlarms_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing Mail... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:microsoft.windowscommunicationsapps_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Feedback Hub... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsFeedbackHub_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Maps... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsMaps_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Sound Recorder... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.WindowsSoundRecorder_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxTCUI... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.Xbox.TCUI_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxGamingOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxGamingOverlay_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxGameOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxGameOverlay_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing XboxSpeechToTextOverlay... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.XboxSpeechToTextOverlay_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing Your Phone... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.YourPhone_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Music... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.ZuneMusic_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing Video... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.ZuneVideo_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing Family... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftCorporationII.MicrosoftFamily_2022.507.447.0_neutral_~_8wekyb3d8bbwe -echo Removing QuickAssist... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftCorporationII.QuickAssist_2022.507.446.0_neutral_~_8wekyb3d8bbwe -echo Removing Teams... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:MicrosoftTeams_23002.403.1788.1930_x64__8wekyb3d8bbwe -echo Removing Cortana... -dism /image:c:\scratchdir /Remove-ProvisionedAppxPackage /PackageName:Microsoft.549981C3F5F10_4.2204.13303.0_neutral_~_8wekyb3d8bbwe - -echo Removing of system apps complete! Now proceeding to removal of system packages... -timeout /t 1 /nobreak > nul -cls -echo Removing Internet Explorer... -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~en-US~11.0.22621.1 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35~amd64~~11.0.22621.1265 > nul -echo Removing LA57: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-Kernel-LA57-FoD-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -echo Removing Handwriting: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-Handwriting-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -echo Removing OCR: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-OCR-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -echo Removing Speech: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-Speech-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -echo Removing TTS: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-LanguageFeatures-TextToSpeech-en-us-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -echo Removing Media Player Legacy: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~wow64~en-US~10.0.22621.1 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35~wow64~~10.0.22621.1 > nul -echo Removing Tablet PC Math: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-TabletPCMath-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul -echo Removing Wallpapers: -dism /image:c:\scratchdir /Remove-Package /PackageName:Microsoft-Windows-Wallpaper-Content-Extended-FoD-Package~31bf3856ad364e35~amd64~~10.0.22621.1265 > nul - -echo Removing Edge: -rd "C:\scratchdir\Program Files (x86)\Microsoft\Edge" /s /q -rd "C:\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" /s /q -echo Removing OneDrive: -takeown /f C:\scratchdir\Windows\System32\OneDriveSetup.exe -icacls C:\scratchdir\Windows\System32\OneDriveSetup.exe /grant Administrators:F /T /C -del /f /q /s "C:\scratchdir\Windows\System32\OneDriveSetup.exe" -echo Removal complete! -timeout /t 2 /nobreak > nul -cls -echo Loading registry... -reg load HKLM\zCOMPONENTS "c:\scratchdir\Windows\System32\config\COMPONENTS" >nul -reg load HKLM\zDEFAULT "c:\scratchdir\Windows\System32\config\default" >nul -reg load HKLM\zNTUSER "c:\scratchdir\Users\Default\ntuser.dat" >nul -reg load HKLM\zSOFTWARE "c:\scratchdir\Windows\System32\config\SOFTWARE" >nul -reg load HKLM\zSYSTEM "c:\scratchdir\Windows\System32\config\SYSTEM" >nul -echo Bypassing system requirements(on the system image): - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassCPUCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassRAMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassSecureBootCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassStorageCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassTPMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\MoSetup" /v "AllowUpgradesWithUnsupportedTPMOrCPU" /t REG_DWORD /d "1" /f >nul 2>&1 -echo Disabling Teams: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\Communications" /v "ConfigureChatAutoInstall" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Disabling Sponsored Apps: -Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "OemPreInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "PreInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager" /v "SilentInstalledAppsEnabled" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent" /v "DisableWindowsConsumerFeatures" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start" /v "ConfigureStartPins" /t REG_SZ /d "{\"pinnedList\": [{}]}" /f >nul 2>&1 -echo Enabling Local Accounts on OOBE: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE" /v "BypassNRO" /t REG_DWORD /d "1" /f >nul 2>&1 -copy /y %~dp0autounattend.xml c:\scratchdir\Windows\System32\Sysprep\autounattend.xml -echo Disabling Reserved Storage: -Reg add "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager" /v "ShippedWithReserves" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Disabling Chat icon: -Reg add "HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat" /v "ChatIcon" /t REG_DWORD /d "3" /f >nul 2>&1 -Reg add "HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "TaskbarMn" /t REG_DWORD /d "0" /f >nul 2>&1 -echo Tweaking complete! -echo Unmounting Registry... -reg unload HKLM\zCOMPONENTS >nul 2>&1 -reg unload HKLM\zDRIVERS >nul 2>&1 -reg unload HKLM\zDEFAULT >nul 2>&1 -reg unload HKLM\zNTUSER >nul 2>&1 -reg unload HKLM\zSCHEMA >nul 2>&1 -reg unload HKLM\zSOFTWARE >nul 2>&1 -reg unload HKLM\zSYSTEM >nul 2>&1 -echo Cleaning up image... -dism /image:c:\scratchdir /Cleanup-Image /StartComponentCleanup /ResetBase -echo Cleanup complete. -echo Unmounting image... -dism /unmount-image /mountdir:c:\scratchdir /commit -echo Exporting image... -Dism /Export-Image /SourceImageFile:c:\tiny11\sources\install.wim /SourceIndex:%index% /DestinationImageFile:c:\tiny11\sources\install2.wim /compress:max -del c:\tiny11\sources\install.wim -ren c:\tiny11\sources\install2.wim install.wim -echo Windows image completed. Continuing with boot.wim. -timeout /t 2 /nobreak > nul -cls -echo Mounting boot image: -dism /mount-image /imagefile:c:\tiny11\sources\boot.wim /index:2 /mountdir:c:\scratchdir -echo Loading registry... -reg load HKLM\zCOMPONENTS "c:\scratchdir\Windows\System32\config\COMPONENTS" >nul -reg load HKLM\zDEFAULT "c:\scratchdir\Windows\System32\config\default" >nul -reg load HKLM\zNTUSER "c:\scratchdir\Users\Default\ntuser.dat" >nul -reg load HKLM\zSOFTWARE "c:\scratchdir\Windows\System32\config\SOFTWARE" >nul -reg load HKLM\zSYSTEM "c:\scratchdir\Windows\System32\config\SYSTEM" >nul -echo Bypassing system requirements(on the setup image): - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV1" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache" /v "SV2" /t REG_DWORD /d "0" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassCPUCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassRAMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassSecureBootCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassStorageCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\LabConfig" /v "BypassTPMCheck" /t REG_DWORD /d "1" /f >nul 2>&1 - Reg add "HKLM\zSYSTEM\Setup\MoSetup" /v "AllowUpgradesWithUnsupportedTPMOrCPU" /t REG_DWORD /d "1" /f >nul 2>&1 -echo Tweaking complete! -echo Unmounting Registry... -reg unload HKLM\zCOMPONENTS >nul 2>&1 -reg unload HKLM\zDRIVERS >nul 2>&1 -reg unload HKLM\zDEFAULT >nul 2>&1 -reg unload HKLM\zNTUSER >nul 2>&1 -reg unload HKLM\zSCHEMA >nul 2>&1 -reg unload HKLM\zSOFTWARE >nul 2>&1 -reg unload HKLM\zSYSTEM >nul 2>&1 -echo Unmounting image... -dism /unmount-image /mountdir:c:\scratchdir /commit -cls -echo the tiny11 image is now completed. Proceeding with the making of the ISO... -echo Copying unattended file for bypassing MS account on OOBE... -copy /y %~dp0autounattend.xml c:\tiny11\autounattend.xml -echo. -echo Creating ISO image... -%~dp0oscdimg.exe -m -o -u2 -udfver102 -bootdata:2#p0,e,bc:\tiny11\boot\etfsboot.com#pEF,e,bc:\tiny11\efi\microsoft\boot\efisys.bin c:\tiny11 %~dp0tiny11.iso -echo Creation completed! Press any key to exit the script... -pause -echo Performing Cleanup... -rd c:\tiny11 /s /q -rd c:\scratchdir /s /q -exit - - - - - From c7001dc2d2f42e24ed19bd4023a5aa4336434df6 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 20 Apr 2024 23:51:16 +0300 Subject: [PATCH 04/63] Update README.md --- README.md | 32 ++++++++++++++++---------------- 1 file changed, 16 insertions(+), 16 deletions(-) diff --git a/README.md b/README.md index 83adab8d..0cf4c5c0 100644 --- a/README.md +++ b/README.md @@ -1,22 +1,24 @@ # tiny11builder -Scripts to build a trimmed-down Windows 11 image. - -This is a script to automate the build of a streamlined Windows 11 image, similar to tiny11. -My main goal is to use only Microsoft utilities like DISM, and nothing external. The only executable included is oscdimg.exe, which is provided in the Windows ADK and it is used to create bootable ISO images. Also included is an unattended answer file, which is used to bypass the MS account on OOBE and to deploy the image with the /compact flag. +Scripts to build a trimmed-down Windows 11 image - now in PowerShell! +Tiny11 builder, now completely overhauled. +After more than a year (for which I am so sorry) of no updates, tiny11 builder is now a much more complete and flexible solution - one script fits all. +You can now use it on ANY Windows 11 release (not just a specific build), as well as ANY language or architecture. +This was made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release. + +This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny11. +My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is oscdimg.exe, which is provided in the Windows ADK and it is used to create bootable ISO images. +Also included is an unattended answer file, which is used to bypass the Microsoft Account on OOBE and to deploy the image with the /compact flag. It's open-source, so feel free to add or remove anything you want! Feedback is also much appreciated. -As of now, only build 22621.525 (the one that can be downloaded from the Microsoft website), 22621.1265 (the latest public build) and 25300 (latest Insider build as of now) are supported. - Instructions: -1. Download Windows 11 22621.1265 from UUPDump or 22621.525 or 25300 from the Microsoft website () +1. Download Windows 11 from the Microsoft website () 2. Mount the downloaded ISO image using Windows Explorer. -3. For .1265, run tiny11 creator.bat as administrator. For .525 or 25300, use the aptly-named script (also as administrator). -4. Select the drive letter where the image is mounted (only the letter, no colon (:)) -5. Select the SKU that you want the image to be based. -6. Sit back and relax :) -7. When the image is completed, you will see it in the folder where the script was extracted, with the name tiny11.iso +3. Select the drive letter where the image is mounted (only the letter, no colon (:)) +4. Select the SKU that you want the image to be based. +5. Sit back and relax :) +6. When the image is completed, you will see it in the folder where the script was extracted, with the name tiny11.iso What is removed: Clipchamp, @@ -51,10 +53,8 @@ OneDrive Known issues: -1. Microsoft Teams (personal) and Cortana are still here. If you find a way to remove them before I find one, feel free to help! -2. Although Edge is removed, the icon and a ghost of its taskbar pin are still available. Also, there are some remnants in the Settings. But the app in itself is deleted. -3. The script is rather inflexible, as in only the builds specified can be modified. This is because with each new build Microsoft also updates the inbox apps included. If one tries to use other builds, it will work with varying degrees of success, but some things like the removal of Edge and OneDrive as well as bypassing system requirements or other patches will always be applied. -4. Only en-us x64 is supported as of now. This can be easily fixable by the end user, just by replacing every instance of en-us with the language needed (like ro-RO and so on), and every x64 instance with arm64. +1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install a browser using WinGet (after you update the app using Microsoft Store) +2. Outlook and Dev Home might reappear after some time. And that's pretty much it for now! Thanks for trying it and let me know how you like it! From de24916ffc0b0fb921d2a8dfccaabcef79c2f040 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 20 Apr 2024 23:58:23 +0300 Subject: [PATCH 05/63] Update README.md --- README.md | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 0cf4c5c0..17f7c58c 100644 --- a/README.md +++ b/README.md @@ -2,9 +2,17 @@ Scripts to build a trimmed-down Windows 11 image - now in PowerShell! Tiny11 builder, now completely overhauled. -After more than a year (for which I am so sorry) of no updates, tiny11 builder is now a much more complete and flexible solution - one script fits all. +After more than a year (for which I am so sorry) of no updates, tiny11 builder is now a much more complete and flexible solution - one script fits all. Also, it is a steppingstone for an even more fleshed-out solution. + You can now use it on ANY Windows 11 release (not just a specific build), as well as ANY language or architecture. -This was made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release. +This is made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release. + +Since it is written in PowerShell, make sure to set the execution policy to Unrestricted, so that you could run the script. +If you haven't done this, make sure to run: +
Set-ExecutionPolicy unrestricted
+as administrator in PowerShell before running the script, otherwise it would just crash. + + This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny11. My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is oscdimg.exe, which is provided in the Windows ADK and it is used to create bootable ISO images. @@ -53,7 +61,7 @@ OneDrive Known issues: -1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install a browser using WinGet (after you update the app using Microsoft Store) +1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store) 2. Outlook and Dev Home might reappear after some time. And that's pretty much it for now! From 491145ce4c407bbd7d098788484717fed906392b Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sun, 21 Apr 2024 00:00:39 +0300 Subject: [PATCH 06/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 17f7c58c..f54c8707 100644 --- a/README.md +++ b/README.md @@ -8,7 +8,7 @@ You can now use it on ANY Windows 11 release (not just a specific build), as wel This is made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release. Since it is written in PowerShell, make sure to set the execution policy to Unrestricted, so that you could run the script. -If you haven't done this, make sure to run: +If you haven't done this before, make sure to run:
Set-ExecutionPolicy unrestricted
as administrator in PowerShell before running the script, otherwise it would just crash. From c2679204e0e20ecd770414069a0d8b9861136ddb Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sun, 21 Apr 2024 03:01:25 +0300 Subject: [PATCH 07/63] Update README.md --- README.md | 13 +++++-------- 1 file changed, 5 insertions(+), 8 deletions(-) diff --git a/README.md b/README.md index f54c8707..4c8b6552 100644 --- a/README.md +++ b/README.md @@ -1,12 +1,14 @@ # tiny11builder Scripts to build a trimmed-down Windows 11 image - now in PowerShell! +
Tiny11 builder, now completely overhauled. +
After more than a year (for which I am so sorry) of no updates, tiny11 builder is now a much more complete and flexible solution - one script fits all. Also, it is a steppingstone for an even more fleshed-out solution. - +
You can now use it on ANY Windows 11 release (not just a specific build), as well as ANY language or architecture. This is made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release. - +
Since it is written in PowerShell, make sure to set the execution policy to Unrestricted, so that you could run the script. If you haven't done this before, make sure to run:
Set-ExecutionPolicy unrestricted
@@ -49,13 +51,7 @@ Your Phone, Media Player, QuickAssist, Internet Explorer, -LA57 support, -OCR for en-us, -Speech support, -TTS for en-us, -Media Player Legacy, Tablet PC Math, -Wallpapers, Edge, OneDrive @@ -63,6 +59,7 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store) 2. Outlook and Dev Home might reappear after some time. +3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. And that's pretty much it for now! Thanks for trying it and let me know how you like it! From 3c72acf1f146f19e8c3f20195102bc2aa44ba343 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sun, 21 Apr 2024 03:02:55 +0300 Subject: [PATCH 08/63] Added tiny11 builder rewritten in PowerShell --- tiny11maker.ps1 | 267 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 267 insertions(+) create mode 100644 tiny11maker.ps1 diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 new file mode 100644 index 00000000..c97105a0 --- /dev/null +++ b/tiny11maker.ps1 @@ -0,0 +1,267 @@ +if ((Get-ExecutionPolicy) -eq 'Restricted') { + Write-Host "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" + $response = Read-Host + if ($response -eq 'yes') { + Set-ExecutionPolicy RemoteSigned -Scope CurrentUser -Confirm:$false + } else { + Write-Host "The script cannot be run without changing the execution policy. Exiting..." + exit + } +} +$myWindowsID=[System.Security.Principal.WindowsIdentity]::GetCurrent() +$myWindowsPrincipal=new-object System.Security.Principal.WindowsPrincipal($myWindowsID) +$adminRole=[System.Security.Principal.WindowsBuiltInRole]::Administrator +if ($myWindowsPrincipal.IsInRole($adminRole)) +{ + $Host.UI.RawUI.WindowTitle = "tiny11 builder" + Clear-Host +} +else +{ + $newProcess = new-object System.Diagnostics.ProcessStartInfo "PowerShell"; + $newProcess.Arguments = $myInvocation.MyCommand.Definition; + $newProcess.Verb = "runas"; + [System.Diagnostics.Process]::Start($newProcess); + exit +} +Write-Host "Welcome to the tiny11 image creator!" +Start-Sleep -Seconds 3 +Clear-Host +$mainOSDrive = $env:SystemDrive + +$DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" +$DriveLetter = $DriveLetter + ":" + +if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { + Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." + Write-Host "Please enter the correct DVD Drive Letter.." + exit +} + +New-Item -ItemType Directory -Force -Path "$mainOSDrive\tiny11" +Write-Host "Copying Windows image..." +Copy-Item -Path "$DriveLetter\*" -Destination "$mainOSDrive\tiny11" -Recurse -Force +Write-Host "Copy complete!" +Start-Sleep -Seconds 2 +Clear-Host +Write-Host "Getting image information:" +& 'dism' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" +$index = Read-Host "Please enter the image index" +Write-Host "Mounting Windows image. This may take a while." +$wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" +& takeown "/F" $wimFilePath +& icacls $wimFilePath "/grant" "Administrators:(F)" +Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false +New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" +& dism "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" + +$imageIntl = & dism /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" +$languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default system UI language : ([a-zA-Z]{2}-[a-zA-Z]{2})' } + +if ($languageLine) { + $languageCode = $Matches[1] + Write-Host "Default system UI language code: $languageCode" +} else { + Write-Host "Default system UI language code not found." +} + +$imageInfo = & 'dism' '/Get-WimInfo' "/wimFile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" +$lines = $imageInfo -split '\r?\n' + +foreach ($line in $lines) { + if ($line -like '*Architecture : *') { + $architecture = $line -replace 'Architecture : ','' + # If the architecture is x64, replace it with amd64 + if ($architecture -eq 'x64') { + $architecture = 'amd64' + } + Write-Host "Architecture: $architecture" + break + } +} + +if (-not $architecture) { + Write-Host "Architecture information not found." +} + + +Write-Host "Mounting complete! Performing removal of applications..." + +$packages = & 'dism' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | + ForEach-Object { + if ($_ -match 'PackageName : (.*)') { + $matches[1] + } + } +$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_' + +$packagesToRemove = $packages | Where-Object { + $packageName = $_ + $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "$_*" }) +} +foreach ($package in $packagesToRemove) { + & 'dism' "/image:$($env:SystemDrive)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" +} + + +Write-Host "Removing Edge:" +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force +if ($architecture -eq 'amd64') { + $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "amd64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName + + if ($folderPath) { + & 'takeown' '/f' $folderPath '/r' + & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' + Remove-Item -Path $folderPath -Recurse -Force + } else { + Write-Host "Folder not found." + } +} elseif ($architecture -eq 'arm64') { + $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName + + if ($folderPath) { + & 'takeown' '/f' $folderPath '/r' + & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' + Remove-Item -Path $folderPath -Recurse -Force + } else { + Write-Host "Folder not found." + } +} else { + Write-Host "Unknown architecture: $architecture" +} +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' 'Administrators:F' '/T' '/C' +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force +Write-Host "Removing OneDrive:" +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' 'Administrators:F' '/T' '/C' +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" -Force +Write-Host "Removal complete!" +Start-Sleep -Seconds 2 +Clear-Host +Write-Host "Loading registry..." +reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS +reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default +reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat +reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE +reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM +Write-Host "Bypassing system requirements(on the system image):" +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' +Write-Host "Disabling Teams:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\Communications' '/v' 'ConfigureChatAutoInstall' '/t' 'REG_DWORD' '/d' '0' '/f' +Write-Host "Disabling Sponsored Apps:" +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSoftware\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSoftware\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' +Write-Host "Enabling Local Accounts on OOBE:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force +Write-Host "Disabling Reserved Storage:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' +Write-Host "Disabling Chat icon:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' +Write-Host "Tweaking complete!" +Write-Host "Unmounting Registry..." +reg unload HKLM\zCOMPONENTS +reg unload HKLM\zDRIVERS +reg unload HKLM\zDEFAULT +reg unload HKLM\zNTUSER +reg unload HKLM\zSCHEMA +reg unload HKLM\zSOFTWARE +reg unload HKLM\zSYSTEM +Write-Host "Cleaning up image..." +& 'dism' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' +Write-Host "Cleanup complete." +Write-Host "Unmounting image..." +& 'dism' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +Write-Host "Exporting image..." +& 'Dism' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' +Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force +Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" +Write-Host "Windows image completed. Continuing with boot.wim." +Start-Sleep -Seconds 2 +Clear-Host +Write-Host "Mounting boot image:" +$wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" +& takeown "/F" $wimFilePath +& icacls $wimFilePath "/grant" "Administrators:(F)" +Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false +& 'dism' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" +Write-Host "Loading registry..." +reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS +reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default +reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat +reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE +reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM +Write-Host "Bypassing system requirements(on the setup image):" +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' +Write-Host "Tweaking complete!" +Write-Host "Unmounting Registry..." +reg unload HKLM\zCOMPONENTS +reg unload HKLM\zDRIVERS +reg unload HKLM\zDEFAULT +reg unload HKLM\zNTUSER +reg unload HKLM\zSCHEMA +reg unload HKLM\zSOFTWARE +reg unload HKLM\zSYSTEM +Write-Host "Unmounting image..." +& 'dism' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +Clear-Host +Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." +Write-Host "Copying unattended file for bypassing MS account on OOBE..." +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force +Write-Host "Creating ISO image..." +& "$PSScriptRoot\oscdimg.exe" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$mainOSDrive\tiny11\boot\etfsboot.com#pEF,e,b$mainOSDrive\tiny11\efi\microsoft\boot\efisys.bin" "$mainOSDrive\tiny11" "$PSScriptRoot\tiny11.iso" +Write-Host "Creation completed! Press any key to exit the script..." +Read-Host "Press Enter to continue" +Write-Host "Performing Cleanup..." +Remove-Item -Path "$mainOSDrive\tiny11" -Recurse -Force +Remove-Item -Path "$mainOSDrive\scratchdir" -Recurse -Force +exit \ No newline at end of file From beab8214d582bae7a48a1e7afdfe5ba957f580f7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Viktor=20Sz=C3=A9pe?= Date: Mon, 22 Apr 2024 08:40:16 +0000 Subject: [PATCH 09/63] Indent with 4 spaces --- autounattend.xml | 74 ++++++++++++++++++++++++------------------------ tiny11maker.ps1 | 20 ++++++------- 2 files changed, 47 insertions(+), 47 deletions(-) diff --git a/autounattend.xml b/autounattend.xml index 9d845e55..ba07e9d6 100644 --- a/autounattend.xml +++ b/autounattend.xml @@ -1,37 +1,37 @@ - - - - - - true - - - - - false - - - - - OnError - - - - true - OnError - - - /IMAGE/INDEX - 1 - - - - - - - - - - - - + + + + + + true + + + + + false + + + + + OnError + + + + true + OnError + + + /IMAGE/INDEX + 1 + + + + + + + + + + + + diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index c97105a0..fab8207a 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -13,16 +13,16 @@ $myWindowsPrincipal=new-object System.Security.Principal.WindowsPrincipal($myWin $adminRole=[System.Security.Principal.WindowsBuiltInRole]::Administrator if ($myWindowsPrincipal.IsInRole($adminRole)) { - $Host.UI.RawUI.WindowTitle = "tiny11 builder" - Clear-Host + $Host.UI.RawUI.WindowTitle = "tiny11 builder" + Clear-Host } else { - $newProcess = new-object System.Diagnostics.ProcessStartInfo "PowerShell"; - $newProcess.Arguments = $myInvocation.MyCommand.Definition; - $newProcess.Verb = "runas"; - [System.Diagnostics.Process]::Start($newProcess); - exit + $newProcess = new-object System.Diagnostics.ProcessStartInfo "PowerShell"; + $newProcess.Arguments = $myInvocation.MyCommand.Definition; + $newProcess.Verb = "runas"; + [System.Diagnostics.Process]::Start($newProcess); + exit } Write-Host "Welcome to the tiny11 image creator!" Start-Sleep -Seconds 3 @@ -33,9 +33,9 @@ $DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image $DriveLetter = $DriveLetter + ":" if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { - Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." - Write-Host "Please enter the correct DVD Drive Letter.." - exit + Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." + Write-Host "Please enter the correct DVD Drive Letter.." + exit } New-Item -ItemType Directory -Force -Path "$mainOSDrive\tiny11" From d2a50a9d693df8a5ba12d981dd3ff500e4017d0a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Viktor=20Sz=C3=A9pe?= Date: Mon, 22 Apr 2024 08:41:31 +0000 Subject: [PATCH 10/63] Use a real list in the README --- README.md | 47 ++++++++++++++++++++++++----------------------- 1 file changed, 24 insertions(+), 23 deletions(-) diff --git a/README.md b/README.md index 4c8b6552..74e065e5 100644 --- a/README.md +++ b/README.md @@ -31,29 +31,30 @@ Instructions: 6. When the image is completed, you will see it in the folder where the script was extracted, with the name tiny11.iso What is removed: -Clipchamp, -News, -Weather, -Xbox (although Xbox Identity provider is still here, so it should be possible to be reinstalled with no issues), -GetHelp, -GetStarted, -Office Hub, -Solitaire, -PeopleApp, -PowerAutomate, -ToDo, -Alarms, -Mail and Calendar, -Feedback Hub, -Maps, -Sound Recorder, -Your Phone, -Media Player, -QuickAssist, -Internet Explorer, -Tablet PC Math, -Edge, -OneDrive + +- Clipchamp +- News +- Weather +- Xbox (although Xbox Identity provider is still here, so it should be possible to be reinstalled with no issues) +- GetHelp +- GetStarted +- Office Hub +- Solitaire +- PeopleApp +- PowerAutomate +- ToDo +- Alarms +- Mail and Calendar +- Feedback Hub +- Maps +- Sound Recorder +- Your Phone +- Media Player +- QuickAssist +- Internet Explorer +- Tablet PC Math +- Edge +- OneDrive Known issues: From 643b85f5a650c06efbd3058c4ac0f8645a1d8df9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Viktor=20Sz=C3=A9pe?= Date: Mon, 22 Apr 2024 08:46:10 +0000 Subject: [PATCH 11/63] Revert to DOS lineends --- autounattend.xml | 74 ++++++++++++++++++++++++------------------------ 1 file changed, 37 insertions(+), 37 deletions(-) diff --git a/autounattend.xml b/autounattend.xml index ba07e9d6..08897e97 100644 --- a/autounattend.xml +++ b/autounattend.xml @@ -1,37 +1,37 @@ - - - - - - true - - - - - false - - - - - OnError - - - - true - OnError - - - /IMAGE/INDEX - 1 - - - - - - - - - - - - + + + + + + true + + + + + false + + + + + OnError + + + + true + OnError + + + /IMAGE/INDEX + 1 + + + + + + + + + + + + From 62db46658f03c1cd6267cfddbe244e7de608ab2d Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:17:42 +0300 Subject: [PATCH 12/63] Update README.md --- README.md | 24 +++++++++++++++--------- 1 file changed, 15 insertions(+), 9 deletions(-) diff --git a/README.md b/README.md index 74e065e5..702f5878 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,6 @@ # tiny11builder -Scripts to build a trimmed-down Windows 11 image - now in PowerShell! +Scripts to build a trimmed-down Windows 11 image - now in **PowerShell**!
Tiny11 builder, now completely overhauled.
@@ -9,17 +9,15 @@ After more than a year (for which I am so sorry) of no updates, tiny11 builder i You can now use it on ANY Windows 11 release (not just a specific build), as well as ANY language or architecture. This is made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release.
-Since it is written in PowerShell, make sure to set the execution policy to Unrestricted, so that you could run the script. -If you haven't done this before, make sure to run: -
Set-ExecutionPolicy unrestricted
-as administrator in PowerShell before running the script, otherwise it would just crash. +Since it is written in PowerShell, you need to set the execution policy to `Unrestricted`, so that you could run the script. +If you haven't done this before, make sure to run `Set-ExecutionPolicy unrestricted` as administrator in PowerShell before running the script, otherwise it would just crash. This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny11. -My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is oscdimg.exe, which is provided in the Windows ADK and it is used to create bootable ISO images. -Also included is an unattended answer file, which is used to bypass the Microsoft Account on OOBE and to deploy the image with the /compact flag. -It's open-source, so feel free to add or remove anything you want! Feedback is also much appreciated. +My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is **oscdimg.exe**, which is provided in the Windows ADK and it is used to create bootable ISO images. +Also included is an unattended answer file, which is used to bypass the Microsoft Account on OOBE and to deploy the image with the `/compact` flag. +It's open-source, **so feel free to add or remove anything you want!** Feedback is also much appreciated. Instructions: @@ -58,9 +56,17 @@ What is removed: Known issues: -1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store) +1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`. +**Note:**You might have to update Winget first usimg Microsoft Store. 2. Outlook and Dev Home might reappear after some time. 3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. +Features to be implemented: +- disabling telemetry +- more ad suppression +- improved language and arch detection +- more flexibility in what to keep and what to delete +- maybe a GUI??? + And that's pretty much it for now! Thanks for trying it and let me know how you like it! From 4953ad860bf64e05aa230f018a6e5a7207b1c318 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:38:58 +0300 Subject: [PATCH 13/63] Update README.md --- README.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 702f5878..a47cd84b 100644 --- a/README.md +++ b/README.md @@ -57,9 +57,11 @@ What is removed: Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`. -**Note:**You might have to update Winget first usimg Microsoft Store. -2. Outlook and Dev Home might reappear after some time. -3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. +
+**Note:** You might have to update Winget first usimg Microsoft Store. +
+3. Outlook and Dev Home might reappear after some time. +4. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. Features to be implemented: - disabling telemetry From d4ae03fe49150c12c9901d918c4b21762725a97f Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:39:21 +0300 Subject: [PATCH 14/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index a47cd84b..7d27155a 100644 --- a/README.md +++ b/README.md @@ -58,7 +58,7 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
-**Note:** You might have to update Winget first usimg Microsoft Store. +**Note**: You might have to update Winget first usimg Microsoft Store.
3. Outlook and Dev Home might reappear after some time. 4. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. From ef962c28856bb479ba814beae5b7dd4b38f70d6a Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:39:45 +0300 Subject: [PATCH 15/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 7d27155a..9bfea962 100644 --- a/README.md +++ b/README.md @@ -58,7 +58,7 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
-**Note**: You might have to update Winget first usimg Microsoft Store. +**Note** : You might have to update Winget first usimg Microsoft Store.
3. Outlook and Dev Home might reappear after some time. 4. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. From 7edad858a8adcc023bd7f9f0fbc56cbfdba56028 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:40:09 +0300 Subject: [PATCH 16/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 9bfea962..8bb519ab 100644 --- a/README.md +++ b/README.md @@ -58,7 +58,7 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
-**Note** : You might have to update Winget first usimg Microsoft Store. +Note: You might have to update Winget first usimg Microsoft Store.
3. Outlook and Dev Home might reappear after some time. 4. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. From 4bc82564696831d2929ad828296befa04b170642 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:40:33 +0300 Subject: [PATCH 17/63] Update README.md --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 8bb519ab..2bbaf3f7 100644 --- a/README.md +++ b/README.md @@ -59,6 +59,7 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
Note: You might have to update Winget first usimg Microsoft Store. +
3. Outlook and Dev Home might reappear after some time. 4. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. From 63b44e4e03b55177c0fa21e3eb1f2304d36d08ef Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:40:59 +0300 Subject: [PATCH 18/63] Update README.md --- README.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index 2bbaf3f7..33301be2 100644 --- a/README.md +++ b/README.md @@ -59,10 +59,10 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
Note: You might have to update Winget first usimg Microsoft Store. - +

-3. Outlook and Dev Home might reappear after some time. -4. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. +2. Outlook and Dev Home might reappear after some time. +3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. Features to be implemented: - disabling telemetry From a543bd256dbef639b031f73c2de642d614f33111 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 23 Apr 2024 20:41:48 +0300 Subject: [PATCH 19/63] Update README.md --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index 33301be2..d6c86651 100644 --- a/README.md +++ b/README.md @@ -62,6 +62,8 @@ Note: You might have to update Winget first usimg Microsoft Store.

2. Outlook and Dev Home might reappear after some time. +
+
3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. Features to be implemented: From 98014c0b2a482ec3225d77a547ea67ca8026aa8a Mon Sep 17 00:00:00 2001 From: Matteo Hausner Date: Wed, 24 Apr 2024 00:13:55 +0200 Subject: [PATCH 20/63] Fixes #136 - add `/English` to `dism` invocations This ensures that the output of the `dism` command is in the expected language, which is especially important if it gets parsed afterwards. --- tiny11maker.ps1 | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index fab8207a..b5eec43d 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -45,7 +45,7 @@ Write-Host "Copy complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Getting image information:" -& 'dism' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" +& 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." $wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" @@ -53,9 +53,9 @@ $wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" & icacls $wimFilePath "/grant" "Administrators:(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" -& dism "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" +& dism /English "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" -$imageIntl = & dism /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" +$imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" $languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default system UI language : ([a-zA-Z]{2}-[a-zA-Z]{2})' } if ($languageLine) { @@ -65,7 +65,7 @@ if ($languageLine) { Write-Host "Default system UI language code not found." } -$imageInfo = & 'dism' '/Get-WimInfo' "/wimFile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" +$imageInfo = & 'dism' '/English' '/Get-WimInfo' "/wimFile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" $lines = $imageInfo -split '\r?\n' foreach ($line in $lines) { @@ -87,7 +87,7 @@ if (-not $architecture) { Write-Host "Mounting complete! Performing removal of applications..." -$packages = & 'dism' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | +$packages = & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | ForEach-Object { if ($_ -match 'PackageName : (.*)') { $matches[1] @@ -100,7 +100,7 @@ $packagesToRemove = $packages | Where-Object { $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "$_*" }) } foreach ($package in $packagesToRemove) { - & 'dism' "/image:$($env:SystemDrive)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" + & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" } @@ -208,12 +208,12 @@ reg unload HKLM\zSCHEMA reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM Write-Host "Cleaning up image..." -& 'dism' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' +& 'dism' '/English' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' Write-Host "Cleanup complete." Write-Host "Unmounting image..." -& 'dism' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' Write-Host "Exporting image..." -& 'Dism' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' +& 'dism' '/English' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" Write-Host "Windows image completed. Continuing with boot.wim." @@ -224,7 +224,7 @@ $wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath & icacls $wimFilePath "/grant" "Administrators:(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -& 'dism' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" +& 'dism' '/English' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" Write-Host "Loading registry..." reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default @@ -252,7 +252,7 @@ reg unload HKLM\zSCHEMA reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM Write-Host "Unmounting image..." -& 'dism' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' Clear-Host Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." Write-Host "Copying unattended file for bypassing MS account on OOBE..." From aa81dfc0d4dcf343d71a79cd77c3297693f04039 Mon Sep 17 00:00:00 2001 From: Adel Johan Holm Gundersen <58791043+Flickza@users.noreply.github.com> Date: Wed, 24 Apr 2024 14:57:12 +0200 Subject: [PATCH 21/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index d6c86651..a9360813 100644 --- a/README.md +++ b/README.md @@ -58,7 +58,7 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
-Note: You might have to update Winget first usimg Microsoft Store. +Note: You might have to update Winget before using Microsoft Store.

2. Outlook and Dev Home might reappear after some time. From dcb2c273321b16b59ed42b6cc06a8cb3303451eb Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Mon, 29 Apr 2024 19:59:03 +0300 Subject: [PATCH 22/63] tiny11 builder v04-29-24 Added telemetry disabling features. --- tiny11maker.ps1 | 129 ++++++++++++++++++++++++++++++++++++++++++++++-- 1 file changed, 125 insertions(+), 4 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index b5eec43d..ca5c17c1 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -24,7 +24,7 @@ else [System.Diagnostics.Process]::Start($newProcess); exit } -Write-Host "Welcome to the tiny11 image creator!" +Write-Host "Welcome to the tiny11 image creator! Release: 04-29-2024" Start-Sleep -Seconds 3 Clear-Host $mainOSDrive = $env:SystemDrive @@ -84,7 +84,6 @@ if (-not $architecture) { Write-Host "Architecture information not found." } - Write-Host "Mounting complete! Performing removal of applications..." $packages = & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | @@ -104,6 +103,7 @@ foreach ($package in $packagesToRemove) { } + Write-Host "Removing Edge:" Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force @@ -184,8 +184,8 @@ Write-Host "Disabling Sponsored Apps:" & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSoftware\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSoftware\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' & 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' & 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' @@ -198,8 +198,127 @@ Write-Host "Disabling Reserved Storage:" Write-Host "Disabling Chat icon:" & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' & 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' +Write-Host "Disabling Telemetry:" +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' +## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. +function Enable-Privilege { + param( + [ValidateSet( + "SeAssignPrimaryTokenPrivilege", "SeAuditPrivilege", "SeBackupPrivilege", + "SeChangeNotifyPrivilege", "SeCreateGlobalPrivilege", "SeCreatePagefilePrivilege", + "SeCreatePermanentPrivilege", "SeCreateSymbolicLinkPrivilege", "SeCreateTokenPrivilege", + "SeDebugPrivilege", "SeEnableDelegationPrivilege", "SeImpersonatePrivilege", "SeIncreaseBasePriorityPrivilege", + "SeIncreaseQuotaPrivilege", "SeIncreaseWorkingSetPrivilege", "SeLoadDriverPrivilege", + "SeLockMemoryPrivilege", "SeMachineAccountPrivilege", "SeManageVolumePrivilege", + "SeProfileSingleProcessPrivilege", "SeRelabelPrivilege", "SeRemoteShutdownPrivilege", + "SeRestorePrivilege", "SeSecurityPrivilege", "SeShutdownPrivilege", "SeSyncAgentPrivilege", + "SeSystemEnvironmentPrivilege", "SeSystemProfilePrivilege", "SeSystemtimePrivilege", + "SeTakeOwnershipPrivilege", "SeTcbPrivilege", "SeTimeZonePrivilege", "SeTrustedCredManAccessPrivilege", + "SeUndockPrivilege", "SeUnsolicitedInputPrivilege")] + $Privilege, + ## The process on which to adjust the privilege. Defaults to the current process. + $ProcessId = $pid, + ## Switch to disable the privilege, rather than enable it. + [Switch] $Disable + ) + $definition = @' + using System; + using System.Runtime.InteropServices; + + public class AdjPriv + { + [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] + internal static extern bool AdjustTokenPrivileges(IntPtr htok, bool disall, + ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); + + [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] + internal static extern bool OpenProcessToken(IntPtr h, int acc, ref IntPtr phtok); + [DllImport("advapi32.dll", SetLastError = true)] + internal static extern bool LookupPrivilegeValue(string host, string name, ref long pluid); + [StructLayout(LayoutKind.Sequential, Pack = 1)] + internal struct TokPriv1Luid + { + public int Count; + public long Luid; + public int Attr; + } + + internal const int SE_PRIVILEGE_ENABLED = 0x00000002; + internal const int SE_PRIVILEGE_DISABLED = 0x00000000; + internal const int TOKEN_QUERY = 0x00000008; + internal const int TOKEN_ADJUST_PRIVILEGES = 0x00000020; + public static bool EnablePrivilege(long processHandle, string privilege, bool disable) + { + bool retVal; + TokPriv1Luid tp; + IntPtr hproc = new IntPtr(processHandle); + IntPtr htok = IntPtr.Zero; + retVal = OpenProcessToken(hproc, TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, ref htok); + tp.Count = 1; + tp.Luid = 0; + if(disable) + { + tp.Attr = SE_PRIVILEGE_DISABLED; + } + else + { + tp.Attr = SE_PRIVILEGE_ENABLED; + } + retVal = LookupPrivilegeValue(null, privilege, ref tp.Luid); + retVal = AdjustTokenPrivileges(htok, false, ref tp, 0, IntPtr.Zero, IntPtr.Zero); + return retVal; + } + } +'@ + + $processHandle = (Get-Process -id $ProcessId).Handle + $type = Add-Type $definition -PassThru + $type[0]::EnablePrivilege($processHandle, $Privilege, $Disable) +} + +Enable-Privilege SeTakeOwnershipPrivilege + +$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::TakeOwnership) +$regACL = $regKey.GetAccessControl() +$regACL.SetOwner([System.Security.Principal.NTAccount]"Administrators") +$regKey.SetAccessControl($regACL) +$regKey.Close() +Write-Host "Owner changed to Administrators." + +$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) +$regACL = $regKey.GetAccessControl() +$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ("Administrators","FullControl","ContainerInherit","None","Allow") +$regACL.SetAccessRule($regRule) +$regKey.SetAccessControl($regACL) +Write-Host "Permissions modified for Administrators group." +Write-Host "Registry key permissions successfully updated." +$regKey.Close() + +Write-Host 'Deleting Application Compatibility Appraiser' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f +Write-Host 'Deleting Customer Experience Improvement Program' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f +Write-Host 'Deleting Program Data Updater' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f +Write-Host 'Deleting autochk proxy' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f +Write-Host 'Deleting QueueReporting' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." +$regKey.Close() reg unload HKLM\zCOMPONENTS reg unload HKLM\zDRIVERS reg unload HKLM\zDEFAULT @@ -244,11 +363,13 @@ Write-Host "Bypassing system requirements(on the setup image):" & 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." +$regKey.Close() reg unload HKLM\zCOMPONENTS reg unload HKLM\zDRIVERS reg unload HKLM\zDEFAULT reg unload HKLM\zNTUSER reg unload HKLM\zSCHEMA +$regKey.Close() reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM Write-Host "Unmounting image..." From 93eb664e56c1228b24a6f7c52fdedbb81e8dd931 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Mon, 29 Apr 2024 20:03:00 +0300 Subject: [PATCH 23/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index a9360813..9af44a8f 100644 --- a/README.md +++ b/README.md @@ -67,7 +67,7 @@ Note: You might have to update Winget before using Microsoft Store. 3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. Features to be implemented: -- disabling telemetry +~~- disabling telemetry~~ Implemented in the 04-29-24 release! - more ad suppression - improved language and arch detection - more flexibility in what to keep and what to delete From 501e10c1adfa29cb9371f46b6e4f4d988cb5434f Mon Sep 17 00:00:00 2001 From: "Eugene San (eugenesan)" Date: Tue, 23 Apr 2024 20:48:03 -0700 Subject: [PATCH 24/63] Add support for system ADK, Logging and Debug --- tiny11maker.ps1 | 43 ++++++++++++++++++++++++++++++++----------- 1 file changed, 32 insertions(+), 11 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index ca5c17c1..3729e792 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -1,3 +1,7 @@ +# Enable debugging +#Set-PSDebug -Trace 1 + +# Check if PowerShell execution is restricted if ((Get-ExecutionPolicy) -eq 'Restricted') { Write-Host "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" $response = Read-Host @@ -8,26 +12,30 @@ if ((Get-ExecutionPolicy) -eq 'Restricted') { exit } } + +# Check and run the script as admin if required $myWindowsID=[System.Security.Principal.WindowsIdentity]::GetCurrent() $myWindowsPrincipal=new-object System.Security.Principal.WindowsPrincipal($myWindowsID) $adminRole=[System.Security.Principal.WindowsBuiltInRole]::Administrator -if ($myWindowsPrincipal.IsInRole($adminRole)) -{ - $Host.UI.RawUI.WindowTitle = "tiny11 builder" - Clear-Host -} -else +if (! $myWindowsPrincipal.IsInRole($adminRole)) { + Write-Host "Restarting Tiny11 image creator as admin in a new window, you can close this one." $newProcess = new-object System.Diagnostics.ProcessStartInfo "PowerShell"; $newProcess.Arguments = $myInvocation.MyCommand.Definition; $newProcess.Verb = "runas"; [System.Diagnostics.Process]::Start($newProcess); exit } -Write-Host "Welcome to the tiny11 image creator! Release: 04-29-2024" -Start-Sleep -Seconds 3 + +# Start the transcript and prepare the window +Start-Transcript -Path "$PSScriptRoot\tiny11.log" -UseMinimalHeader + +$Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host +Write-Host "Welcome to the tiny11 image creator! Release: 04-29-2024" + $mainOSDrive = $env:SystemDrive +$hostArchitecture = $Env:PROCESSOR_ARCHITECTURE $DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" $DriveLetter = $DriveLetter + ":" @@ -103,7 +111,6 @@ foreach ($package in $packagesToRemove) { } - Write-Host "Removing Edge:" Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force @@ -379,10 +386,24 @@ Write-Host "The tiny11 image is now completed. Proceeding with the making of the Write-Host "Copying unattended file for bypassing MS account on OOBE..." Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force Write-Host "Creating ISO image..." -& "$PSScriptRoot\oscdimg.exe" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$mainOSDrive\tiny11\boot\etfsboot.com#pEF,e,b$mainOSDrive\tiny11\efi\microsoft\boot\efisys.bin" "$mainOSDrive\tiny11" "$PSScriptRoot\tiny11.iso" +$ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" +if ([System.IO.Directory]::Exists($ADKDepTools)) { + Write-Host "Will be using oscdimg.exe from system ADK." + $OSCDIMG = "$ADKDepTools\oscdimg.exe" +} else { + Write-Host "Will be using bundled oscdimg.exe." + $OSCDIMG = "$PSScriptRoot\oscdimg.exe" +} +& "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$mainOSDrive\tiny11\boot\etfsboot.com#pEF,e,b$mainOSDrive\tiny11\efi\microsoft\boot\efisys.bin" "$mainOSDrive\tiny11" "$PSScriptRoot\tiny11.iso" + +# Finishing up Write-Host "Creation completed! Press any key to exit the script..." Read-Host "Press Enter to continue" Write-Host "Performing Cleanup..." Remove-Item -Path "$mainOSDrive\tiny11" -Recurse -Force Remove-Item -Path "$mainOSDrive\scratchdir" -Recurse -Force -exit \ No newline at end of file + +# Stop the transcript +Stop-Transcript + +exit From fd1aa7dd61084aeba09b40edfa6007841c1ca71f Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Wed, 1 May 2024 23:40:33 +0300 Subject: [PATCH 25/63] ESD support, cleans Edge, fixes logging This new release of tiny11 builder enables the ability to use images that has ESD files instead of the standard WIM. It also suppresses some of the output, making it a bit easier to track what is going on. It also cleans up the last remains of Edge! Last, but not least, it fixes an issue with logging. --- tiny11maker.ps1 | 276 +++++++++++++++++++++++++----------------------- 1 file changed, 146 insertions(+), 130 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 3729e792..988ec761 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -28,27 +28,37 @@ if (! $myWindowsPrincipal.IsInRole($adminRole)) } # Start the transcript and prepare the window -Start-Transcript -Path "$PSScriptRoot\tiny11.log" -UseMinimalHeader +Start-Transcript -Path "$PSScriptRoot\tiny11.log" $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host -Write-Host "Welcome to the tiny11 image creator! Release: 04-29-2024" +Write-Host "Welcome to the tiny11 image creator! Release: 05-01-2024" $mainOSDrive = $env:SystemDrive $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE - +New-Item -ItemType Directory -Force -Path "$mainOSDrive\tiny11\sources" >null $DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" $DriveLetter = $DriveLetter + ":" if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { - Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." - Write-Host "Please enter the correct DVD Drive Letter.." - exit + if ((Test-Path "$DriveLetter\sources\install.esd") -eq $true) { + Write-Host "Found install.esd, converting to install.wim..." + & 'dism' '/English' "/Get-WimInfo" "/wimfile:$DriveLetter\sources\install.esd" + $index = Read-Host "Please enter the image index" + Write-Host ' ' + Write-Host 'Converting install.esd to install.wim. This may take a while...' + & 'DISM' /Export-Image /SourceImageFile:"$DriveLetter\sources\install.esd" /SourceIndex:$index /DestinationImageFile:"$mainOSDrive\tiny11\sources\install.wim" /Compress:max /CheckIntegrity + } else { + Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." + Write-Host "Please enter the correct DVD Drive Letter.." + exit + } } -New-Item -ItemType Directory -Force -Path "$mainOSDrive\tiny11" Write-Host "Copying Windows image..." -Copy-Item -Path "$DriveLetter\*" -Destination "$mainOSDrive\tiny11" -Recurse -Force +Copy-Item -Path "$DriveLetter\*" -Destination "$mainOSDrive\tiny11" -Recurse -Force > null +Set-ItemProperty -Path "$mainOSDrive\tiny11\sources\install.esd" -Name IsReadOnly -Value $false > $null 2>&1 +Remove-Item "$mainOSDrive\tiny11\sources\install.esd" > $null 2>&1 Write-Host "Copy complete!" Start-Sleep -Seconds 2 Clear-Host @@ -56,11 +66,15 @@ Write-Host "Getting image information:" & 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." -$wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" -& takeown "/F" $wimFilePath -& icacls $wimFilePath "/grant" "Administrators:(F)" -Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" +$wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" +& takeown "/F" $wimFilePath +& icacls $wimFilePath "/grant" "Administrators:(F)" +try { + Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -ErrorAction Stop +} catch { + # This block will catch the error and suppress it. +} +New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" > $null & dism /English "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" $imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" @@ -112,110 +126,111 @@ foreach ($package in $packagesToRemove) { Write-Host "Removing Edge:" -Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force -Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force -Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force >null +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force >null +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force >null if ($architecture -eq 'amd64') { $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "amd64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName if ($folderPath) { - & 'takeown' '/f' $folderPath '/r' - & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' - Remove-Item -Path $folderPath -Recurse -Force + & 'takeown' '/f' $folderPath '/r' >null + & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' >null + Remove-Item -Path $folderPath -Recurse -Force >null } else { Write-Host "Folder not found." } } elseif ($architecture -eq 'arm64') { - $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName + $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName >null if ($folderPath) { - & 'takeown' '/f' $folderPath '/r' - & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' - Remove-Item -Path $folderPath -Recurse -Force + & 'takeown' '/f' $folderPath '/r'>null + & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' >null + Remove-Item -Path $folderPath -Recurse -Force >null } else { Write-Host "Folder not found." } } else { Write-Host "Unknown architecture: $architecture" } -& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' -& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' 'Administrators:F' '/T' '/C' -Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' >null +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' 'Administrators:F' '/T' '/C' >null +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force >null Write-Host "Removing OneDrive:" -& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" -& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' 'Administrators:F' '/T' '/C' -Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" -Force +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" >null +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' 'Administrators:F' '/T' '/C' >null +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" -Force >null Write-Host "Removal complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Loading registry..." -reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS -reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default -reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat -reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE -reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM +reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS >null +reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default >null +reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat >null +reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE >null +reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM >null Write-Host "Bypassing system requirements(on the system image):" -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' -Write-Host "Disabling Teams:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\Communications' '/v' 'ConfigureChatAutoInstall' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Disabling Sponsored Apps:" -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f'>null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' >null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Enabling Local Accounts on OOBE:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' >null +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null Write-Host "Disabling Reserved Storage:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null Write-Host "Disabling Chat icon:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' >null +Write-Host "Removing Edge related registries" +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f >null Write-Host "Disabling Telemetry:" -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' >null ## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. function Enable-Privilege { param( @@ -311,44 +326,45 @@ Write-Host "Registry key permissions successfully updated." $regKey.Close() Write-Host 'Deleting Application Compatibility Appraiser' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f >null Write-Host 'Deleting Customer Experience Improvement Program' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f -Write-Host 'Deleting Program Data Updater' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f >null +Write-Host 'Deleting Program Data Updater' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f >null Write-Host 'Deleting autochk proxy' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f >null Write-Host 'Deleting QueueReporting' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f >null Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() -reg unload HKLM\zCOMPONENTS -reg unload HKLM\zDRIVERS -reg unload HKLM\zDEFAULT -reg unload HKLM\zNTUSER -reg unload HKLM\zSCHEMA +reg unload HKLM\zCOMPONENTS >null +reg unload HKLM\zDRIVERS >null +reg unload HKLM\zDEFAULT >null +reg unload HKLM\zNTUSER >null +reg unload HKLM\zSCHEMA >null reg unload HKLM\zSOFTWARE -reg unload HKLM\zSYSTEM +reg unload HKLM\zSYSTEM >null Write-Host "Cleaning up image..." -& 'dism' '/English' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' +& 'dism' '/English' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' >null Write-Host "Cleanup complete." +Write-Host ' ' Write-Host "Unmounting image..." & 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' Write-Host "Exporting image..." & 'dism' '/English' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' -Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force -Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" +Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force >null +Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" >null Write-Host "Windows image completed. Continuing with boot.wim." Start-Sleep -Seconds 2 Clear-Host Write-Host "Mounting boot image:" -$wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" -& takeown "/F" $wimFilePath -& icacls $wimFilePath "/grant" "Administrators:(F)" +$wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" +& takeown "/F" $wimFilePath >null +& icacls $wimFilePath "/grant" "Administrators:(F)" >null Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false & 'dism' '/English' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" Write-Host "Loading registry..." @@ -358,33 +374,33 @@ reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM Write-Host "Bypassing system requirements(on the setup image):" -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() -reg unload HKLM\zCOMPONENTS -reg unload HKLM\zDRIVERS -reg unload HKLM\zDEFAULT -reg unload HKLM\zNTUSER -reg unload HKLM\zSCHEMA +reg unload HKLM\zCOMPONENTS >null +reg unload HKLM\zDRIVERS >null +reg unload HKLM\zDEFAULT >null +reg unload HKLM\zNTUSER >null +reg unload HKLM\zSCHEMA >null $regKey.Close() reg unload HKLM\zSOFTWARE -reg unload HKLM\zSYSTEM +reg unload HKLM\zSYSTEM >null Write-Host "Unmounting image..." & 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' Clear-Host Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." Write-Host "Copying unattended file for bypassing MS account on OOBE..." -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force >null Write-Host "Creating ISO image..." $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" if ([System.IO.Directory]::Exists($ADKDepTools)) { @@ -400,8 +416,8 @@ if ([System.IO.Directory]::Exists($ADKDepTools)) { Write-Host "Creation completed! Press any key to exit the script..." Read-Host "Press Enter to continue" Write-Host "Performing Cleanup..." -Remove-Item -Path "$mainOSDrive\tiny11" -Recurse -Force -Remove-Item -Path "$mainOSDrive\scratchdir" -Recurse -Force +Remove-Item -Path "$mainOSDrive\tiny11" -Recurse -Force >null +Remove-Item -Path "$mainOSDrive\scratchdir" -Recurse -Force >null # Stop the transcript Stop-Transcript From 8158c07cd97b79fe4d4a229cfcaedc3681f8636f Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Thu, 2 May 2024 01:51:15 +0300 Subject: [PATCH 26/63] language-agnostic admin icacls --- tiny11maker.ps1 | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 988ec761..859c5476 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -66,9 +66,11 @@ Write-Host "Getting image information:" & 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." +$adminSID = New-Object System.Security.Principal.SecurityIdentifier("S-1-5-32-544") +$adminGroup = $adminSID.Translate([System.Security.Principal.NTAccount]) $wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" & takeown "/F" $wimFilePath -& icacls $wimFilePath "/grant" "Administrators:(F)" +& icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" try { Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -ErrorAction Stop } catch { @@ -134,7 +136,7 @@ if ($architecture -eq 'amd64') { if ($folderPath) { & 'takeown' '/f' $folderPath '/r' >null - & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' >null + & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' >null Remove-Item -Path $folderPath -Recurse -Force >null } else { Write-Host "Folder not found." @@ -144,7 +146,7 @@ if ($architecture -eq 'amd64') { if ($folderPath) { & 'takeown' '/f' $folderPath '/r'>null - & 'icacls' $folderPath '/grant' 'Administrators:F' '/T' '/C' >null + & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' >null Remove-Item -Path $folderPath -Recurse -Force >null } else { Write-Host "Folder not found." @@ -153,11 +155,11 @@ if ($architecture -eq 'amd64') { Write-Host "Unknown architecture: $architecture" } & 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' >null -& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' 'Administrators:F' '/T' '/C' >null +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force >null Write-Host "Removing OneDrive:" & 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" >null -& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' 'Administrators:F' '/T' '/C' >null +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" -Force >null Write-Host "Removal complete!" Start-Sleep -Seconds 2 @@ -364,7 +366,7 @@ Clear-Host Write-Host "Mounting boot image:" $wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath >null -& icacls $wimFilePath "/grant" "Administrators:(F)" >null +& icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false & 'dism' '/English' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" Write-Host "Loading registry..." From d014d0119eab1c6273b73e119494ea834ea1e17b Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Thu, 2 May 2024 02:30:41 +0300 Subject: [PATCH 27/63] more lang-agnostic admin --- tiny11maker.ps1 | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 859c5476..11e4806a 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -14,6 +14,8 @@ if ((Get-ExecutionPolicy) -eq 'Restricted') { } # Check and run the script as admin if required +$adminSID = New-Object System.Security.Principal.SecurityIdentifier("S-1-5-32-544") +$adminGroup = $adminSID.Translate([System.Security.Principal.NTAccount]) $myWindowsID=[System.Security.Principal.WindowsIdentity]::GetCurrent() $myWindowsPrincipal=new-object System.Security.Principal.WindowsPrincipal($myWindowsID) $adminRole=[System.Security.Principal.WindowsBuiltInRole]::Administrator @@ -66,8 +68,6 @@ Write-Host "Getting image information:" & 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." -$adminSID = New-Object System.Security.Principal.SecurityIdentifier("S-1-5-32-544") -$adminGroup = $adminSID.Translate([System.Security.Principal.NTAccount]) $wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" & takeown "/F" $wimFilePath & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" @@ -313,14 +313,13 @@ Enable-Privilege SeTakeOwnershipPrivilege $regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::TakeOwnership) $regACL = $regKey.GetAccessControl() -$regACL.SetOwner([System.Security.Principal.NTAccount]"Administrators") +$regACL.SetOwner($adminGroup) $regKey.SetAccessControl($regACL) $regKey.Close() Write-Host "Owner changed to Administrators." - $regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) $regACL = $regKey.GetAccessControl() -$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ("Administrators","FullControl","ContainerInherit","None","Allow") +$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ($adminGroup,"FullControl","ContainerInherit","None","Allow") $regACL.SetAccessRule($regRule) $regKey.SetAccessControl($regACL) Write-Host "Permissions modified for Administrators group." From d4756879230fbb8fde6546f5b937739446c6e23e Mon Sep 17 00:00:00 2001 From: Elrondo46 <18145437+Elrondo46@users.noreply.github.com> Date: Thu, 2 May 2024 10:56:55 +0200 Subject: [PATCH 28/63] Disable bing search in Start Menu --- tiny11maker.ps1 | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 11e4806a..6e2121d8 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -233,6 +233,10 @@ Write-Host "Disabling Telemetry:" & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' >null & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' >null & 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' >null +Write-Host "Disabling bing in Start Menu:" +& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'ShowRunAsDifferentUserInStart' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'DisableSearchBoxSuggestions' '/t' 'REG_DWORD' '/d' '1' '/f' ## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. function Enable-Privilege { param( From e8327ffa5ff562ef1f66028f4a68957eda9c67d8 Mon Sep 17 00:00:00 2001 From: Sebastian Gustavsson Date: Fri, 3 May 2024 14:56:34 +0200 Subject: [PATCH 29/63] Use PowerShell DISM cmdlets --- tiny11maker.ps1 | 86 +++++++++++++++++++++---------------------------- 1 file changed, 37 insertions(+), 49 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 6e2121d8..4d0fb8ed 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -45,11 +45,11 @@ $DriveLetter = $DriveLetter + ":" if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { if ((Test-Path "$DriveLetter\sources\install.esd") -eq $true) { Write-Host "Found install.esd, converting to install.wim..." - & 'dism' '/English' "/Get-WimInfo" "/wimfile:$DriveLetter\sources\install.esd" + Get-WindowsImage -ImagePath "$DriveLetter\sources\install.esd" $index = Read-Host "Please enter the image index" Write-Host ' ' Write-Host 'Converting install.esd to install.wim. This may take a while...' - & 'DISM' /Export-Image /SourceImageFile:"$DriveLetter\sources\install.esd" /SourceIndex:$index /DestinationImageFile:"$mainOSDrive\tiny11\sources\install.wim" /Compress:max /CheckIntegrity + Export-WindowsImage -SourceImagePath "$DriveLetter\sources\install.esd" -SourceIndex $index -DestinationImagePath "$mainOSDrive\tiny11\sources\install.wim" -CompressionType 'max' -CheckIntegrity } else { Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." Write-Host "Please enter the correct DVD Drive Letter.." @@ -65,7 +65,7 @@ Write-Host "Copy complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Getting image information:" -& 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" +Get-WindowsImage -ImagePath "$mainOSDrive\tiny11\sources\install.wim" $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." $wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" @@ -77,54 +77,42 @@ try { # This block will catch the error and suppress it. } New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" > $null -& dism /English "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" +Mount-WindowsImage -ImagePath $wimFilePath -Index $index -Path "$($env:SystemDrive)\scratchdir" -$imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" -$languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default system UI language : ([a-zA-Z]{2}-[a-zA-Z]{2})' } +$imageInfo = Get-WindowsImage -ImagePath $wimFilePath -Index $index -if ($languageLine) { - $languageCode = $Matches[1] - Write-Host "Default system UI language code: $languageCode" -} else { - Write-Host "Default system UI language code not found." -} - -$imageInfo = & 'dism' '/English' '/Get-WimInfo' "/wimFile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" -$lines = $imageInfo -split '\r?\n' - -foreach ($line in $lines) { - if ($line -like '*Architecture : *') { - $architecture = $line -replace 'Architecture : ','' - # If the architecture is x64, replace it with amd64 - if ($architecture -eq 'x64') { - $architecture = 'amd64' - } - Write-Host "Architecture: $architecture" - break - } -} +$languageCode = $imageInfo.Languages[$imageInfo.DefaultLanguageIndex] +Write-Host "Default system UI language code: $languageCode" -if (-not $architecture) { - Write-Host "Architecture information not found." +# Architecture enumeration found at https://github.com/jeffkl/ManagedDism/blob/94cf084528f4a986089335327ea67ff747a1dc6d/src/Microsoft.Dism/NativeEnums.cs#L275 +switch ($imageInfo.Architecture) { + 0 { $architecture = 'x86'} + 9 { $architecture = 'amd64'} + 5 { $architecture = 'arm'} + 12 { $architecture = 'arm64'} + 6 { $architecture = 'ia64'} + 11 { $architecture = 'neutral'} + Default { $architecture = 'unknown' } } +Write-Host "Architecture: $architecture" Write-Host "Mounting complete! Performing removal of applications..." -$packages = & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | - ForEach-Object { - if ($_ -match 'PackageName : (.*)') { - $matches[1] - } - } -$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_' - -$packagesToRemove = $packages | Where-Object { - $packageName = $_ - $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "$_*" }) -} -foreach ($package in $packagesToRemove) { - & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" -} +$packagesToRemove = @( + 'Clipchamp.Clipchamp', 'Microsoft.BingNews', 'Microsoft.BingWeather', + 'Microsoft.GamingApp', 'Microsoft.GetHelp', 'Microsoft.Getstarted', + 'Microsoft.MicrosoftOfficeHub', 'Microsoft.MicrosoftSolitaireCollection', + 'Microsoft.People', 'Microsoft.PowerAutomateDesktop', 'Microsoft.Todos', + 'Microsoft.WindowsAlarms', 'microsoft.windowscommunicationsapps', + 'Microsoft.WindowsFeedbackHub', 'Microsoft.WindowsMaps', + 'Microsoft.WindowsSoundRecorder', 'Microsoft.Xbox.TCUI', + 'Microsoft.XboxGamingOverlay', 'Microsoft.XboxGameOverlay', + 'Microsoft.XboxSpeechToTextOverlay', 'Microsoft.YourPhone', + 'Microsoft.ZuneMusic', 'Microsoft.ZuneVideo', + 'MicrosoftCorporationII.MicrosoftFamily', 'MicrosoftCorporationII.QuickAssist', + 'MicrosoftTeams', 'Microsoft.549981C3F5F10' +) +Get-AppxProvisionedPackage -Path "$($env:SystemDrive)\scratchdir" | Where-Object { $_.DisplayName -In $packagesToRemove } | Remove-AppxProvisionedPackage -Path "$($env:SystemDrive)\scratchdir" Write-Host "Removing Edge:" @@ -354,13 +342,13 @@ reg unload HKLM\zSCHEMA >null reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Cleaning up image..." -& 'dism' '/English' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' >null +Repair-WindowsImage -Path "$mainOSDrive\scratchdir" -StartComponentCleanup -ResetBase Write-Host "Cleanup complete." Write-Host ' ' Write-Host "Unmounting image..." -& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +Dismount-WindowsImage -Path "$mainOSDrive\scratchdir" -Save Write-Host "Exporting image..." -& 'dism' '/English' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' +Export-WindowsImage -SourceImagePath "$mainOSDrive\tiny11\sources\install.wim" -SourceIndex $index -DestinationImagePath "$mainOSDrive\tiny11\sources\install2.wim" -CompressionType 'max' Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force >null Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" >null Write-Host "Windows image completed. Continuing with boot.wim." @@ -371,7 +359,7 @@ $wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath >null & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -& 'dism' '/English' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" +Mount-WindowsImage -ImagePath $wimFilePath -Index 2 -Path "$mainOSDrive\scratchdir" Write-Host "Loading registry..." reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default @@ -401,7 +389,7 @@ $regKey.Close() reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Unmounting image..." -& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +Dismount-WindowsImage -Path "$mainOSDrive\scratchdir" -Save Clear-Host Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." Write-Host "Copying unattended file for bypassing MS account on OOBE..." From 08eb2ff74155391e591120e5049a96a41c555476 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 4 May 2024 18:12:58 +0300 Subject: [PATCH 30/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 9af44a8f..df94c468 100644 --- a/README.md +++ b/README.md @@ -58,7 +58,7 @@ Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
-Note: You might have to update Winget before using Microsoft Store. +Note: You might have to update Winget before being able to install any apps, using Microsoft Store.

2. Outlook and Dev Home might reappear after some time. From 218e14189731b5556ce23c75fbbc50ea0def17f0 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Mon, 6 May 2024 19:59:43 +0300 Subject: [PATCH 31/63] Introducing tiny11 core builder! --- README.md | 14 +- tiny11Coremaker.ps1 | 758 ++++++++++++++++++++++++++++++++++++++++++++ tiny11maker.ps1 | 8 +- 3 files changed, 774 insertions(+), 6 deletions(-) create mode 100644 tiny11Coremaker.ps1 diff --git a/README.md b/README.md index df94c468..5d1e7e18 100644 --- a/README.md +++ b/README.md @@ -13,12 +13,14 @@ Since it is written in PowerShell, you need to set the execution policy to `Unr If you haven't done this before, make sure to run `Set-ExecutionPolicy unrestricted` as administrator in PowerShell before running the script, otherwise it would just crash. - This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny11. My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is **oscdimg.exe**, which is provided in the Windows ADK and it is used to create bootable ISO images. Also included is an unattended answer file, which is used to bypass the Microsoft Account on OOBE and to deploy the image with the `/compact` flag. It's open-source, **so feel free to add or remove anything you want!** Feedback is also much appreciated. +Also, for the very first time, **introducing tiny11 core builder**! A more powerful script, designed for a quick and dirty development testbed. Just the bare minimun, none of the fluff. +This script generates a significantly reduced Windows 11 image. However, it's not suitable for regular use due to its lack of serviceability - you can't add languages, updates, or features post-creation. tiny11 Core is not a full Windows 11 substitute but a rapid testing or development tool, potentially useful for VM environments. + Instructions: 1. Download Windows 11 from the Microsoft website () @@ -54,6 +56,16 @@ What is removed: - Edge - OneDrive +For tiny11 core: +- all of the above + +- Windows Component Store (WinSxS) +- Windows Defender (only disabled, can be enabled back if needed) +- Windows Update (Windows Update wouldn't work anyway without WinSxS, so enabling it would only put the system in a state where it would try to update but fail spectacularily) +- WinRE +Keep in mind that **you cannot add back features in tiny11 core**! +
+You will be asked during iamge creation if you want to enable .net 3.5 support! +
Known issues: 1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`. diff --git a/tiny11Coremaker.ps1 b/tiny11Coremaker.ps1 new file mode 100644 index 00000000..bb72f855 --- /dev/null +++ b/tiny11Coremaker.ps1 @@ -0,0 +1,758 @@ +# Enable debugging +#Set-PSDebug -Trace 1 + +# Check if PowerShell execution is restricted +if ((Get-ExecutionPolicy) -eq 'Restricted') { + Write-Host "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" + $response = Read-Host + if ($response -eq 'yes') { + Set-ExecutionPolicy RemoteSigned -Scope CurrentUser -Confirm:$false + } else { + Write-Host "The script cannot be run without changing the execution policy. Exiting..." + exit + } +} + +# Check and run the script as admin if required +$adminSID = New-Object System.Security.Principal.SecurityIdentifier("S-1-5-32-544") +$adminGroup = $adminSID.Translate([System.Security.Principal.NTAccount]) +$myWindowsID=[System.Security.Principal.WindowsIdentity]::GetCurrent() +$myWindowsPrincipal=new-object System.Security.Principal.WindowsPrincipal($myWindowsID) +$adminRole=[System.Security.Principal.WindowsBuiltInRole]::Administrator +if (! $myWindowsPrincipal.IsInRole($adminRole)) +{ + Write-Host "Restarting Tiny11 image creator as admin in a new window, you can close this one." + $newProcess = new-object System.Diagnostics.ProcessStartInfo "PowerShell"; + $newProcess.Arguments = $myInvocation.MyCommand.Definition; + $newProcess.Verb = "runas"; + [System.Diagnostics.Process]::Start($newProcess); + exit +} +Start-Transcript -Path "$PSScriptRoot\tiny11.log" +# Ask the user for input +Write-Host "Welcome to tiny11 core builder! BETA 05-06-24" +Write-Host "This script generates a significantly reduced Windows 11 image. However, it's not suitable for regular use due to its lack of serviceability - you can't add languages, updates, or features post-creation. tiny11 Core is not a full Windows 11 substitute but a rapid testing or development tool, potentially useful for VM environments." +Write-Host "Do you want to continue? (y/n)" +$input = Read-Host + +if ($input -eq 'y') { + Write-Host "Off we go..." +Start-Sleep -Seconds 3 +Clear-Host + +$mainOSDrive = $env:SystemDrive +$hostArchitecture = $Env:PROCESSOR_ARCHITECTURE +New-Item -ItemType Directory -Force -Path "$mainOSDrive\tiny11\sources" >null +$DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" +$DriveLetter = $DriveLetter + ":" + +if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { + if ((Test-Path "$DriveLetter\sources\install.esd") -eq $true) { + Write-Host "Found install.esd, converting to install.wim..." + & 'dism' '/English' "/Get-WimInfo" "/wimfile:$DriveLetter\sources\install.esd" + $index = Read-Host "Please enter the image index" + Write-Host ' ' + Write-Host 'Converting install.esd to install.wim. This may take a while...' + & 'DISM' /Export-Image /SourceImageFile:"$DriveLetter\sources\install.esd" /SourceIndex:$index /DestinationImageFile:"$mainOSDrive\tiny11\sources\install.wim" /Compress:max /CheckIntegrity + } else { + Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." + Write-Host "Please enter the correct DVD Drive Letter.." + exit + } +} + +Write-Host "Copying Windows image..." +Copy-Item -Path "$DriveLetter\*" -Destination "$mainOSDrive\tiny11" -Recurse -Force > null +Set-ItemProperty -Path "$mainOSDrive\tiny11\sources\install.esd" -Name IsReadOnly -Value $false > $null 2>&1 +Remove-Item "$mainOSDrive\tiny11\sources\install.esd" > $null 2>&1 +Write-Host "Copy complete!" +Start-Sleep -Seconds 2 +Clear-Host +Write-Host "Getting image information:" +& 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" +$index = Read-Host "Please enter the image index" +Write-Host "Mounting Windows image. This may take a while." +$wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" +& takeown "/F" $wimFilePath +& icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" +try { + Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -ErrorAction Stop +} catch { + # This block will catch the error and suppress it. +} +New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" > $null +& dism /English "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" + +$imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" +$languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default system UI language : ([a-zA-Z]{2}-[a-zA-Z]{2})' } + +if ($languageLine) { + $languageCode = $Matches[1] + Write-Host "Default system UI language code: $languageCode" +} else { + Write-Host "Default system UI language code not found." +} + +$imageInfo = & 'dism' '/English' '/Get-WimInfo' "/wimFile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" +$lines = $imageInfo -split '\r?\n' + +foreach ($line in $lines) { + if ($line -like '*Architecture : *') { + $architecture = $line -replace 'Architecture : ','' + # If the architecture is x64, replace it with amd64 + if ($architecture -eq 'x64') { + $architecture = 'amd64' + } + Write-Host "Architecture: $architecture" + break + } +} + +if (-not $architecture) { + Write-Host "Architecture information not found." +} + +Write-Host "Mounting complete! Performing removal of applications..." + +$packages = & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | + ForEach-Object { + if ($_ -match 'PackageName : (.*)') { + $matches[1] + } + } +$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.SecHealthUI_', 'Microsoft.Windows.PeopleExperienceHost_', 'Microsoft.Windows.PinningConfirmationDialog_', 'Windows.CBSPreview_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_' + +$packagesToRemove = $packages | Where-Object { + $packageName = $_ + $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "$_*" }) +} +foreach ($package in $packagesToRemove) { + write-host "Removing $package :" + & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" +} + +Write-Host "Removing of system apps complete! Now proceeding to removal of system packages..." +Start-Sleep -Seconds 1 +Clear-Host + +$scratchDir = "$($env:SystemDrive)\scratchdir" +$packagePatterns = @( + "Microsoft-Windows-InternetExplorer-Optional-Package~31bf3856ad364e35", + "Microsoft-Windows-Kernel-LA57-FoD-Package~31bf3856ad364e35~amd64", + "Microsoft-Windows-LanguageFeatures-Handwriting-$languageCode-Package~31bf3856ad364e35", + "Microsoft-Windows-LanguageFeatures-OCR-$languageCode-Package~31bf3856ad364e35", + "Microsoft-Windows-LanguageFeatures-Speech-$languageCode-Package~31bf3856ad364e35", + "Microsoft-Windows-LanguageFeatures-TextToSpeech-$languageCode-Package~31bf3856ad364e35", + "Microsoft-Windows-MediaPlayer-Package~31bf3856ad364e35", + "Microsoft-Windows-Wallpaper-Content-Extended-FoD-Package~31bf3856ad364e35", + "Windows-Defender-Client-Package~31bf3856ad364e35~", + "Microsoft-Windows-WordPad-FoD-Package~", + "Microsoft-Windows-TabletPCMath-Package~", + "Microsoft-Windows-StepsRecorder-Package~" + +) + +# Get all packages +$allPackages = & dism /image:$scratchDir /Get-Packages /Format:Table +$allPackages = $allPackages -split "`n" | Select-Object -Skip 1 + +foreach ($packagePattern in $packagePatterns) { + # Filter the packages to remove + $packagesToRemove = $allPackages | Where-Object { $_ -like "$packagePattern*" } + + foreach ($package in $packagesToRemove) { + # Extract the package identity + $packageIdentity = ($package -split "\s+")[0] + + Write-Host "Removing $packageIdentity..." + & dism /image:$scratchDir /Remove-Package /PackageName:$packageIdentity + } +} + +Write-Host "Do you want to enable .NET 3.5? (y/n)" +$input = Read-Host + +# Check the user's input +if ($input -eq 'y') { + # If the user entered 'y', enable .NET 3.5 using DISM + Write-Host "Enabling .NET 3.5..." + & 'dism' "/image:$scratchDir" '/enable-feature' '/featurename:NetFX3' '/All' "/source:$($env:SystemDrive)\tiny11\sources\sxs" + Write-Host ".NET 3.5 has been enabled." +} +elseif ($input -eq 'n') { + # If the user entered 'n', exit the script + Write-Host "You chose not to enable .NET 3.5. Continuing..." +} +else { + # If the user entered anything other than 'y' or 'n', ask for input again + Write-Host "Invalid input. Please enter 'y' to enable .NET 3.5 or 'n' to continue without installing .net 3.5." +} +Write-Host "Removing Edge:" +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force >null +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force >null +Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force >null +if ($architecture -eq 'amd64') { + $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "amd64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName + + if ($folderPath) { + & 'takeown' '/f' $folderPath '/r' >null + & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' >null + Remove-Item -Path $folderPath -Recurse -Force >null + } else { + Write-Host "Folder not found." + } +} elseif ($architecture -eq 'arm64') { + $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName >null + + if ($folderPath) { + & 'takeown' '/f' $folderPath '/r'>null + & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' >null + Remove-Item -Path $folderPath -Recurse -Force >null + } else { + Write-Host "Folder not found." + } +} else { + Write-Host "Unknown architecture: $architecture" +} +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force +Write-Host "Removing WinRE" +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Recovery" '/r' +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Recovery" '/grant' 'Administrators:F' '/T' '/C' +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Recovery" -Recurse -Force +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' >null +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force >null +Write-Host "Removing OneDrive:" +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" >null +& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" -Force >null +Write-Host "Removal complete!" +Start-Sleep -Seconds 2 +Clear-Host +Write-Host "Taking ownership of the WinSxS folder. This might take a while..." +& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\WinSxS" '/r' +& 'icacls' "$mainOSDrive\scratchdir\Windows\WinSxS" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' +Write-host "Complete!" +Start-Sleep -Seconds 2 +Clear-Host +Write-Host "Preparing..." +$folderPath = Join-Path -Path $mainOSDrive -ChildPath "\scratchdir\Windows\WinSxS_edit" +$sourceDirectory = "$mainOSDrive\scratchdir\Windows\WinSxS" +$destinationDirectory = "$mainOSDrive\scratchdir\Windows\WinSxS_edit" +New-Item -Path $folderPath -ItemType Directory +if ($architecture -eq "amd64") { + # Specify the list of files to copy + $dirsToCopy = @( + "x86_microsoft.windows.common-controls_6595b64144ccf1df_*", + "x86_microsoft.windows.gdiplus_6595b64144ccf1df_*", + "x86_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_*", + "x86_microsoft.windows.isolationautomation_6595b64144ccf1df_*", + "x86_microsoft-windows-s..ngstack-onecorebase_31bf3856ad364e35_*", + "x86_microsoft-windows-s..stack-termsrv-extra_31bf3856ad364e35_*", + "x86_microsoft-windows-servicingstack_31bf3856ad364e35_*", + "x86_microsoft-windows-servicingstack-inetsrv_*", + "x86_microsoft-windows-servicingstack-onecore_*", + "amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_*", + "amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_*", + "amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_*", + "amd64_microsoft.windows.common-controls_6595b64144ccf1df_*", + "amd64_microsoft.windows.gdiplus_6595b64144ccf1df_*", + "amd64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_*", + "amd64_microsoft.windows.isolationautomation_6595b64144ccf1df_*", + "amd64_microsoft-windows-s..stack-inetsrv-extra_31bf3856ad364e35_*", + "amd64_microsoft-windows-s..stack-msg.resources_31bf3856ad364e35_*", + "amd64_microsoft-windows-s..stack-termsrv-extra_31bf3856ad364e35_*", + "amd64_microsoft-windows-servicingstack_31bf3856ad364e35_*", + "amd64_microsoft-windows-servicingstack-inetsrv_31bf3856ad364e35_*", + "amd64_microsoft-windows-servicingstack-msg_31bf3856ad364e35_*", + "amd64_microsoft-windows-servicingstack-onecore_31bf3856ad364e35_*", + "Catalogs", + "FileMaps", + "Fusion", + "InstallTemp", + "Manifests", + "x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_*", + "x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_*", + "x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_*", + "x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_*" + ) + # Copy each directory + foreach ($dir in $dirsToCopy) { + $sourceDirs = Get-ChildItem -Path $sourceDirectory -Filter $dir -Directory + foreach ($sourceDir in $sourceDirs) { + $destDir = Join-Path -Path $destinationDirectory -ChildPath $sourceDir.Name + Write-Host "Copying $sourceDir.FullName to $destDir" + Copy-Item -Path $sourceDir.FullName -Destination $destDir -Recurse -Force + } + } +} + elseif ($architecture -eq "arm64") { + # Specify the list of files to copy + $dirsToCopy = @( + "arm64_microsoft-windows-servicingstack-onecore_31bf3856ad364e35_*", + "Catalogs" + "FileMaps" + "Fusion" + "InstallTemp" + "Manifests" + "SettingsManifests" + "Temp" + "x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_*" + "x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_*" + "x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_*" + "x86_microsoft.windows.common-controls_6595b64144ccf1df_*" + "x86_microsoft.windows.gdiplus_6595b64144ccf1df_*" + "x86_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_*" + "x86_microsoft.windows.isolationautomation_6595b64144ccf1df_*" + "arm_microsoft.windows.c..-controls.resources_6595b64144ccf1df_*" + "arm_microsoft.windows.common-controls_6595b64144ccf1df_*" + "arm_microsoft.windows.gdiplus_6595b64144ccf1df_*" + "arm_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_*" + "arm_microsoft.windows.isolationautomation_6595b64144ccf1df_*" + "arm64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_*" + "arm64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_*" + "arm64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_*" + "arm64_microsoft.windows.common-controls_6595b64144ccf1df_*" + "arm64_microsoft.windows.gdiplus_6595b64144ccf1df_*" + "arm64_microsoft.windows.i..utomation.proxystub_6595b64144ccf1df_*" + "arm64_microsoft.windows.isolationautomation_6595b64144ccf1df_*" + "arm64_microsoft-windows-servicing-adm_31bf3856ad364e35_*" + "arm64_microsoft-windows-servicingcommon_31bf3856ad364e35_*" + "arm64_microsoft-windows-servicing-onecore-uapi_31bf3856ad364e35_*" + "arm64_microsoft-windows-servicingstack_31bf3856ad364e35_*" + "arm64_microsoft-windows-servicingstack-inetsrv_31bf3856ad364e35_*" + "arm64_microsoft-windows-servicingstack-msg_31bf3856ad364e35_*" + ) +} +foreach ($dir in $dirsToCopy) { + $sourceDirs = Get-ChildItem -Path $sourceDirectory -Filter $dir -Directory + foreach ($sourceDir in $sourceDirs) { + $destDir = Join-Path -Path $destinationDirectory -ChildPath $sourceDir.Name + Write-Host "Copying $sourceDir.FullName to $destDir" + Copy-Item -Path $sourceDir.FullName -Destination $destDir -Recurse -Force + } + } + + +Write-Host "Deleting WinSxS. This may take a while..." + Remove-Item -Path $mainOSDrive\scratchdir\Windows\WinSxS -Recurse -Force + +Rename-Item -Path $mainOSDrive\scratchdir\Windows\WinSxS_edit -NewName $mainOSDrive\scratchdir\Windows\WinSxS +Write-Host "Complete!" + +Write-Host "Loading registry..." +reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS >null +reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default >null +reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat >null +reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE >null +reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM >null +Write-Host "Bypassing system requirements(on the system image):" +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +Write-Host "Disabling Sponsored Apps:" +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f'>null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' >null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null +Write-Host "Enabling Local Accounts on OOBE:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' >null +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null +Write-Host "Disabling Reserved Storage:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null +Write-Host "Disabling Chat icon:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' +Write-Host "Disabling Telemetry:" +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' +Write-Host "Disabling OneDrive folder backup" +& 'reg' 'add' "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" '/v' 'DisableFileSyncNGSC' '/t' 'REG_DWORD' '/d' '1' '/f' +Write-Host "Removing Edge related registries" +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f +Write-Host "Disabling bing in Start Menu:" +& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'ShowRunAsDifferentUserInStart' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'DisableSearchBoxSuggestions' '/t' 'REG_DWORD' '/d' '1' '/f' +## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. +function Enable-Privilege { + param( + [ValidateSet( + "SeAssignPrimaryTokenPrivilege", "SeAuditPrivilege", "SeBackupPrivilege", + "SeChangeNotifyPrivilege", "SeCreateGlobalPrivilege", "SeCreatePagefilePrivilege", + "SeCreatePermanentPrivilege", "SeCreateSymbolicLinkPrivilege", "SeCreateTokenPrivilege", + "SeDebugPrivilege", "SeEnableDelegationPrivilege", "SeImpersonatePrivilege", "SeIncreaseBasePriorityPrivilege", + "SeIncreaseQuotaPrivilege", "SeIncreaseWorkingSetPrivilege", "SeLoadDriverPrivilege", + "SeLockMemoryPrivilege", "SeMachineAccountPrivilege", "SeManageVolumePrivilege", + "SeProfileSingleProcessPrivilege", "SeRelabelPrivilege", "SeRemoteShutdownPrivilege", + "SeRestorePrivilege", "SeSecurityPrivilege", "SeShutdownPrivilege", "SeSyncAgentPrivilege", + "SeSystemEnvironmentPrivilege", "SeSystemProfilePrivilege", "SeSystemtimePrivilege", + "SeTakeOwnershipPrivilege", "SeTcbPrivilege", "SeTimeZonePrivilege", "SeTrustedCredManAccessPrivilege", + "SeUndockPrivilege", "SeUnsolicitedInputPrivilege")] + $Privilege, + ## The process on which to adjust the privilege. Defaults to the current process. + $ProcessId = $pid, + ## Switch to disable the privilege, rather than enable it. + [Switch] $Disable + ) + $definition = @' + using System; + using System.Runtime.InteropServices; + + public class AdjPriv + { + [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] + internal static extern bool AdjustTokenPrivileges(IntPtr htok, bool disall, + ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); + + [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] + internal static extern bool OpenProcessToken(IntPtr h, int acc, ref IntPtr phtok); + [DllImport("advapi32.dll", SetLastError = true)] + internal static extern bool LookupPrivilegeValue(string host, string name, ref long pluid); + [StructLayout(LayoutKind.Sequential, Pack = 1)] + internal struct TokPriv1Luid + { + public int Count; + public long Luid; + public int Attr; + } + + internal const int SE_PRIVILEGE_ENABLED = 0x00000002; + internal const int SE_PRIVILEGE_DISABLED = 0x00000000; + internal const int TOKEN_QUERY = 0x00000008; + internal const int TOKEN_ADJUST_PRIVILEGES = 0x00000020; + public static bool EnablePrivilege(long processHandle, string privilege, bool disable) + { + bool retVal; + TokPriv1Luid tp; + IntPtr hproc = new IntPtr(processHandle); + IntPtr htok = IntPtr.Zero; + retVal = OpenProcessToken(hproc, TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, ref htok); + tp.Count = 1; + tp.Luid = 0; + if(disable) + { + tp.Attr = SE_PRIVILEGE_DISABLED; + } + else + { + tp.Attr = SE_PRIVILEGE_ENABLED; + } + retVal = LookupPrivilegeValue(null, privilege, ref tp.Luid); + retVal = AdjustTokenPrivileges(htok, false, ref tp, 0, IntPtr.Zero, IntPtr.Zero); + return retVal; + } + } +'@ + + $processHandle = (Get-Process -id $ProcessId).Handle + $type = Add-Type $definition -PassThru + $type[0]::EnablePrivilege($processHandle, $Privilege, $Disable) +} + +Enable-Privilege SeTakeOwnershipPrivilege + +$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::TakeOwnership) +$regACL = $regKey.GetAccessControl() +$regACL.SetOwner($adminGroup) +$regKey.SetAccessControl($regACL) +$regKey.Close() +Write-Host "Owner changed to Administrators." +$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) +$regACL = $regKey.GetAccessControl() +$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ($adminGroup,"FullControl","ContainerInherit","None","Allow") +$regACL.SetAccessRule($regRule) +$regKey.SetAccessControl($regACL) +Write-Host "Permissions modified for Administrators group." +Write-Host "Registry key permissions successfully updated." +$regKey.Close() + +Write-Host 'Deleting Application Compatibility Appraiser' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f +Write-Host 'Deleting Customer Experience Improvement Program' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f +Write-Host 'Deleting Program Data Updater' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f +Write-Host 'Deleting autochk proxy' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f +Write-Host 'Deleting QueueReporting' +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f +Write-Host "Disabling Windows Update..." +& 'reg' 'add' "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" '/v' 'StopWUPostOOBE1' '/t' 'REG_SZ' '/d' 'net stop wuauserv' '/f' +& 'reg' 'add' "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" '/v' 'StopWUPostOOBE2' '/t' 'REG_SZ' '/d' 'sc stop wuauserv' '/f' +& 'reg' 'add' "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" '/v' 'StopWUPostOOBE3' '/t' 'REG_SZ' '/d' 'sc config wuauserv start= disabled' '/f' +& 'reg' 'add' "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" '/v' 'DisbaleWUPostOOBE1' '/t' 'REG_SZ' '/d' 'reg add HKLM\SYSTEM\CurrentControlSet\Services\wuauserv /v Start /t REG_DWORD /d 4 /f' '/f' +& 'reg' 'add' "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" '/v' 'DisbaleWUPostOOBE2' '/t' 'REG_SZ' '/d' 'reg add HKLM\SYSTEM\ControlSet001\Services\wuauserv /v Start /t REG_DWORD /d 4 /f' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' '/v' 'DoNotConnectToWindowsUpdateInternetLocations' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' '/v' 'DisableWindowsUpdateAccess' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' '/v' 'WUServer' '/t' 'REG_SZ' '/d' 'localhost' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' '/v' 'WUStatusServer' '/t' 'REG_SZ' '/d' 'localhost' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate' '/v' 'UpdateServiceUrlAlternate' '/t' 'REG_SZ' '/d' 'localhost' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU' '/v' 'UseWUServer' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'DisableOnline' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\wuauserv' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' +function Disable-Privilege { + param( + [ValidateSet( + "SeAssignPrimaryTokenPrivilege", "SeAuditPrivilege", "SeBackupPrivilege", + "SeChangeNotifyPrivilege", "SeCreateGlobalPrivilege", "SeCreatePagefilePrivilege", + "SeCreatePermanentPrivilege", "SeCreateSymbolicLinkPrivilege", "SeCreateTokenPrivilege", + "SeDebugPrivilege", "SeEnableDelegationPrivilege", "SeImpersonatePrivilege", "SeIncreaseBasePriorityPrivilege", + "SeIncreaseQuotaPrivilege", "SeIncreaseWorkingSetPrivilege", "SeLoadDriverPrivilege", + "SeLockMemoryPrivilege", "SeMachineAccountPrivilege", "SeManageVolumePrivilege", + "SeProfileSingleProcessPrivilege", "SeRelabelPrivilege", "SeRemoteShutdownPrivilege", + "SeRestorePrivilege", "SeSecurityPrivilege", "SeShutdownPrivilege", "SeSyncAgentPrivilege", + "SeSystemEnvironmentPrivilege", "SeSystemProfilePrivilege", "SeSystemtimePrivilege", + "SeTakeOwnershipPrivilege", "SeTcbPrivilege", "SeTimeZonePrivilege", "SeTrustedCredManAccessPrivilege", + "SeUndockPrivilege", "SeUnsolicitedInputPrivilege")] + $Privilege, + ## The process on which to adjust the privilege. Defaults to the current process. + $ProcessId = $pid, + ## Switch to disable the privilege, rather than enable it. + [Switch] $Disable + ) + $definition = @' + using System; + using System.Runtime.InteropServices; + + public class AdjPriv + { + [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] + internal static extern bool AdjustTokenPrivileges(IntPtr htok, bool disall, + ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); + + [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] + internal static extern bool OpenProcessToken(IntPtr h, int acc, ref IntPtr phtok); + [DllImport("advapi32.dll", SetLastError = true)] + internal static extern bool LookupPrivilegeValue(string host, string name, ref long pluid); + [StructLayout(LayoutKind.Sequential, Pack = 1)] + internal struct TokPriv1Luid + { + public int Count; + public long Luid; + public int Attr; + } + + internal const int SE_PRIVILEGE_ENABLED = 0x00000002; + internal const int SE_PRIVILEGE_DISABLED = 0x00000000; + internal const int TOKEN_QUERY = 0x00000008; + internal const int TOKEN_ADJUST_PRIVILEGES = 0x00000020; + public static bool EnablePrivilege(long processHandle, string privilege, bool disable) + { + bool retVal; + TokPriv1Luid tp; + IntPtr hproc = new IntPtr(processHandle); + IntPtr htok = IntPtr.Zero; + retVal = OpenProcessToken(hproc, TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, ref htok); + tp.Count = 1; + tp.Luid = 0; + if(disable) + { + tp.Attr = SE_PRIVILEGE_DISABLED; + } + else + { + tp.Attr = SE_PRIVILEGE_ENABLED; + } + retVal = LookupPrivilegeValue(null, privilege, ref tp.Luid); + retVal = AdjustTokenPrivileges(htok, false, ref tp, 0, IntPtr.Zero, IntPtr.Zero); + return retVal; + } + } +'@ + + $processHandle = (Get-Process -id $ProcessId).Handle + $type = Add-Type $definition -PassThru + $type[0]::EnablePrivilege($processHandle, $Privilege, $Disable) +} + +Disable-Privilege SeTakeOwnershipPrivilege +$everyone = New-Object System.Security.Principal.NTAccount('Everyone') +$accessRule = New-Object System.Security.AccessControl.RegistryAccessRule($everyone, 'ReadKey', 'Allow') +$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSYSTEM\ControlSet001\Services\wuauserv",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::TakeOwnership) +$regACL = $regKey.GetAccessControl() +$regACL.SetOwner($everyone) +$regKey.Close() +Write-Host "Owner changed to Everyone." +$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSYSTEM\ControlSet001\Services\wuauserv",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) +$regACL = $regKey.GetAccessControl() +$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ($everyone, 'ReadKey', 'Allow') +$regACL.SetAccessRule($regRule) +$regKey.SetAccessControl($regACL) +Write-Host "Permissions modified for Everyone group." +Write-Host "Registry key permissions successfully updated." + + +Write-Host "All users have been granted read-only access to the registry key." +$regKey.Close() +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2540477E-E654-4302-AD44-383BBFFBFF16}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{341B2255-6A6B-442A-AF5A-C610B7DBE12D}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{476E8CFA-78E2-4C51-854E-538F8643B4FD}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{764DDB74-CB08-4E0A-8580-B41F94F2C7BE}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{817CCFDD-4DD0-4102-AC6E-3F5D3B789FB8}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99CEDA8C-A866-4787-BBD3-6F3C9F61DD5C}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B3CDCDA-4197-490B-AA5C-C9F5F42A9D88}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9CBBFAAE-DB9F-48B4-BAC0-4CFF482A4E01}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A31197EC-EAEE-4837-8A9C-3A17D358B9EB}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4FBEFA9-6F7C-4C74-A891-3774B7BCD072}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B53BD60A-5823-411C-9C75-AA91DB3C35F8}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CECDC345-7460-4A15-9D8B-DAC3F9CC5368}" '/f' +& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" '/f' +& 'reg' 'delete' 'HKLM\zSYSTEM\ControlSet001\Services\WaaSMedicSVC' '/f' +& 'reg' 'delete' 'HKLM\zSYSTEM\ControlSet001\Services\UsoSvc' '/f' +& 'reg' 'add' 'HKEY_LOCAL_MACHINE\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU' '/v' 'NoAutoUpdate' '/t' 'REG_DWORD' '/d' '1' '/f' +Write-Host "Disabling Windows Defender" +# Set registry values for Windows Defender services +$servicePaths = @( + "WinDefend", + "WdNisSvc", + "WdNisDrv", + "WdFilter", + "Sense" +) + +foreach ($path in $servicePaths) { + Set-ItemProperty -Path "HKLM:\zSYSTEM\ControlSet001\Services\$path" -Name "Start" -Value 4 +} +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer' '/v' 'SettingsPageVisibility' '/t' 'REG_SZ' '/d' 'hide:virus;windowsupdate' '/f' +Write-Host "Tweaking complete!" +Write-Host "Unmounting Registry..." +$regKey.Close() +reg unload HKLM\zCOMPONENTS >null +reg unload HKLM\zDEFAULT >null +reg unload HKLM\zNTUSER >null +reg unload HKLM\zSOFTWARE +reg unload HKLM\zSYSTEM >null +Write-Host "Cleaning up image..." +& 'dism' '/English' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' >null +Write-Host "Cleanup complete." +Write-Host ' ' +Write-Host "Unmounting image..." +& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +Write-Host "Exporting image..." +& 'dism' '/English' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' +Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force >null +Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" >null +Write-Host "Windows image completed. Continuing with boot.wim." +Start-Sleep -Seconds 2 +Clear-Host +Write-Host "Mounting boot image:" +$wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" +& takeown "/F" $wimFilePath >null +& icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" +Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false +& 'dism' '/English' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" +Write-Host "Loading registry..." +reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS +reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default +reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat +reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE +reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM +Write-Host "Bypassing system requirements(on the setup image):" +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +Write-Host "Tweaking complete!" +Write-Host "Unmounting Registry..." +$regKey.Close() +reg unload HKLM\zCOMPONENTS >null +reg unload HKLM\zDEFAULT >null +reg unload HKLM\zNTUSER >null +$regKey.Close() +reg unload HKLM\zSOFTWARE +reg unload HKLM\zSYSTEM >null +Write-Host "Unmounting image..." +& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +Clear-Host +Write-Host "Exporting ESD. This may take a while..." +& dism /Export-Image /SourceImageFile:"$mainOSDrive\tiny11\sources\install.wim" /SourceIndex:1 /DestinationImageFile:"$mainOSDrive\tiny11\sources\install.esd" /Compress:recovery +Remove-Item "$mainOSDrive\tiny11\sources\install.wim" > $null 2>&1 +Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." +Write-Host "Copying unattended file for bypassing MS account on OOBE..." +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force >null + +Write-Host "Creating ISO image..." +$ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" +if ([System.IO.Directory]::Exists($ADKDepTools)) { + Write-Host "Will be using oscdimg.exe from system ADK." + $OSCDIMG = "$ADKDepTools\oscdimg.exe" +} else { + Write-Host "Will be using bundled oscdimg.exe." + $OSCDIMG = "$PSScriptRoot\oscdimg.exe" +} +& "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$mainOSDrive\tiny11\boot\etfsboot.com#pEF,e,b$mainOSDrive\tiny11\efi\microsoft\boot\efisys.bin" "$mainOSDrive\tiny11" "$PSScriptRoot\tiny11.iso" + +# Finishing up +Write-Host "Creation completed! Press any key to exit the script..." +Read-Host "Press Enter to continue" +Write-Host "Performing Cleanup..." +Remove-Item -Path "$mainOSDrive\tiny11" -Recurse -Force >null +Remove-Item -Path "$mainOSDrive\scratchdir" -Recurse -Force >null + +# Stop the transcript +Stop-Transcript + +exit +} +elseif ($input -eq 'n') { + Write-Host "You chose not to continue. The script will now exit." + exit +} +else { + Write-Host "Invalid input. Please enter 'y' to continue or 'n' to exit." +} diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 6e2121d8..d8fda8f1 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -34,7 +34,7 @@ Start-Transcript -Path "$PSScriptRoot\tiny11.log" $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host -Write-Host "Welcome to the tiny11 image creator! Release: 05-01-2024" +Write-Host "Welcome to the tiny11 image creator! Release: 05-06-24" $mainOSDrive = $env:SystemDrive $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE @@ -222,6 +222,8 @@ Write-Host "Disabling Chat icon:" Write-Host "Removing Edge related registries" reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f >null reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f >null +Write-Host "Disabling OneDrive folder backup" +& 'reg' 'add' "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" '/v' 'DisableFileSyncNGSC' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Disabling Telemetry:" & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null @@ -233,10 +235,6 @@ Write-Host "Disabling Telemetry:" & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' >null & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' >null & 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' >null -Write-Host "Disabling bing in Start Menu:" -& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'ShowRunAsDifferentUserInStart' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'DisableSearchBoxSuggestions' '/t' 'REG_DWORD' '/d' '1' '/f' ## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. function Enable-Privilege { param( From 5dc7bdce49580bc19479c9bc32fd3469c3a1cb41 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Mon, 6 May 2024 20:28:23 +0300 Subject: [PATCH 32/63] Update README.md --- README.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 5d1e7e18..4bde7c99 100644 --- a/README.md +++ b/README.md @@ -62,7 +62,9 @@ For tiny11 core: - Windows Defender (only disabled, can be enabled back if needed) - Windows Update (Windows Update wouldn't work anyway without WinSxS, so enabling it would only put the system in a state where it would try to update but fail spectacularily) - WinRE -Keep in mind that **you cannot add back features in tiny11 core**! +
+Keep in mind that **you cannot add back features in tiny11 core**! +

You will be asked during iamge creation if you want to enable .net 3.5 support!
From 47ef9128b8544c6504d6bd2cfc80db1fd8329006 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Tue, 7 May 2024 00:00:40 +0300 Subject: [PATCH 33/63] Create FUNDING.yml --- .github/FUNDING.yml | 8 ++++++++ 1 file changed, 8 insertions(+) create mode 100644 .github/FUNDING.yml diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml new file mode 100644 index 00000000..b07f46cb --- /dev/null +++ b/.github/FUNDING.yml @@ -0,0 +1,8 @@ + + +github: [ntdevlabs] +patreon: [ntdev] +ko-fi: [ntdev] + +# Add custom links to support your work +custom: ['https://paypal.me/ntdev2'] From e618386dbd14d74867b084d9795aab49c92a22b1 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Thu, 9 May 2024 01:29:55 +0300 Subject: [PATCH 34/63] Revert "Use PowerShell DISM cmdlets" --- tiny11maker.ps1 | 86 ++++++++++++++++++++++++++++--------------------- 1 file changed, 49 insertions(+), 37 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index de3c21d9..d8fda8f1 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -45,11 +45,11 @@ $DriveLetter = $DriveLetter + ":" if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { if ((Test-Path "$DriveLetter\sources\install.esd") -eq $true) { Write-Host "Found install.esd, converting to install.wim..." - Get-WindowsImage -ImagePath "$DriveLetter\sources\install.esd" + & 'dism' '/English' "/Get-WimInfo" "/wimfile:$DriveLetter\sources\install.esd" $index = Read-Host "Please enter the image index" Write-Host ' ' Write-Host 'Converting install.esd to install.wim. This may take a while...' - Export-WindowsImage -SourceImagePath "$DriveLetter\sources\install.esd" -SourceIndex $index -DestinationImagePath "$mainOSDrive\tiny11\sources\install.wim" -CompressionType 'max' -CheckIntegrity + & 'DISM' /Export-Image /SourceImageFile:"$DriveLetter\sources\install.esd" /SourceIndex:$index /DestinationImageFile:"$mainOSDrive\tiny11\sources\install.wim" /Compress:max /CheckIntegrity } else { Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." Write-Host "Please enter the correct DVD Drive Letter.." @@ -65,7 +65,7 @@ Write-Host "Copy complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Getting image information:" -Get-WindowsImage -ImagePath "$mainOSDrive\tiny11\sources\install.wim" +& 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." $wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" @@ -77,42 +77,54 @@ try { # This block will catch the error and suppress it. } New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" > $null -Mount-WindowsImage -ImagePath $wimFilePath -Index $index -Path "$($env:SystemDrive)\scratchdir" +& dism /English "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" -$imageInfo = Get-WindowsImage -ImagePath $wimFilePath -Index $index +$imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" +$languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default system UI language : ([a-zA-Z]{2}-[a-zA-Z]{2})' } -$languageCode = $imageInfo.Languages[$imageInfo.DefaultLanguageIndex] -Write-Host "Default system UI language code: $languageCode" +if ($languageLine) { + $languageCode = $Matches[1] + Write-Host "Default system UI language code: $languageCode" +} else { + Write-Host "Default system UI language code not found." +} + +$imageInfo = & 'dism' '/English' '/Get-WimInfo' "/wimFile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" +$lines = $imageInfo -split '\r?\n' + +foreach ($line in $lines) { + if ($line -like '*Architecture : *') { + $architecture = $line -replace 'Architecture : ','' + # If the architecture is x64, replace it with amd64 + if ($architecture -eq 'x64') { + $architecture = 'amd64' + } + Write-Host "Architecture: $architecture" + break + } +} -# Architecture enumeration found at https://github.com/jeffkl/ManagedDism/blob/94cf084528f4a986089335327ea67ff747a1dc6d/src/Microsoft.Dism/NativeEnums.cs#L275 -switch ($imageInfo.Architecture) { - 0 { $architecture = 'x86'} - 9 { $architecture = 'amd64'} - 5 { $architecture = 'arm'} - 12 { $architecture = 'arm64'} - 6 { $architecture = 'ia64'} - 11 { $architecture = 'neutral'} - Default { $architecture = 'unknown' } +if (-not $architecture) { + Write-Host "Architecture information not found." } -Write-Host "Architecture: $architecture" Write-Host "Mounting complete! Performing removal of applications..." -$packagesToRemove = @( - 'Clipchamp.Clipchamp', 'Microsoft.BingNews', 'Microsoft.BingWeather', - 'Microsoft.GamingApp', 'Microsoft.GetHelp', 'Microsoft.Getstarted', - 'Microsoft.MicrosoftOfficeHub', 'Microsoft.MicrosoftSolitaireCollection', - 'Microsoft.People', 'Microsoft.PowerAutomateDesktop', 'Microsoft.Todos', - 'Microsoft.WindowsAlarms', 'microsoft.windowscommunicationsapps', - 'Microsoft.WindowsFeedbackHub', 'Microsoft.WindowsMaps', - 'Microsoft.WindowsSoundRecorder', 'Microsoft.Xbox.TCUI', - 'Microsoft.XboxGamingOverlay', 'Microsoft.XboxGameOverlay', - 'Microsoft.XboxSpeechToTextOverlay', 'Microsoft.YourPhone', - 'Microsoft.ZuneMusic', 'Microsoft.ZuneVideo', - 'MicrosoftCorporationII.MicrosoftFamily', 'MicrosoftCorporationII.QuickAssist', - 'MicrosoftTeams', 'Microsoft.549981C3F5F10' -) -Get-AppxProvisionedPackage -Path "$($env:SystemDrive)\scratchdir" | Where-Object { $_.DisplayName -In $packagesToRemove } | Remove-AppxProvisionedPackage -Path "$($env:SystemDrive)\scratchdir" +$packages = & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | + ForEach-Object { + if ($_ -match 'PackageName : (.*)') { + $matches[1] + } + } +$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_' + +$packagesToRemove = $packages | Where-Object { + $packageName = $_ + $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "$_*" }) +} +foreach ($package in $packagesToRemove) { + & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" +} Write-Host "Removing Edge:" @@ -340,13 +352,13 @@ reg unload HKLM\zSCHEMA >null reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Cleaning up image..." -Repair-WindowsImage -Path "$mainOSDrive\scratchdir" -StartComponentCleanup -ResetBase +& 'dism' '/English' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' >null Write-Host "Cleanup complete." Write-Host ' ' Write-Host "Unmounting image..." -Dismount-WindowsImage -Path "$mainOSDrive\scratchdir" -Save +& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' Write-Host "Exporting image..." -Export-WindowsImage -SourceImagePath "$mainOSDrive\tiny11\sources\install.wim" -SourceIndex $index -DestinationImagePath "$mainOSDrive\tiny11\sources\install2.wim" -CompressionType 'max' +& 'dism' '/English' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force >null Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" >null Write-Host "Windows image completed. Continuing with boot.wim." @@ -357,7 +369,7 @@ $wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath >null & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -Mount-WindowsImage -ImagePath $wimFilePath -Index 2 -Path "$mainOSDrive\scratchdir" +& 'dism' '/English' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" Write-Host "Loading registry..." reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default @@ -387,7 +399,7 @@ $regKey.Close() reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Unmounting image..." -Dismount-WindowsImage -Path "$mainOSDrive\scratchdir" -Save +& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' Clear-Host Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." Write-Host "Copying unattended file for bypassing MS account on OOBE..." From 27a7f54e6a0710548a9d9fa6c29f7d5f2f5edec2 Mon Sep 17 00:00:00 2001 From: chinmoykr <46194827+chinmoykr@users.noreply.github.com> Date: Thu, 16 May 2024 11:49:20 +0530 Subject: [PATCH 35/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 4bde7c99..a9280f8b 100644 --- a/README.md +++ b/README.md @@ -66,7 +66,7 @@ For tiny11 core: Keep in mind that **you cannot add back features in tiny11 core**!

-You will be asked during iamge creation if you want to enable .net 3.5 support! +You will be asked during image creation if you want to enable .net 3.5 support!
Known issues: From fb59b449b269b6c73d5b98464fd56054e247cada Mon Sep 17 00:00:00 2001 From: "Robert C. Maehl" Date: Sun, 19 May 2024 18:22:36 -0400 Subject: [PATCH 36/63] Implement #183 Allow ScratchDisk parameter --- tiny11maker.ps1 | 86 ++++++++++++++++++++++++++----------------------- 1 file changed, 45 insertions(+), 41 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index d8fda8f1..72d33b56 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -29,6 +29,11 @@ if (! $myWindowsPrincipal.IsInRole($adminRole)) exit } +param ($ScratchDisk) +if ($Null -eq $ScratchDisk) { + $ScratchDisk = $env:SystemDrive +} + # Start the transcript and prepare the window Start-Transcript -Path "$PSScriptRoot\tiny11.log" @@ -36,9 +41,8 @@ $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host Write-Host "Welcome to the tiny11 image creator! Release: 05-06-24" -$mainOSDrive = $env:SystemDrive $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE -New-Item -ItemType Directory -Force -Path "$mainOSDrive\tiny11\sources" >null +New-Item -ItemType Directory -Force -Path "$ScratchDisk\tiny11\sources" >null $DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" $DriveLetter = $DriveLetter + ":" @@ -49,7 +53,7 @@ if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$Driv $index = Read-Host "Please enter the image index" Write-Host ' ' Write-Host 'Converting install.esd to install.wim. This may take a while...' - & 'DISM' /Export-Image /SourceImageFile:"$DriveLetter\sources\install.esd" /SourceIndex:$index /DestinationImageFile:"$mainOSDrive\tiny11\sources\install.wim" /Compress:max /CheckIntegrity + & 'DISM' /Export-Image /SourceImageFile:"$DriveLetter\sources\install.esd" /SourceIndex:$index /DestinationImageFile:"$ScratchDisk\tiny11\sources\install.wim" /Compress:max /CheckIntegrity } else { Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." Write-Host "Please enter the correct DVD Drive Letter.." @@ -58,14 +62,14 @@ if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$Driv } Write-Host "Copying Windows image..." -Copy-Item -Path "$DriveLetter\*" -Destination "$mainOSDrive\tiny11" -Recurse -Force > null -Set-ItemProperty -Path "$mainOSDrive\tiny11\sources\install.esd" -Name IsReadOnly -Value $false > $null 2>&1 -Remove-Item "$mainOSDrive\tiny11\sources\install.esd" > $null 2>&1 +Copy-Item -Path "$DriveLetter\*" -Destination "$ScratchDisk\tiny11" -Recurse -Force > null +Set-ItemProperty -Path "$ScratchDisk\tiny11\sources\install.esd" -Name IsReadOnly -Value $false > $null 2>&1 +Remove-Item "$ScratchDisk\tiny11\sources\install.esd" > $null 2>&1 Write-Host "Copy complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Getting image information:" -& 'dism' '/English' "/Get-WimInfo" "/wimfile:$mainOSDrive\tiny11\sources\install.wim" +& 'dism' '/English' "/Get-WimInfo" "/wimfile:$ScratchDisk\tiny11\sources\install.wim" $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." $wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" @@ -76,7 +80,7 @@ try { } catch { # This block will catch the error and suppress it. } -New-Item -ItemType Directory -Force -Path "$mainOSDrive\scratchdir" > $null +New-Item -ItemType Directory -Force -Path "$ScratchDisk\scratchdir" > $null & dism /English "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" $imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" @@ -128,11 +132,11 @@ foreach ($package in $packagesToRemove) { Write-Host "Removing Edge:" -Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force >null -Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force >null -Remove-Item -Path "$mainOSDrive\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force >null +Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force >null +Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force >null +Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force >null if ($architecture -eq 'amd64') { - $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "amd64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName + $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "amd64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName if ($folderPath) { & 'takeown' '/f' $folderPath '/r' >null @@ -142,7 +146,7 @@ if ($architecture -eq 'amd64') { Write-Host "Folder not found." } } elseif ($architecture -eq 'arm64') { - $folderPath = Get-ChildItem -Path "$mainOSDrive\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName >null + $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName >null if ($folderPath) { & 'takeown' '/f' $folderPath '/r'>null @@ -154,22 +158,22 @@ if ($architecture -eq 'amd64') { } else { Write-Host "Unknown architecture: $architecture" } -& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' >null -& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null -Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force >null +& 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' >null +& 'icacls' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null +Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force >null Write-Host "Removing OneDrive:" -& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" >null -& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null -Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" -Force >null +& 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" >null +& 'icacls' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null +Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" -Force >null Write-Host "Removal complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Loading registry..." -reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS >null -reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default >null -reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat >null -reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE >null -reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM >null +reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS >null +reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default >null +reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat >null +reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE >null +reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM >null Write-Host "Bypassing system requirements(on the system image):" & 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null & 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null @@ -213,7 +217,7 @@ Write-Host "Disabling Sponsored Apps:" & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Enabling Local Accounts on OOBE:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' >null -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null Write-Host "Disabling Reserved Storage:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null Write-Host "Disabling Chat icon:" @@ -352,15 +356,15 @@ reg unload HKLM\zSCHEMA >null reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Cleaning up image..." -& 'dism' '/English' "/image:$mainOSDrive\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' >null +& 'dism' '/English' "/image:$ScratchDisk\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' >null Write-Host "Cleanup complete." Write-Host ' ' Write-Host "Unmounting image..." -& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +& 'dism' '/English' '/unmount-image' "/mountdir:$ScratchDisk\scratchdir" '/commit' Write-Host "Exporting image..." -& 'dism' '/English' '/Export-Image' "/SourceImageFile:$mainOSDrive\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$mainOSDrive\tiny11\sources\install2.wim" '/compress:max' -Remove-Item -Path "$mainOSDrive\tiny11\sources\install.wim" -Force >null -Rename-Item -Path "$mainOSDrive\tiny11\sources\install2.wim" -NewName "install.wim" >null +& 'dism' '/English' '/Export-Image' "/SourceImageFile:$ScratchDisk\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$ScratchDisk\tiny11\sources\install2.wim" '/compress:max' +Remove-Item -Path "$ScratchDisk\tiny11\sources\install.wim" -Force >null +Rename-Item -Path "$ScratchDisk\tiny11\sources\install2.wim" -NewName "install.wim" >null Write-Host "Windows image completed. Continuing with boot.wim." Start-Sleep -Seconds 2 Clear-Host @@ -369,13 +373,13 @@ $wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath >null & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -& 'dism' '/English' '/mount-image' "/imagefile:$mainOSDrive\tiny11\sources\boot.wim" '/index:2' "/mountdir:$mainOSDrive\scratchdir" +& 'dism' '/English' '/mount-image' "/imagefile:$ScratchDisk\tiny11\sources\boot.wim" '/index:2' "/mountdir:$ScratchDisk\scratchdir" Write-Host "Loading registry..." -reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS -reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default -reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat -reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE -reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM +reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS +reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default +reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat +reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE +reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM Write-Host "Bypassing system requirements(on the setup image):" & 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null & 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null @@ -399,11 +403,11 @@ $regKey.Close() reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Unmounting image..." -& 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' +& 'dism' '/English' '/unmount-image' "/mountdir:$ScratchDisk\scratchdir" '/commit' Clear-Host Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." Write-Host "Copying unattended file for bypassing MS account on OOBE..." -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force >null +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\tiny11\autounattend.xml" -Force >null Write-Host "Creating ISO image..." $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" if ([System.IO.Directory]::Exists($ADKDepTools)) { @@ -413,14 +417,14 @@ if ([System.IO.Directory]::Exists($ADKDepTools)) { Write-Host "Will be using bundled oscdimg.exe." $OSCDIMG = "$PSScriptRoot\oscdimg.exe" } -& "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$mainOSDrive\tiny11\boot\etfsboot.com#pEF,e,b$mainOSDrive\tiny11\efi\microsoft\boot\efisys.bin" "$mainOSDrive\tiny11" "$PSScriptRoot\tiny11.iso" +& "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$ScratchDisk\tiny11\boot\etfsboot.com#pEF,e,b$ScratchDisk\tiny11\efi\microsoft\boot\efisys.bin" "$ScratchDisk\tiny11" "$PSScriptRoot\tiny11.iso" # Finishing up Write-Host "Creation completed! Press any key to exit the script..." Read-Host "Press Enter to continue" Write-Host "Performing Cleanup..." -Remove-Item -Path "$mainOSDrive\tiny11" -Recurse -Force >null -Remove-Item -Path "$mainOSDrive\scratchdir" -Recurse -Force >null +Remove-Item -Path "$ScratchDisk\tiny11" -Recurse -Force >null +Remove-Item -Path "$ScratchDisk\scratchdir" -Recurse -Force >null # Stop the transcript Stop-Transcript From eeb3c580e2ad763c92fbc35e4ed60e53829b9eef Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Mon, 20 May 2024 21:02:09 +0300 Subject: [PATCH 37/63] Added oscdimg downloader --- tiny11Coremaker.ps1 | 32 +++++++++++++++++++++++++++++--- tiny11maker.ps1 | 30 ++++++++++++++++++++++++++++-- 2 files changed, 57 insertions(+), 5 deletions(-) diff --git a/tiny11Coremaker.ps1 b/tiny11Coremaker.ps1 index bb72f855..03a01d29 100644 --- a/tiny11Coremaker.ps1 +++ b/tiny11Coremaker.ps1 @@ -727,15 +727,41 @@ Write-Host "Copying unattended file for bypassing MS account on OOBE..." Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force >null Write-Host "Creating ISO image..." +# Define the path to the ADK Deployment Tools folder $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" +$localOSCDIMGPath = "$PSScriptRoot\oscdimg.exe" + +# Check if the ADK Deployment Tools folder exists if ([System.IO.Directory]::Exists($ADKDepTools)) { Write-Host "Will be using oscdimg.exe from system ADK." $OSCDIMG = "$ADKDepTools\oscdimg.exe" } else { - Write-Host "Will be using bundled oscdimg.exe." - $OSCDIMG = "$PSScriptRoot\oscdimg.exe" + Write-Host "ADK folder not found. Will be using bundled oscdimg.exe." + + # Define the URL of the file to be downloaded + $url = "https://msdl.microsoft.com/download/symbols/oscdimg.exe/3D44737265000/oscdimg.exe" + + # Download oscdimg.exe if it doesn't exist in the script's directory + if (-not (Test-Path -Path $localOSCDIMGPath)) { + Write-Host "Downloading oscdimg.exe..." + Invoke-WebRequest -Uri $url -OutFile $localOSCDIMGPath + + # Check if the download was successful + if (Test-Path $localOSCDIMGPath) { + Write-Host "oscdimg.exe downloaded successfully." + } else { + Write-Error "Failed to download oscdimg.exe." + exit 1 + } + } else { + Write-Host "oscdimg.exe already exists locally." + } + + $OSCDIMG = $localOSCDIMGPath } -& "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$mainOSDrive\tiny11\boot\etfsboot.com#pEF,e,b$mainOSDrive\tiny11\efi\microsoft\boot\efisys.bin" "$mainOSDrive\tiny11" "$PSScriptRoot\tiny11.iso" + +# Execute oscdimg.exe with the specified parameters +& "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$ScratchDisk\tiny11\boot\etfsboot.com#pEF,e,b$ScratchDisk\tiny11\efi\microsoft\boot\efisys.bin" "$ScratchDisk\tiny11" "$PSScriptRoot\tiny11.iso" # Finishing up Write-Host "Creation completed! Press any key to exit the script..." diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 72d33b56..9b263b49 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -409,14 +409,40 @@ Write-Host "The tiny11 image is now completed. Proceeding with the making of the Write-Host "Copying unattended file for bypassing MS account on OOBE..." Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\tiny11\autounattend.xml" -Force >null Write-Host "Creating ISO image..." +# Define the path to the ADK Deployment Tools folder $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" +$localOSCDIMGPath = "$PSScriptRoot\oscdimg.exe" + +# Check if the ADK Deployment Tools folder exists if ([System.IO.Directory]::Exists($ADKDepTools)) { Write-Host "Will be using oscdimg.exe from system ADK." $OSCDIMG = "$ADKDepTools\oscdimg.exe" } else { - Write-Host "Will be using bundled oscdimg.exe." - $OSCDIMG = "$PSScriptRoot\oscdimg.exe" + Write-Host "ADK folder not found. Will be using bundled oscdimg.exe." + + # Define the URL of the file to be downloaded + $url = "https://msdl.microsoft.com/download/symbols/oscdimg.exe/3D44737265000/oscdimg.exe" + + # Download oscdimg.exe if it doesn't exist in the script's directory + if (-not (Test-Path -Path $localOSCDIMGPath)) { + Write-Host "Downloading oscdimg.exe..." + Invoke-WebRequest -Uri $url -OutFile $localOSCDIMGPath + + # Check if the download was successful + if (Test-Path $localOSCDIMGPath) { + Write-Host "oscdimg.exe downloaded successfully." + } else { + Write-Error "Failed to download oscdimg.exe." + exit 1 + } + } else { + Write-Host "oscdimg.exe already exists locally." + } + + $OSCDIMG = $localOSCDIMGPath } + +# Execute oscdimg.exe with the specified parameters & "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$ScratchDisk\tiny11\boot\etfsboot.com#pEF,e,b$ScratchDisk\tiny11\efi\microsoft\boot\efisys.bin" "$ScratchDisk\tiny11" "$PSScriptRoot\tiny11.iso" # Finishing up From af2e6159d0eded36cd31bc80b3599238b1f78792 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Mon, 20 May 2024 21:04:18 +0300 Subject: [PATCH 38/63] Add files via upload --- tiny11Coremaker.ps1 | 7 +------ tiny11maker.ps1 | 6 ------ 2 files changed, 1 insertion(+), 12 deletions(-) diff --git a/tiny11Coremaker.ps1 b/tiny11Coremaker.ps1 index 03a01d29..40316479 100644 --- a/tiny11Coremaker.ps1 +++ b/tiny11Coremaker.ps1 @@ -727,26 +727,22 @@ Write-Host "Copying unattended file for bypassing MS account on OOBE..." Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force >null Write-Host "Creating ISO image..." -# Define the path to the ADK Deployment Tools folder $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" $localOSCDIMGPath = "$PSScriptRoot\oscdimg.exe" -# Check if the ADK Deployment Tools folder exists if ([System.IO.Directory]::Exists($ADKDepTools)) { Write-Host "Will be using oscdimg.exe from system ADK." $OSCDIMG = "$ADKDepTools\oscdimg.exe" } else { Write-Host "ADK folder not found. Will be using bundled oscdimg.exe." - # Define the URL of the file to be downloaded + $url = "https://msdl.microsoft.com/download/symbols/oscdimg.exe/3D44737265000/oscdimg.exe" - # Download oscdimg.exe if it doesn't exist in the script's directory if (-not (Test-Path -Path $localOSCDIMGPath)) { Write-Host "Downloading oscdimg.exe..." Invoke-WebRequest -Uri $url -OutFile $localOSCDIMGPath - # Check if the download was successful if (Test-Path $localOSCDIMGPath) { Write-Host "oscdimg.exe downloaded successfully." } else { @@ -760,7 +756,6 @@ if ([System.IO.Directory]::Exists($ADKDepTools)) { $OSCDIMG = $localOSCDIMGPath } -# Execute oscdimg.exe with the specified parameters & "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$ScratchDisk\tiny11\boot\etfsboot.com#pEF,e,b$ScratchDisk\tiny11\efi\microsoft\boot\efisys.bin" "$ScratchDisk\tiny11" "$PSScriptRoot\tiny11.iso" # Finishing up diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 9b263b49..5a159a37 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -409,26 +409,21 @@ Write-Host "The tiny11 image is now completed. Proceeding with the making of the Write-Host "Copying unattended file for bypassing MS account on OOBE..." Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\tiny11\autounattend.xml" -Force >null Write-Host "Creating ISO image..." -# Define the path to the ADK Deployment Tools folder $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" $localOSCDIMGPath = "$PSScriptRoot\oscdimg.exe" -# Check if the ADK Deployment Tools folder exists if ([System.IO.Directory]::Exists($ADKDepTools)) { Write-Host "Will be using oscdimg.exe from system ADK." $OSCDIMG = "$ADKDepTools\oscdimg.exe" } else { Write-Host "ADK folder not found. Will be using bundled oscdimg.exe." - # Define the URL of the file to be downloaded $url = "https://msdl.microsoft.com/download/symbols/oscdimg.exe/3D44737265000/oscdimg.exe" - # Download oscdimg.exe if it doesn't exist in the script's directory if (-not (Test-Path -Path $localOSCDIMGPath)) { Write-Host "Downloading oscdimg.exe..." Invoke-WebRequest -Uri $url -OutFile $localOSCDIMGPath - # Check if the download was successful if (Test-Path $localOSCDIMGPath) { Write-Host "oscdimg.exe downloaded successfully." } else { @@ -442,7 +437,6 @@ if ([System.IO.Directory]::Exists($ADKDepTools)) { $OSCDIMG = $localOSCDIMGPath } -# Execute oscdimg.exe with the specified parameters & "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$ScratchDisk\tiny11\boot\etfsboot.com#pEF,e,b$ScratchDisk\tiny11\efi\microsoft\boot\efisys.bin" "$ScratchDisk\tiny11" "$PSScriptRoot\tiny11.iso" # Finishing up From 9d9e51758adfeb2566e8a4fb35f5f1fd72466838 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Mon, 20 May 2024 21:11:14 +0300 Subject: [PATCH 39/63] Delete oscdimg.exe There is no need for it since it downloads it on the fly now. --- oscdimg.exe | Bin 148968 -> 0 bytes 1 file changed, 0 insertions(+), 0 deletions(-) delete mode 100644 oscdimg.exe diff --git a/oscdimg.exe b/oscdimg.exe deleted file mode 100644 index 3270677f847379b808eadde20641cac53338eae9..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 148968 zcmeFad3Y4X_BTG0NkdqM4#-Fp0s{mE0~if>GltPL%s>xJBy1W51Vkb(D9a3>Y>Ayn znxfqmy?U=+H@sJ`;PQnK6%&F9`>GN|1zfPh2*!h4KE{66pd@9$@xC(~Wq zsZ*y;ojP^uRCVqxk2+iqha(aHhT(9O;Yoiv{P%zV(UIJ)TX{Rjd#$#2FLQ>scON_b z&N<$hv+uiO_LLdksZ;K~_r8etwrSqk(R;mj-s=sF9OIpF-|f@-yWOqREYMvO`+juG zw81~v|Ls$U9m_|!eX4ZqR{k7%Y$SgUIW~#s8}h?09v*&dEPsCZ!+8G8IY!UXcTSy7 zu+GOkFX(XG{!k0Y-ygfnYp2yadN|r7wCn1~aXK9JL;;7xdl7z;`76bm?+CZXEB&{i zIQq-M8{!+DOaT2RSH>x3mPH2ZB_58)@ZxRvIvs=P&D+A!o2pK3;h333;RJ`?3(t%e zjyybas-2Fpc>dX6a-Nf;Z>Q&tayqZJ03jP)NivoX9;4cdNMS;I4 z@D~OCqQGAi_=^I6QQ$8M{QsB&+pND?8KZ95!S*8^A-^WXP%zt;MS< z%*BHV6ZSbBsuLMnA_Eg79@NWGSn<1d0bbNCYwicIiZ(pk04lRWRyOvo;w_vde}3cB z*Zow2_GK}l9g2oEVIC?EF!!0yP>JT5f{-fQhhIPm^M^ojvKmP98lGDKQ5CW%LfM#Q zLfy7aRwtw-$!a7mSymUOrARlSf{bZ0OYD___Q@1T!~y)%F6YQ$fcq3nRd6bmY~}Tx=)+iO*R#Fj3E`#OA zQAb7-HT4Eik_jD6BvL^am1@x3v+>X`Yw2**2)}?}wA3y+5p4w`FBQHb3M&31csL>h zkoilz>4iWY(9?iM@BQi)ogI`B9iP&U1sHON{TS&whyzegeT*KUH8n_bWWH73F>h$=ekF zTs!-Jc=p>7l-Y!|9GOMZWSK2Y%R{$jNRzCNo%PZe9qwB3>}nbh`Uo_HSgEevS;MeL zO!H?!f!K{09@(cnOx9NX&6ywm0Y;sW=a=gV zk*$X3XS^7mGuKgYQ+caIM+K_%j+c#In~*YV%jcJ_=~VWttcJmFML(2MU7C9anqhc$ zau`BBdXAV?2AO4TELz0EX|myYostosBP$EjavYJta!nvDi({(=(()-OL&n==dh3lr z-ie5VcW)Q~a>5KCWd?YJ?-&4!^+f+I;}k?b;Shfl?x%-R0lpIMHDhY%fibfK4_2H; zCL{!Xh^-MsL{cMbgjRT?@lYdNgf}uqmXRS$zPo~2*oF$%Bsz)T?06^Qe*u-jEgiQ} z6&;;+QUa1{%_Qe}NyzU0ZYyOECr-EXlQ^lhBT@E;Yr%Kp(amzvMxt?ioGU-fNAm9g zZFnZ}P7-uN4P-i>-dU84`2TBquOx*3gx=ryEqY%{wK3!qX7V>qH;dk9d5eXcI6}fE zG`vQ53%@3TU&otC;CHMyyY)oi{~(SC%xSKLLlYxz1 zp7^^p3}!vCw?pOimEX{Kk(sk7YwDaChoU`|`6-FfR3>}1qC=BxE3 z8Et8JMiP|fQo3nOHJ^`w5qir;9vQ8YH_aWi>IaD2wJXSqyHF*)EERwEzUQW17r1fB-3R0+?gg z9I_ceLxy1MgMq3q1!5HFvW_^kz$Z_LCbG(ySfI?G;Np{<7}(FM_*k}}8NFJ>vCgcB zSHYVR25!O3&0$w%nC+3owK*Mw;@bQc=;xG>t0Gu(AkvlPwGC(QncbSnNvmG9YL7DBPmC7^d8B{K+pTQu6_=Fd2dyUJ5XfvUTUuH~A6m|3yTR0xKrh)-5jHAjnZ@{W_) z4;(FJT8cw{|LT_x_IoxRU4eOh6UdugC6+t^9Azyx#qd0hQ7N-vimV2c4bO`Ru?qPr zdSBk`eZKi#c__t9n{I}+++;a3i2q6e^O_*0QBu$=uOq&qeGj?vkQce=KUwZsiJqm2 z+AWu5#u3{jtL|582$2bphYesC;hz))X(m?9nl(26NXydNcsq?=qq3V=GfuM&_9PIG zF<)%{(mU}+cN{NQew`@0hzY&p<9zdU9OSG=$9MStpEGw@bBW@=O~(*NA4ew2C7UDp zHAUM1h(^8sn1^s~1Fpin0PZ$CcVsyoVmGh=q7lqHH@N$6@zfDXveMImEMLasn&Cs3 zQ(q?ERF;9N^ori7DE$z+a4~i*UZvdzO*-tNeVzV$*d8DZjKjXH8NXn)|9zTzrT@K z{P{GQU>9v9)S6f~XAE$~7E8xCu6sUihHJvPxL(U~9g<`ti-HZah$#t6!*kO$7TQ{u zAdP+?TCu%3qG496KRnyv2tfdF3;`b)?rQ*sgjs^a?pvZ|fC;G}T;?8DDI1$G+(Vjd z$PK%}kD-Qo#h?Bo`ZLTbKwrr0NI%6t3r|NhtsG5sWN(<)d9c>jk-cT^Md`a#;YOsX zo-lsPoJgi5)g44IE^tuaf2r|WkpZ<%?&SdCh(9h+_3Gnx)h{sZ%nmEALOkfQcaTaGN{Bteym|tJ>kr zJR!3$<&tBOd~mRt*YI?=Gmu_@$tjoY z0mOvC@X&{`MVL+gS_S_)ql$jVkQ=FgeWjpy09y`DuF{Tn*O^86@yN4r^5odT= zy~kRgNMnh-Ot@)3b!Lc@xL8I{b8+F*TaSpW}d%cvo(^Pc`O%{_UE$CW0&Nz5&04erRj}l3`0^S zZ-@=a4`a2Ki_ZVr_&Aq6|AY5ur-OofV`$^M1Tiu}@z35sFJrKBIsCcP5zO2Z>lI?5 zWPOzhC?&)s0FqO3OEyQ3NXCYdZ22eNQv_*q^s|7^-5G$QnEZst_n-+(1_w*Y7y&U! z@t*==9MLSrAEer%S3+bH^x?_+C=PuvpbrN0JfOLUpjVD$Pi`~u+!OtbdOw5sAdBGmuNP|1rL1|cV}Yhjeg@t;SQ< zp5z&1wnM*fF9f9y4r}9YkNsh>_5m*+8JmltJ~B7^w|T>J*_XNL zUxhU0fW9hc@0^zv)Sfs);*0GKvJDax8Lbmq#I{OhlqKxiDyfN=hS;YewoSkEO4547 z;#6MO%iu7FSX_;oGEXQ*U-7{;cnxNLD{CVXL#}N_zW0{yJS~=#AXX~#;uovo*c0IB z3ElZ({JvbRZI>XsIZaYd_nke3)udMkvTNt%2N;IqUc$u*TtdjCI)mDnGcwx^9HBHG zy%=MVZ5g3;9DsTVikf%{6S`FpON7(%16qy|bX6If8g>PGR_Ie94MC~9Tmygqh(^m1 zSsU6{&aM$38V%(o%+N=C_y=erEYCY4{O zrlFLwak4Z?x>cGeO_+4+#Hwv*=+%#7ByBeIYb&6#Abj*OGkk>={v2VpUGGdm^Uu@; zxRmja1)@wiPScChtNI}C)YKY0G0GbuVa4K8s9I(tXz>J_fD@8_enwoTjhL)#F%Xq| zr4^;TPx_1_nk$zW(L|Xo@IvyFJ^+TV0sqRCx|i((V`iY#(s-#xLoEIWuZR?#JM4Jk zfrohXn8{dOT#t2=eq9aW^Tdl3t-1SBR636uA*1LA{hM&hL-@^R;e3RjZwj{|1uPkH zrSUjYqM&7K?(HCm{s}maW)MD1A*sWRGz`y_=gA?EG9XUd*;@^u$-7Z97F%j}g+TbKtWx%x?%DqvA z#k!h$FG>bnyGU-S`F-)g`c2L+y1y@}#p2TMQ4|6W(sE-%?Rr`^Nb6}}1v?***`3K! z!vU$Nit7&;qhWDvt~W@^&Ws$TvOB9pH7-mX)mq1^r0l)o&}wafQ_>UyAc;e(r0iV* zRx4=_SrOF%k}AidWmIFZ#E2wo4-xEgQcdKZ8)6BpI;2X;VHP3*E0$bN+Ivk{bC3O$ zgjd^>Bxb*3!lxe)|4*QCaZlRhfa)p4Yy)jda&4hO)pL{Tz6&v2P7>dP>p9c^7YcUf zW_{>~=g_|_IDhIrLq-pAsE^eH8(A&V@d#jvSSCdy_fbliZASF3h?dGp97*CDXUM3; zW0#z{ORCh-!@^GVa3C}BQAycgM86EEMU>N)(s5g2TxW<&>Y^XK5Wbi*E`y2C(yPhW zMP{iJwgKUa%wuFd$ULF;dlAzU#4)i<1|Md_U{I0XKZJg(yBM$H+96)0I>}WJU7~l+ ziE3x$O2z;4w-}!hZxA{U?31bW2u3>KmYn054y zUC=75Aa`m^P&x$3mLRE4Ei$wg#PzpHcShM zYlnFQ+T(;rfb9rs)4NOTW3XnxrJJlbL~DCx_7<>bP#n4wy3U>e%xqrR7{4Jf^#OHk zTAEmV0|oBu64q`{%M;7L6KOglgxPjhB|*eeuRmT>d90gJC6*s@gvG&Mi{*#K*;gxm z2LXyEkq|zNd_gR4m0G+EDIDbOA8A7muUJAekp#g>(mHyXuisWou2B$9)UWc=3?P>L z6KMg=5a=s3k_>86Wt{+1b}`I0Mzn7(~@*3X6eVfMxWxV67wE^t_*Ffwc(<$L)j~VF7TZ zRI`%`0@;(ib1&wU$HXhMPWpgL?H&v;kdwDU@y|ms$1rVBpU4&9jA$=8+dm6Y#D4yn z^aA$t--nlIYxJ4y6xxt=fGx?A*dFTWl5UvOSigVMbOYuj%K}%<761OjfE;NrX-kPO z)|nEdGUlS`P92g=Y(wUGK2pj_uF-HQ`GOQJqgvKd6QD^BXI*}=hf?$))?H=b`GEsa z8DxoThb>CFA%fO-d`x0}*HDL9S$m%IX^4%_2(i1fLTpY>hcGh;Mk7PJKPlj9Bq9Z{O^~6^q;YQz^xo#okPAS* ze#q?jh))Y2@^OA8joamEIUv3@bcdzbgL$$QGY~QMFs3TPECcH;vG``RCxEq-_kCLa zVZyqxhoor)R!bb$15s#QUssKk{V^tw?HH#&`ue$0KL%@Wv6ysbi7m$XgehAr|6U|D zl<;6X(dPm79Y*KI${)K)Mh%+er6HOt4z3IXXpT8fef@4e2u@3)v9$;Vl~XfCC4!d% z$=4+>(zZZS2IXO#PNAAUz>kACumVqCziucgmb`)Y5L=u?TGmbskf-`sBZu4AWTqpo z$c{5rXj)nR7VAXnft-Nk+v3UC$jO(p8zN(5=#%MC(hi-4VKaHj5IOz0tbB*S?@3Fp z$vhV8RiHF_=k^!Z?!vgeA`1R6Je`|^xd{6`3F6w81pv9X?j<0Zd5q{BEcsR}CNo=* zZHExKejtV@p{q+~9n0bDrhnl(^ z@zK^nED41mOwVYt@aelW=E!~&(hB*!Xq%D9e&imF5}A99&3uW}FmNSuyEZk{_S_^v zTXSv2GPMGr*>2U{7dhEak#4H{XY`p;nXDYHSKSv=>~8iGOzo=hB@$5OZ2$s0S4dn{ zf$}*hk2&7+IZ$iKJ_B-*B(_CbM}wKxDoM0%R|Ns-tdhzgP`|&)LPWHN99)=|JWkf$ zOshDJo-O(zN1)O|w|4-XL|{oqB1O1w+)Mkpm=-^BU{vyDLFNIruauM^*o%8u98BB` zQ#N*%jf$);&S)csgBN^%(N)x4`^;p+oDgx z%e|$SmD^g40F3(xt?doZT06;?I_Lm$6@$wO-IbKAJw@DrC7Zqr!+@~wU7$|P2y4L% zLPg`^-tfe*)U-^axzw0%?C?jh9zrLGb^=Pb03|Avo1u5R75ii+-UZ6SV8(<V6EL zYUvSnhX5s_3_1h zyJA$nq&;8U_X)5uSlFNHJG+}U>`Wkg*St>9+s~+(Si)m52a%W765WN%r zuD_Ae8Y!w!TT2RVh^KX+G|k;>HKDOrUnkO-q1C#KHS`k5P8ljF*Ia1Dl0`!#hgK(( z>gJBIWdXI(G$)QTtvEN)&?tl`!q6z>BSA=9g$nr4m`U?IOHHrft`1{&QN<^#u|S53 znMh=z!61DI`eWAIR}dim0sZXiY4vkR*#_y2JR#VGY->Cj++cT527y7stfm?x13g0Q zIvFu2zOiYnk-$@;uPBX@K-b_%=IC@*o4v)W+omplKVP)i$(PzLZ@vw-xaP zBv9;2kc$8k_SnA1sKXve0`@@2ntiFnKDE*T;`eTGsUTwu`!huSY)2t;E7FkbzNKw! zc95@!6pruty@{+O(K>D@X~msafNjR&g#Tdl0PycpPTgl^K@}@(C|ot>ymY2Z91Dxf55>7WvZR^3YDN}f z@j+0Bo3Z$(Hkfl+e7zlQvA8ZAv^zD@qwYS=+hnVAe@PAI2tAi-ArxX?5qDog+`R*x zYjgMiV%MSlnAERVV;1><>{w8$sP&1RL)ja#xH%-jVx9B~^_6=X(!$vFWCQ1Ha5}*C z5JC=TSR3HN9+fj!yAP}5P>L!i1euf~u}zhA_^psiZ%C-rlcmz3SoK!G28Fl8VChi7 zw(>ElZ-Jx^YY`8R>dQ8m`C3S&H?|BZ)vfDZM`hyL#a^j&5zSdr>2+*qilhb;*o`Ta zI|Wb^=!I8gmrq1_tZatzHKSQiuthv<)f3Wk2`65c%r4fGTN7C?4rw<)->uP|JUBET zM$yAgr83F2Q)V+$!mhfo>nH5Vi6zsBY#+2H41iS(p;3 z>#>tW6Koz$uvq#>;O~S9HohRQ8`aL9Xwh{S+MgV2ZJVIedI9F2ciNbjc&Dv~9)?a^ zZ}pa}4RS$dy@S|XZC>l@mQJ#AvQb_&FM-|yO!CINu5={zT$l$L z^;>UF_tIf4N^fe3#a`>W3f^mX_i!DPO8W=cr#YoiFNWm96-QEUNZ_w|UfzAB!_3}8 zWfqXc(woqA=5inQU{o~}U1xKkv@s7kPIcUSp5JAMy78 z*)h1h#W`be5f7d>2GMhW9D}?6=MQ7>hF7g#JNCvoz4oVLa68V}#``SpCrN%Ia`x6} zt7>8E4$L00FgEubs7>>HfUv$7ECLyy2i4W|DAC-nARaSFzm&Kt1CJB;!-%zgPCD30 zuvN^Z+z#8z?%D?6dwd| zbBoFSFv2`d&!8GLVG$zEX*l7V(tMX#yC^dDN^0?D0RxNt+07~6LSShyN95v8Wn-8 zw3bkpl}6WG%yUz)Pe?|%6l{i?7Oa+t0E`}Tx#7Y*z0~38n=$Chc`an|(l4MsEP&iB|c*%tpisBAf*nvk;HgM^|?r4&a!GTs)uH!Wkee|hUIRM zD8!o@v?0@8PEz(SV)1gMl|$!rC}&&G9;=+aeU6~raymA==q$OO&uRHS(KnV|bT;{N z9>iM95$juY_Qi*slnTw(5lbyPn=@FXAQ%_U{6%LApMJ(6Dla31#r2lKT4HAUR*b;8 zcfxgj1NK-rN-)yyNZ%d8tZjG}cC@=1yLv-mn&Rl*YsaGO!%&m$mJl@!&&+r#tFcoM zeX|`cGgu~|N|){-CGGjNM~O#^HWI7GXLZ`l&SgP#f#+Y-xoz#Pe>D>^+h8Z?4TGD6 zxgUm^uWCqy?UGgay>Tm%>4PS-;W8Z54?$BaPzS?@<}J#n4o(iMgL~6%FO(c%!zPNu zVr)33BjG(Bl9H_8t7b4c#B%b(s_+_g0QgxXW9V7u6G-UAbq>=X3hCIQAty5QPbd#lsNwY)kIdN9ikuIp-!xqVG>j){;KzZDk-yC z6p8l2jyaZ^!NLd9*sxJOk#z#)2L5CtpCX(tI$}3>RDBFRXBc!oU|<>JWu4 zzl~zze}B*q%w6^j7>s0gG|YaI=pak7WA2o7$!LRK`zkgi)*6OL8eZk`j%o&6*^)5m zCZU%OLgj;St&km#_o+}AcFf+{r@4!FF8PLhDh@sf-!A>)dJLed^wY9S54-A>Y9m@1 z>nba^r}YL{`1IbM=7q`)t=GLAAocHmG${doXr{vA(1LVp+~JG(2-~zt*4zc{>SuHM z+!;;9C<_CQHGe@+c|5RnanTs_n^UU(5zQj3WwShWHUpseF)aF;CGD`2sB8YZQ1 zTns=Pp|JCrh`dqm4uRb=%-Kw@<_HY4C&wLn3CM^N513Wcgte>RKSbIkFb#ne0L03LK&e*P?xZImU)bCA}y~ z8?AXvIE{5_$AY}A>1GfD#Ro;XREdkv!WDKL;w zCEudO;Lw*St`C||aYqmr8>#pgQWsz-{C5gqsKR0brMZXQMh{^%MT!CNImn|5_oHE$ zI|~OTk;#h*&r*X_f&4U7_aG_>CL;wuhx^Q6q2O6F$sFxZKZmi*m-3#iR+Q2dRgWkP z_*qRcEhh7rNlh_b5JPe#Y(e#eV<-@ zl6n))HT!4?45uv-t!-CJZ?wGrCe>X$$gcmqx{2%dqa#n+U2QqpZY8Ug;rZH*CQdcE z{%q`0SYDjAgKb4T2a+$9vrm&#M~$40!wro|OIpe4(7etjF22S-Gl1@b`or~M=uC5U zam{YD=7D^)#_-H(4s1KzVVAWj-W=VBi4mOh(Vx-JZo@#k^to;5YDfQR8_vWT`+sf2 z$P2VVlXeZdVqUVPJ3^)6T4N7QdSTEdb32=j+kO*o+|$i!iM(ewZoS#K*X+if*FUCv z@K10LHpn;ll4yfX_+ib#b!*-w{hFn~arAVzm`gd`bzXm*6Y06EU144S!jo6c^UCGF zi!h{igX|Pv-ZCfIsF988?9;QqG!cp)@@Up!=iq3uu2{iYcRxE7@hL{q>;d{MKa=J~ zyUxWJW9ZdSVX@)!37_fp%XU&aiMow;0*24)q@l33r=U4STgYmcQ<(GMeFpDpc(=-I zi_G#;;1nH&!Xx2yT0RsEzDJuJ^C%0tI2N_hZi1S%RiBKR0uI|bFcU)*#z|hJPOC;#p8?knTxC-M04CXqocvA)WX+R{8g{wz< zOuwivN3bx$GOBmqdrDn+UQs&4iAVp^Aqlj&Djhv$y-);tkMYCfj8D+wuJFg@hj1dQk`=43)|GGR0w7`>HfVI-~% zr$xlIW7B5C1uBp>Q(Q0n1QRX-W7F=%?}W6w@EcB>jz;l`TqY-$9FYGFWP`g|R(S_> zV*tt65f+YjMOno54q$oiMMeEu#ycYnbr{W1K1MUnJF`f8=$!wnojt=kp}0pyfmIs9o4#2YDcfgCYpvqDY^oCP&Q zx;dRWr33fEjfNQ5Pw1M6qZNOOHyfS&e}nT#bSKAoBv9oz5B~$s6W~(v z|Bf@;ziu+RPd|&Xh^YwD*t0GJ5j8no@LQ-Kp?GyzzT)2sayg>y)}>JPon|ynQs;2g zE?q|+eR`Q0ou^DDADCfyVr*Z~TC{E3GUuSak<`GlP13STsqkdaNc&*%=15!URm+@+ z9n=@c21*?;H?*h*FXP;x+B&|A9-ohJ90#5=@x>=CCPPpi6s#wq{Ho*XX;oBt)C&bh z9rr7D;2!1VD@jj+&6jGBvNPE73EdYKh zy>MJeT9%juA|=DfWK@#3E*!3CsScmtcf5M^C)C8lR!LK)CpWj7@r8Rv=7I3k!`&y= zlR*qCF?C|Tw!q1D2AC1fJ}f@$X#+s4%UMhv5uq@?g5}( z@*Oxntc_{Km5&hHq6#8j(YrZel~(=Z8ue>1>c~d4C7=z))aO}jmsf>3*c*TooVYX% zRaYJourPY&Nsiqpq~O3E$E!CInP(Vcf>&2$9te~Mb4vDz#rFa;VhZA@LLcVJzX6vZ zIywb8^1|AyIcO+ca|*N6 zr648SDpwvB3I?lzOIpO{o>MmE{IZjpl^qc;JGeA(Nn$LURgs9HUJ?eY9aCcPg=mJy zHmoApUcv(hPKA(bul_Xb8^FOueNCiV7R(`1m3#{6%{;&U4|YoU{Eoo{ki(UQDajz@ zQgE{5+MoTo_~6UPSeFQ16W7zBi!BD;=&&in6iXgJW#Ak43LsPW0yJ@skm_DV;YSeWtfdNT z5r%4!MGwf9o|^2{?|z&!OPU#n(-PoVt9S~VMF$aG=WD7(qHrICq1d&8 z9fD`8OGO0g+V-AVS1+o|c#PLoX2yxdk2lrzCgNg(Swm9Y0Ssd0=pACQ1Ztq2rl**4 zG(jx>7pDwjO6i4KzYtJNb9doF7u@SkVEN@0mtKbGur|b5-ko|IdfakgVt6ub@>AOT zl*X01wq~lwPDO!}j2AeH^CP^!Ol#S56sx%tkzc>O20eQPaJ4A&1R7D-4PkLTB(&i< z_`6k9(XWc+D!MZwDUDJzqb8V-b`f?7<P|JLERZX%e?O8YN`AG3?7?*E~1QB$~t!m|)oPR$V?iBfIF zgqL#kUa{ECU!0M}=dqdyi9xLP!=orXpb6Ma0+xm_ChL8Kd9>F$FWRWLd6f70Mrt1k z>3?D%SnOCval~JS=fg7=rJz+li|A4*v2HhHyp?kUqEulU|1GCdu3B?2EwalI=oe8y zY0QocQyQmYMb=mlxkzceGXkgCIgwZA_D`;SLJCtn|7O zPe<%CEB0oJ)u>CYh`xwWh3oJO%uk=TFlX)nVoX_}G)5#buvv9qMNw>XU2C9*UOb9n zZ}pA~DRsZ_(H#+sck>r;^(!O?h|h=d7sUKXJwbf_B#kH>rQlMe*sfM-yiI(h5a>tl zB^o?WfWU33#BE_kcSWwHx8C$~vC;_9y9#rO)sQ7`qh)Vefh`nx!3wOSz~ffn6$+GC zfhQ2Ci((2a!(JW8u%HxS@;gu(Z;vKhnI57{c|5YfI$hX!k628+t~A~!7XKaiDvh%v z(?O_6C#7+oSds#?Gp!rNHE9%_ zYGR|&NQA!KqD}=Yu8d7@N~I=bS^gB|K?2al?}?25e*azJJsuu5jeGI56H<>0a4AWu#m#_0BMEuDSQawX1tb! zIFbu6b#Wm?s8H*b#;b{N;OT>yu{2p#-G^aDsQXtFxKAnk7{Z)dybg>TRk#`PsxS$^ zOc;mX!tATX+{(i2OjQ`lBM0D@#|%(~-aO_CGe#A<t&|ulfLJ^xh>0}M>%5GAVsuNf_6$CrF22c$qpQ%p3YOiup|eFY}n`h z9b&hx4BTT$*hO}o#Pdst$!92fW@J3Qg%rJQB#YiIqo0nrY(*@2`xH^jP~C0NlGt2} z@(C2U(+V7Z3xNqWLFySt-AyQ9C2XUFAy!~51+K9IuTj97z1&YBP&Wg`INgamRpB={ zROr9jGli_Aoy8f$lW_J3WuIBptuE;|xY}vMoKp72MXf_qvCkW>PQo76X1y#2oHj9^ z2|EEH)A0GX;wc7eeEzFZjVhEO7`fW#e}-0AcGilnH!z~^7JjB5D~tmX3) z4pG40N9Dpk{{cM3l3Jd&mA`M}?`tW&ug_1umtsi`k6VfNXbRx*xDD|*v1AQ@e}u{q zd9Ulparx*(9GB^ograBOAaGCf?7cadW&FJn@sR;Oe;H55jFveg0A^3-Y|l^WVYCerv_)JnlBcF`?{1r-Pqi&90{GpYo&| zk%UzkP>WKycpNW2gQtb)eNlZJHlM6~{xA|FNj|@9Js+iK8~uJ9_F%#oRO0iurzp4V z^G6^e#geW7gi47tJw2Q>uV5{~g$S)oXJy!T6tLn`t`V z0GFHu3SR&Wl>JZA3xn|qAxclKKtYdEs5 zno7Ch*=J|vnk#eAfJ3t73sKf~S_2Fpgm+?Y*Sjo1FX>;seZIdhyxAARkt*)LA>6$P)pF0N zM!EoIKke_Uiw@ym$A5iJmQO7H1cVH*eK3<9lEn4N+TdM-TFvVrF`Oi?(BxBE+fuFV za7k?yJ6w1)qwrL#xvh~PElV!m6FrWrMnXzuA`Yyyn7yHBkxt${;)5>$qPRAwOYaw8 z9Ribc?jdpQxNq_N0fBM#_zC`6payrr?K^i*fjaK90yVc5fpMSXC-_Byy6CF{DZ6Uk zbew%W*>>KP0_9Y`f@uQ zXnXK2>c$B$mBWc+CWM{k#BrZFN_Q;+EjdqmG&5#B#l-*O{xQ>&>8hX{S((fYlFDS< zAjXc?kk$_#C3e5{Z%9q15GwJs4lV*R)a}A{TZZ__W3fN ze#cqEIq!B{pE%hOod}atFNnDS+=^%;etNTwcz6N?$zZkJt`5zghkUdNKONie(M6_z z!3;Z{$dPBdb6^hwmk^lk@0ZJk&H9CLiYQ@ogZho8s28oMXPTluMihk9LrpQA0f{!Y z=U7qZE{bP>S;0h#wf}O)jcIm0jP@q(h=fwN35x*zyDva2ezn)j4_JI$vKqDnRzlZn zh1p@OWAB8#fngXGjKz^FNG6#g)`NTr5jl2L7C(GE#m=1$sACgbmm9sCBiz0|L3{iT&u2{d|1_NyND@KC&;J*O@DzG=9pvH9tbV4v%^(z7<*Zd-4H~0Oo(8fvt zr}XK}l;PQZ)b483CiBiN`3NwOw8Kt^i*QlDsSFfouE1 zTED(nrHMYE=NcV{H`DVlssfAxQ#pvp`>{_AwQ@d2DkDv9z+@1llk!t@O#ll zqF|Fl+IVtYGCV_?P)Uf;oc{C6fDe!V2QBcLCo5of-LL4R*lRhZ*}&)d;{eTS!Hkz#gbthgU^D~`?w&y-HoB#?G@7i7Cwd;+;}W?cC`S$wKezwC%%oWK@d0`4D+ z2x9s4F4(7*<*+)LyZ&MCDp(A^zYx0tn_Pjkg|aGPqu2~Y5J=9+@()EXMOsK=`Mq64 zpa0N{rrwx{+Du*WC4sneX3WCL=U;~`(aTY?ElPsNoyfrsiceMPmw#m#&{M~N{4H}z z{XbAqO*s57Joxou^``egO0)r2L`3iR`5z)svn1`N{-&TiWiuXn5G7ZlWOSrb<%;Ek zi0^^gcmB&{#FLoE0RvOs$iXzmH-YKyr+PGDI7QGNQCJKBh-WCm7yu(4Ko{-Bs!yp( z0PcCf%{)k7boxv5xVZE+{QCS~ya0@nfsNjk8dD(_Kg{EQMZ8!H!GudfjL4*A?l!zO zPa-|ohFEK`D;!A{PhFM-SCOCPbli^E*lP)-&Drv7Krlt?rFQ#ZDIwS+0FOq%Tkwwt zs^fub9d=J0%Y-*yq{g^k#UlpxtsLZCoMhdN@utszEwCZ&{#JUD#$H5dz@BY$6X8j1UMY_coyVj#0X^mc(tgqVjT=01^w%?eKLLwLiXEYP+Rj#{lb5!}WL zsERH+04Cie$R{qy4bM~?E?=7K@BNpiSTgsFwi7@ei~bLh4WFufX&0wOC%}O`#jwOp z0MyY#u^J&qY)z2q4V{Z#jm{_1LK@fo1j~fallo5(B**6o;u+2Ic_eyfEW@bS0VrZ| z6^LuoQ#9!*r|*Ctbg#vi;@)56Mh0qXw2jZB{{v^|7Z?#2-xtG4lUu#|Ca@8lxk4&7 z>EY@`jhSH&SK7AE53$em_g7(+dq+=4f4!d+q~Fn3pgC)m7Q)1VP%8mPgqoJyLF)2KW2TjFrv zi^JUmGY;3cwUJJ}R~%}U9qse)g0}|A)^>VVNM*3YwFIkO9MC; z+6frnfF>3{hPH;-#oU$7sD%4a>u7^=vfI4D*lGpJ(PatT(>*h^&UP{ni7!{q=_z3b zFg64*4SyNS<6}U4_$F`(@3$Z8=*BQYZq^Q)fJ5TQ)g7@KY9e=S9JyLM!RNo3nmP#U z-zV`B%?xMvdQQR16=*!h;^lyap2+&n0t6-E9^@;jz&s00$~_4ICXC`yV(}c%ACN{9 zBp)D+B1mw!CrIC2&mkTEwh7V|ycpI;cv|o}S&;gekdkdkEt^4l!-VuoGf4V#gcB1s z;b}qolt+oh2f@m~X$OL0$sPoN*SZHO@G$}=Zg-jxM>j#l{jrdx{hk*9Hrg_*4tyBp z0~lgCbuXY;Fw+S5{QvnoNEak7X{_a3;-ikxx7i)h17PV;r{S4w(@!Fnd*|OaljPa) zfHs++ah`iybBlu~a^4&f3!oUaJcYLnky0rvQP z1=1Soox-E@Xy6N9B1}q*D(t1VbG6A`h|&*U1Wn!NF9eR!t3gfMr|y?;Y*s-ZT!I9M zzc$>zn$9}^W~XLCEc%td3ugC_wvK&r&rn2|y2Y7878p!5B{NQd^thkij#C;tM7kq; zr@xys>dLKF=XoYxYpQma%puuI*5sacA&6@_#aO%>BRUM8m`)nXovv+WHV&;S(F5Sb@#~Dbkc2!HpCO#Rl zoz=J?cg-&Z7%pXW7Gep!;&4UI5WapV?_E}1ci`7%i{(G8IbkUq%dfKIclMFTaB77gVufPO_Ai3H~^8n7Tw$KvF~3gW$5F#ivDQyQWA zFBL$krmL)>y!-n*`eRnOmlCvbFH+U_V$P={Ra)+g<#cRJ?{^6`dUF^TKV(>%`HL6Q z%-@FYW|=6PH1iit&HSlsP;cx^sC{P>sVZ98ad!T~E`-rVnz@yK8s$$zelu5rovZF6 zD$Yxew&O@3PM1zpCq&%nke%o!vG^Helh}4iIl^`GWuJ51d^*mvHd?wl&VBbgfL=3$ zIKx7!`h2dc_ptPH@a0IZtCM=3WC!jcT^(z{r=PaR_IxaQdBXwnJyg%?qjxBc_s)fs z+o@08gl>YZ4Fj1pCi2UptL-$Q|KAX!37zR-Do_LNBemFtb6BR9O2d8OL7S*hiTvl0rjozXtIaG(*_R)o_xBdVexh^jikT`vKl#8#AoT#;|_GrKK!4;+or zx+nU9tlpGG7vBnD_I)fdq%O$vrM~whO=`DecEYzo@J^cbS&RtfY|h;ABz4BXHvj|x zj@_@Jp)>F@JZRA%2FO$YTeKHL$B)*b^>5kZ!<0qFOSUZfhn;{kR!@KsxPxQhmjlh} z9-#ra)_vkhkU;bNh)1liCLNN>I90XL2{2Su%u5cH84HX#5I7<}&A(G?9$}IM;YRgMp!mtowT($1=%A#>DdGIF=1Ii~3T}JdU|958^S; z1raH^KK9oG&AHc6Ejg%#Yn`4WfP~f`G~uqci<@wrakwwo3BXM(sRST4u@rKN1((NX z+kOvGjS|hagQ$`N@cT3?DKabBU{*51hD9^(KmTPDc#s{98F%%a){OheqiC->2{SGk zcDM407x&vkjxaYv8lQ2y&O|0A+)a7;j5~$iaHQqIMj+Z`!?^{~`kigT@`tDa!sEb~ zxMe5h@})k3VD#E>w*T?_@p2VLUlMv#`w@xQhdW@83g*6xmt(?cJYkH%5f}GO7N}wq zRGtlLSaVQ6XAy#)y`MLMy4(WQvI$g29tEw%m)f4d3;;$B0+ViGRAqu$-VBWX7`4R0 zK^6zUc97s7BfgMu1PFY66P&>ia5Po~ioFBGh_uTBw zHW)r+w`;fyl;MKWX%`ByGZ^n;@m`RDG=#};aD$G33k2?gi4BUvSl^^BqV^J!#kKQ# zXgKcg+8oY4IcEql%zxrl2!#H>7(`hE+%Z(Ox0@er+GFq2w zu<=jo=%h{1a-n=cACR?H-Y` z4w}t$1Q|n?t}@0AC>!g3Ko;99Y2SZK*Qi@JFyw#{FD(Ghro(s!Jmm9XGGr+j7GiN9 zU?0#HJMn2JH)Wz-0>xkV2%?FS>}(M1M0Zx>n3gIWod$jtKoqWZEky%Jxx!gqubjSX zS<nD9WJ&tO@KN1gva>ftz?wLIG2K~`YJ~z1ZP1TUhI4V(~F7PgbrDdy5W;@)r3{41= zoO#K;SaN_z;yfZwAd~8G{R+y&?elcf5(epWjuy(emx$llKNGtf^HX2}Gw`f*@=HhUXr8Fev^_8em3n=gtn9Elvi&Ms^;+ z9}%Iy^$`b{eJ;SU2$Ge-@LXy`1R%XV=wJ6fP(Cpf=Q02m-$6SNyO;?JZztIK5R(VV z;7L-l7FCu|l|aCms^CrWXK7^`=@Gzg){2jM+LgY#&yo;|-^q&%r`laW6*dkG z%=TDw0k_3=w%8T=k@Xzp6X$|l9tSzv&MV_`MCy`~1-zTj`PP+rXE^OP$G=!$ol80Q z?om2DfD`KOaRlD*ocPQ_x7<+(#Bi<;@mMr$p=3V1wSM#tH|bmm7PcK_HrQqOmOIK+ z@(k5HKl?16@9%a##eWtwgxXz-DpcVLI4$6jjz{Dw6#oy3qY&M(PBqfmW2$DnU0ik! zY*10eIj|8A+~G^Wc*z$pT(Wz!k{_BS*V982Ubt|9`cEw?ppNCpDSf~%mvs(Y$}7yF z3QY%Az)&s>sy{Hc<4o z2eb!i&;)zpem2keI6&qehJr>73m}(MI0}a~!5my05&Qux(M6B3Y!?~X9xw>zju+_#qU zFy1EM4Yhtp@tW{e532PG1kSDXAsZC3mYZ4k@~m(FA?tWMD-)hXBCmBR6>+-trFN}H z@P>0zAhRQKx8i@8UZS@#;kC)c#_sDuL+06yOq{xd4SZ9AuJjD_tN@btqh^!I4bL&m zy__7(^AcrudK5g2EzCV0pj^9gF(!$IT}YTs>54xA4@cyB=6Q!tNy2zQqZ`DDzNmU5 z&^HCCA&O1KsW4i zUxi0(B);)B9pwOD1$e+{fe%VPFl0DvO(Czj_eCTH%Z^s67%9S9c+2dTqG{PifcDnErO#@EhVS?in9>D|O zL*YG4BI-&&xIoX8+2zqCV|mGeY0IhGWX=N-Qjf4 zop=vviLLpE&G0q8+d~aM!SH~)Kb>-!=dEFfAL#hjuu#L{vTh}@QQ`D0q20I>XiLL4 zp~|`zx%ie#eG0rsgL4UcRfWq2euqMC%-2> zrV4ae3Cj;BG_P7e^rV>u^Pru8)-_$$gE^|VnR5+tq7^$8qN-;;NCTp+qYzhPN7}_r z{kGJCi<3O~yj>3@##K)KV$-WL$PIe^k4diwfwlP1>l8?L2LT&jNn!2*RLR|yw{txH z-w73V38x-(IzTTF%ZnO_SdrT}v1Z_*rrv>H{j(=*Vr_$s-6YlnSXeb9*1J{~`1{%k z=MW1mJKvYcQmQlbrLW^q3TzntE?bC+XkZo?APNf#O|PHquxgRkgBTcEJ9IZ}S-yd7 zkO>@|2dP4-nWBjN~Xi(zo6E%41hYu<;CFYTSV*1X0Vo&E;E6{s`MngBoC zVgZCEd^R@2Y|Cmp(yWD1SGK9ZqBbXMKyNq|W>?P*!4l2ey=}XV5v%=(RyU#auX3`o zqrD3k7}w$=Av{byG@J>WiACsknD`|zYbl1Cp!l6J zuOk?{(`40-HXz?XCod-)Q9!4j0CzJ7*Bnk2l59A!?qKxFLbS*7$BDPE%`b=03p_uHu6L@PKCz)4<(6+u8 z%e)}=|6CRN6-NytCg?71(DS@WS=n&Y8jRE3z6|(cHTk?WlT>ttNtoe|IL{_%u-JF3 zyt&zcB%Z~p18YD&-89`1igR|jAC$U~2`%$c8TYZO$Fhnprh>_*WoAX)@3i5A`>6oD zCmEs)&wDm~u?~aPZ(tf(f3#lx@Q7hUX<%P7JP?nMynqh7)>U{1IpDt#hNcfc6B|T` z1!34ufipK7gDP@YBXO*q2%8(M^5$2?4$@6InmY-AkY$R^>;MPwqbb&ekHm;wo`BQG zCFtIh6kN1!E)b_(e@nIDtrQs?0*cOw`C*}*x zHRgJ<-^WpmRNIhoCEfR;4Sahs>5p*6+=0~&`&4(W!4*rxu;ug>hV3VdA>!DMYTP$n z?YaUr#x}-lY&2+yk(b~?Q#UtYxtFQblZWrpQcj2D2`tsiS=+? z2>sFpIvwn9+2i6;h|im0wk4O|i?|8DJvM?8$oQaaKm~P9jJFavkPSX7(`RfO_7|urysigOS4=45 zRidFuP3OFKAC=Y-_*}ZWW3Ykm`^_5)1umSv8|Qza^0lWLJJBuyjOG;)cL8QBY#Z>_ z95Q{osIp4AfxJW=@!G1kp}bik+L(wmr(NlJ`+WDL9fsHjpQBTSywSGU7R6*CVGOas zz~>gw>{Ef8a>8ovLGmzEgCD^&_PLtiPG`^H9oSP^Q4`#&zOnsB>~O8B3GO@lMfo#e zgPP!hxnr+R{zY68{2m5cy~Q+$?Qzek!56f_*DHrAwAqFlT*-uYP^+t+f3cxH`)BdN zAm)ewTeO1ANE273Z^1W1(l@}oJp`T67FWAh;JZW%-$fo@zp212(%$~c+YY_+zo}?F zQYKQ0NGV$G_rzwq-sUBKe*p2xMcKJyh766u8}#mLl&ROCOmHPK!cekTUx|#0{}beM zh{?g7Ka0t^2gUZmhM&duxh?V43bSZpK)w4KP+?^*Y;oE+vfaLeNl*XqMpTo1Hh>R| z-~({tU~vn7p<*p3&1$RzZR838tl~Dyo+T|wM^f5!QKa6|%4 zurVavL+1nb6u=JBmy3>~yU3Ccwc4Rq{e${$+)B6;VZqm1zx;jZjul+ALfG)0qAsGo z(Uqy_f{D+C*`ihG1}6M%6c*%j44e8axFWrZ?MUCssU6bVb~CBn?j1Br8*)9A5D6Uz zN;T+(tBFj9VW~HJfYP9gKD(0lfZ{*EQ|uln&6K#7(nG0YJ$J;!9XLRfyM%jfP*!`(=-|a>~uh#rpW5VN7RWc z^q;4oL&m0!Rf9{-K@p%)0sko`JV#ZVJrn3zAE1%(Z>Vy7Zvm8+S@Z=O8z0N+xSdVo z<7%_VCJ?Pt13){{F-Uy&8Qo!h=2a?xNDV6Z4hE%(l&0m9o}jOKi;8?X578GDUB|~q zn*dvUO+a0=LcJCH48RI`f26z$&-*szZENMlfLMG@m<88@aaVy15C-lS$AN3#7{fmo z1Y<)Z@hm(OK<418Fq@9?Fk@ecZ4db-CPmuoM`=ogAXF!=f}uPn>U|JF(}_yC_hJr) zMPoOt{g(hN;*v>06X*$ zp;=M^oF#m-R(~Q)(!+>$464&+>eK#CID7&a`qe;|co6nPxO{^D;^F{&oxTC`V2dpe zE;hOA?0<=jN1!@H+Ou2*f{Yvi|A`UIS?e$*SR?-+rHp+O`9UMR+q8l!fjRD1zW_xa zjK*c50jJ40VOrFigei_eDu6KisOjBo5--fhpssm_w-WN=Q~k;{pz>vCJVM*`n^TZn z_$-$m2U$>oUlJTiNOYvbGao(u5xi{a+BElp@qF_Y-#7liQe=?23aMgoGI|6#*4a6F z+d1k^fHQ*G$4P@`JA>lj-_YB-1nisob=Z$qzph1INL;f|vA%2S)?X)@l;>mG>|e%& zmqwh^3mD=T?1cM?sHs!XDn0{(wlu^qd5I5kU+M%(Xx<4s|AUn5sqW54x?e)wYlXUgNxo52SWEGSpmfMn~?~@C;^ld~V{~ zm~l<%yLf~xeeLh1lM8K9(>aIu`5fG(pQ|&!gqaE4U5g7pF^DlY(g5D2uYnRs2S=!P zwxf3xe@ozo=~7k}?VlEs4Ef)(vx+o_PXdlwsOh8BD43fJ#1QSvapOw80Chfz<=7!yYo`(b3UyBdcpdvOg z4}F-v1vinJ3J-*vEB8?59t=BOMgO5ihotN;FvuZvzQLvXy7mn5+(x>zbWy$|@=%yf ztA8J$9Od*wqHGM2j8o?lF!nC8r?|h*hXgb{`Rgo_AidTRq4ZjwUSpiO7juJ(qU>0zCc~6m6DCR=rHZ`q;JBvux`K% zGh;AF=e`?7A-%Cd@g*Wreyctc+o%9K3Mu%OyYMl^^AA<{&hp9s6<)nyisW0iCR4B;l{ z7t1#1V-bcwoByGMG<^Y@-%*6G8H~i74>IM2S$9xM1~d8yXKft5%vUG5zJiXYPR!9) zk0#==-c$%D$A9~ni<_b$2o%OdUr&=R4GqPr_$G~$c!SSK)&jG?iW z(hSe*c7i!HPA;~G#tJ(DpTh+fIgoM?VEUtX$N6g~zR{@H6F#Ui1+2CF#-_z+BNmRl zLhzSt@|Vo{>kec>y|s2awHa-rHdABuoulFnEa?Ve#3mARs6)-3IE|jDi8F_JtIma( z<5Ng_Juiot;|3HpnWF-cC=Wj=*t-FA08)rKUZ?mAFh?zJ(SWqWH!JXMU&^Dpci%%C zkV_okjmtdF0#~9zW;gR+(oDR#iwY|&^SfHY@cGWRoj3e?l!`Ko;*;;<4np(pRJsp6{syBM+if zn^iIMl+d~h@b;VV?uwV>fX2sz+W+C~P2i&{vWD*@orbV9-5`yTMI!_aMic~;Oo()o zPSOntL;+V+R3@Uhuq1#2Be6kpx%SAojLSIVIxeF#?rbh3fFywIA|Ni{dSg@&l>jRJ z{ZCcj&V}K5zW06oN&42Q{nV*br%s(ZuUbPe(*L8|DK zWH9ELty6q&w~O{H)1Z$Wpo1Dzp9HCLmL`KSPxdbMUHdwy?vCMGclVq(6F8FY-mB=x zGhAZh{#nV)s;rxn!I)>JPI0*d^ri+CJ3t3CXn+HB?nkQVEC*A&yQ7Y zqaC1YG$`NzJ*Gi@9iUwr)HMlG4QQ7P#yl%X(KyUQ`7!@bl3LMbHOdf0&@x!5GC}dD zq08FXGGBzqS0sZmPrFZ4GhcFm!W#6512kWQ?skAyYS1(XXrBg+cYw~8!)@M;cYrR} z1OEpHXrxYcrUNuhgE~7v&udVs1GGVdez3bvm)m}(YTWGrovA?$4v^Bb$Ng_QKvQ(8 zryQVXHRxUkXuSrB<|)BFJQ;gbjW;GiYQU~Y24kL9Iz@>CG(dv}IzRypI^6-9qd^@U zpye9$>uYucRBhiSgE5aqipE~;XjIIfy_X+F9@o9J`9GFuMPF&?N|Nj+mLjp9jXLwFWM)NQfn+e|`A(j0h3Q94-d>HrmMP-_QhmInQ7*Gg?qXwY5l~m{IijFVqa2_sHE4(f^sol? zae%gKP!|WNQlEIi~iB9pn1N5^7J?H@S z{|;QeuegO@{Do*-wfmO?S4cL3t4k#oy-G5(sxgub#ysv@9S+be4O;C0&DEe+9iV?}&_5iY<$xNur%A{B2PImONaq(E z-FB;3&mNum+GJ+c?TeGanCGZYG1LLd|3S6>YzJtf2A$#nRcTNw2k2iK^po8XFtJI4 z_BcT4`&9889H2HDwA=wI)}ZGcpzAg00SD*_4XSp4KGC3C9iY!O=t>9Zl>;oVp9A#1 z2L1kAOJDbD(6l`5ij>H_zHwkrFpq^^zdw87Hwy^|!`Opf!9a zPm%&e`TeFHAqtg#qD`@1igEN+bXd-JI(azp-By;re(eQxYRm2C-@3CIU1~|2u2I)Ib6ZI^&Rz=87{ZX+A3bOzm$aX z)W~FCV=nQ{#oa||jOR)_8dUwUc@^*SM7DT{C&E)l?5El(d%LjGB^+noHZ5m+*Rl zacNtXAo1ctiGFb*TJX0kXi80qujbN@Yf8GOt|>V!HB@s$mb|=RpgmWw7>HM6{qjQC zyo3XRPS#%^j}iA5 zam0Mon#K3h{QmfO!x{ORrK6#o$wQR`qXnPHH_xAo zjmdgz?jorgdyQM;al?HoaZRmEcNc!;WOkEvh#RG%8O*`sv7#Biv(OuIAm!PwtO9me z;k%@8F)7l9M0TSCqmL!zoUmE&On|0;-&oE{HlP;ciU(>TqM7sE6QxG?8AGwWb(tkT zb#X&=skb8U22xG7e(Ix19CdDua6vKBY~WbKTEjSFooAE!5`xi!k0A%t`-`R79O0Cj zd#ciTVVQ&_kh;DycaPvDcVk)XU8$zjbr}3ewlZ@gKA$4yLChyA|1kgis`JD7JvI|l z*_V$^@{!HQM)~L#HpNZO9WPT<+`s;*1aD~UMmf!eiJ2tQ9W!YXo^i^YGiYA+TzVp> zI{Ed}TSuzvRcou)sGt1WGH>yZOfRO=&o!85j_hQP=Iv?Y5;cp86SJr|F^h^bYA$JG zj+R+;iJC>liCI)^&!VxH(u|s7U(F>Q*KomWO|i_PTh%NoPZwdLW7t@&!`TU zy1q^r3VP=oiu&JBLu!uVP~$_>?KwvbK^Sv2k6u=`-7;!3GXTz1R|OkzBrR`X7hH6q zu=XMQ6!bZukYP^ppy2AOk`LS@){&$yN&8uA_^XE#67#S*NPe~HWzgKA2;TbBnR3*# zxhPiR4b==@I6A$i9DcePYn57-V{gYmI_Hdh8R5u;>Oy}$A2sFf0b3d9a}oR)=+>rZ5MM_4WUk{2tilL)Tj)NM zuV78EM*{5^vx0KM)xbS-Ec&=Q67zVElEMgo<%G)#k0(4n?1J!ulf%5j)N$B;udj`_W81Jilf|Q~W-!y> z`7Cn_LKN%Bm5npu?KUrNk)h;lC$q(loOg~FabP9~nqkxZPM^eqS<(1~?o5P^gPb3` zy?iL|c(uH5l*XZHMYDhp$zf@?tpnC_;mf-B4ho2Q9>{}@xW8tBvR*w$xb>IfvjeLh zPb@sxTHH@++1b>YSEL5idONzj9SiAyVOH2E?6-{VG3R|(X7JBv-FBfE!voK>Ch*Be zmUR*(N=mD(e8Bn*-e%|BoJYZ>ytE;m3|Qayh1KTuJ}B0e+zk$hm?EdIhxg+Az+7F` zn(yyFjq~Oq<&tm^39ByF7in&}Ru+;5wqW-oS5kK8zbDFG27*$ovP3*~xR2QpjA)8A zFd4Dcj-cp2Q#3~GWcALQO*%Nu(|{URki{(Q{sN%6-ueHQew)*L>K^eE1fmV_)%8YU z_tL!UGb%mS(Cfq^XFvDfo7!1-shSRznLl%!I_F$D#6uk65iKz_0Re;MR4~VS=saai zH73+%7Ispe34_7L{CLD0Ix6>ecnHtG_TfYikSPA1BSahSGiWxWs~r%niHKJO?SQC{ zveQ#fuAM}Uux>6r@Al3g%ygtrJFp)4zwOf`x{>VDe|XXk@kICO1$h67`?LyS3{tZD zvzP)ncIo|)*=^U!I+w}a}FYooY$=;NL#aCt^VKy zHI6=Q@B2UXX&+O<(Wkf1|F1rs?&#AmXC(UcLD`A>^o+ozPm`$em_9|K8*s1Hdlduh zo!18S3W0wRfW97jR+_rA@hk|H%j;PfaEM`B%zxHPY7%U+DaE#eC{!X9hA}?}SENfO z2#T!%<}`An{P|>ZPRQm}3w29m1mj8dRC%iMraUIzU^YbZH+iG2DNUsa)l5h)w>)z8 z4NCA`j0-v@>rV7C6g%aS#Mm}1g7~U3#GVCSf^latJE{HJp)zuqPF-lHZe$$jot(!t z+nA*EOuO`_bo!I*^g8JWElDf8$jsurS10_orFXlf6wmGdQO(wVt4<(}m6Q+vYI(zyLlK2!U-s}l6X+hX`9;yfN(Bz|%nK0{L#Pr$}muHtlf&_;<@ z28{QsYycw_$$zg3foqnJHvR&S(Kb{h%CTG8bd!kq*AA38Ug<6LRbEaalDDEu(rNBL z+juZNw`W7c$`a`!u|x{T*G61B!mbg%NUzP2UJc=Ve5QKR$vIs(Y_7)2+jf4K)n@2R zJp(N-{w0`|dLr8T7M9JJjP)*`)SYqlEFM70`3EE3qJzS%c;epQ?SYn=y|0(dg3>+( z8?ha8%xrmbUCr!&2wY~tAE`2u|9hoZkLnNiCkjc$4I|(<^SbKXWK1r zN{nEMa#R zy9nP8qj8mk8JeqJ4Y_Rm)mRVJY+|!be3bAd3(ASd`e^R4W4*5be~tCI_qB|*i>9ct z{#>|{xW>Z>j+H4n)~^X%#`<=ubc}VHT}X1QFJ`Qp&Zb|R^i0mO+pE|1DVNItiI&D| zM?e`bLrUyhzoV7jdEddyg67Y%)0p>zjCQQ=HX<6anjn$dRyM*%9J7A`p;FfNl(_tht;Uy#~cA{!xut3NCC;g=bH{WDw+zeV% zqHz;(9lL7(Rp5e~t5^%c17ypp4a=bgdOM{yO+f&0OwDHhBI~Jlet&|E9q3UL z0mi>_lIeN(RNjDR40%KB+}>pWS0*&-e;%mm83q6e@MM12Z1V{5X6w0I#8%H;Lp(bf z&u=h(+(}$p#E&rjh6HYf*QUD90}N7A-G?QaSvFqm*S;UcNXH(_mTd+1?fUVO0N&$f z1$a%s-kGD_5(W|Tiw!l`Ue}$9F`sqMMJ;=lROpry=8cX-?5Xgy#lptqP91EE4;> z>?}b-*zB+5@u%oPQXe{(fOpBQJxgOxOETB@u`;egr*kE0mskag=^UERFT&p9k80X! z#bYRA)+t)?IHJ{@5pzd~$^;KU1N(OTlMAS3v0TOep0*h+@7vv6d^+tl}{qKazT7R5$37uBSTA*vFlyTJC;Hyes;`E}I(Jhmal*Y%g)H5s9$+B? zWi7ki3}>0{jp*K#=BTRrI99h2{ZPn!TPd5EdVX{y+!-Bi4vB}11XMWSlUj{5*d|tt zFOzB{haUlD^k^P_hmNP1+qJ%Eq+iwrcN23G@pMf}TA*fPt3b{3QxLgL|DI11`i0$m zpkIiMJq=~TRE(WaCS11Aa}!@R;VXFSJi|I0kNBWg?&Z#*LnO6MQ6TeO>H~U%g5GJl zG!#9UK>JWcZ0w!Z_a8`h^IZ+iO+a^O=!MK5(!NJ4ByC+Ht%jaU+hb#IwO#~@`okB5 zPx!lvua4M=F))VPy0RE{jP|8R3*BkN*68T3 z6?2V_xmL%FS1}V*jJ#Hb7ISpDoCRWpKEA>u=-I% z?25J?By@8E`a~kFhJFYNW0%}&Ed&a+ETLf2Uw3Mfu)0uhlCWMN zHc41RC@)D^LkT1aOYA?1(S+4o#UuzTL&s>sYNuk3C#;Rf5>|gjSpCrhhG|rVG3~_U zl_aHOs0cbc%B8Xd)g_p6*mZmrrrRP_&6xiGhlF(JMR2V1lrgM8)o0 zFJ#-6rOXxL5W<3{u5P?;_AxZ2S=dT$u|fcKd)g^6fyK-`>@D8O0nwd4X3QpWxl*^6 zD?Y4?iIT2q%uJS~eXC?Tk9*K7?n1Aa0+FCs{G%Vlh#`IvcOgCsUyoMQ|0FvYHS-7gXF7XSdd#GMc0W@;}*;q#q_l#r@{|MEYpKP#`?{cfXg+u{o~10(oQ1 zdskG#<_6NNu;5d2T@<0{W~C1$0EjnYcfi1jYT2C%+B%Nt9#V zajJAdya>kqZS6`#u#EY)LA@$U_VI&>KLDrEQsL5++8fVWD>KdLJ!S~WQr-WQ)aEvk zSbA?SpyX%fseP$@2?1C|EM7eJUF2;_=kHq~oVx~^+;S2VK;K`B z-j~N2$5X-58T=P)wt~5v>yEgD*iUn9uJNZ+>D(imXS?Sf8ThBRH0q~6u)r?-Anbj2 zWq4Ui*D0AW0$G~tXnBM5-EeOqNo8yFaZk__IO!wu16=^Nw!;7c-K{~*Jpr9F1jL!{ zX@IQZcZ!&|9nDf{{tt6HmgZ%zs%jT>ZI8I#3+Jzyy)Xa6Ic4GNR{{x}?N@P^r1wC| zzJ6s>`x7NSg*GjcHeJ6mk^Crnh{{e)ZHSmb1U^;Ps`m;ApG>&210S6v!o9*xzYx4X zI712E5rFmX9j6GdPD!f@v6Fj^vKR%EWk-<#8=Jm_2iW0g?NP>KI=8~y3nXdG@B4>6 zEdM!)VF4$Xu%40U2Ad9LmMkA`&yve*@Y0`U)*0@4l=1vD@MFani?ro_NkB1AUn$7+ z|5ZZxKeaPTc{e4?%do*@22AJmW40I81HAv9xF_akYHo2m8t^r$>>qK)+^Pt~5GNTpI z>?XD0{x=JS;l7Q(l^x{%X`fO#z8*>(g{M$N)g&o0kI+*9IjrR#vry0T{}OC@JbZ`E zi@32o%tvE8+@Y=%elwXVFqKVe(*-o4C+WUI=&>qwo?RjUwdDEeb`l52lGsb%Dt*=q zk~=&aQ-B_KP^Wb}>?`Vntr-dj$lyX}{jQxTJM6(Q3zmcL7d_vSZD%gn7a zJOKcP`+WY^y9e?YktxNRaSnfmp^u@ID5Ox?*YvdG7tHm-x7VS;vNPNgiPmKX&B%Uh zHRByLQp;kItg_tgRZZl&NOE;T8>>d)X%ZOj4P>(dXuH6n+uBDR^kahbBkupVP3=NI z022KDA2ygG-z7VTOE1z@==B5i;drDQOZHNZ81b=n9iJroMkgCjh%xI$|1hR{p; zOYGvLmPbqMS_a!-vhS4arn`#bP0t7d^tXXPRgW?>d)cHI39zaZB~9R2Zq9pNB(kY} z$mn}MaMD!vht;0NH_6YylgRYbX~R+GK_nN$7`91FV3}7aa=A_VJ!{eXrvE%izqPU# zc}^qwP-$}9|1eUiUKy|<0@P?^05{y$AW7|=|2Ig-YJIta%~r=R>O?JzCcj4#D(Zs# z2eL*HsrmREsV{7%EMr}hq6&zyCU#bs`}YOXbm~F zg{Mee*kjWq3ZE)fnf~kLC+`2UI?-n3ck2?>49|0PpCkdDq|Q!489z!4{?BcY3{0xj zXNtb1AA_;?|$)nN*j<~6LRgS`ZQ$RB?*ll2B7BQoe(9!s)QZfaLfagw$%3B0N;ILE51PP%F!`l<)&wa-nomEi zr^)7B;$L)uTXl`8K%1fWpH?%y3n1$SCh|l%N+*|k#}b} z`lbS@ojN#uE~>e)mG%1+M>Ruq>r~Sk$RYa?|0+J%|I%bf>()p%H2^;klrdsVN>3+d?4QseyUnqU3i$hNfzS`?MUWUXQYIhC0Qpv9+liYZ_)cff!x5y zGm`LX(<8s!``vXODDb}gV{A&?HK>6AYVPLEz4qr1dW(SfuCvl?RNv+nRJ)%6EW~U2 zm&;;p?zBp8PK*JrGd5bku^5!*^>&l2GTZdL$@&G_t^PXqvjmka?fJ4lRJw`8v?(l& zJDHCriiALa`;K1utT%b=L3M6_TflB>*AA7si}dMg(|sLfA<8|(-BVmONj^BDEXATsm<1|Oj?M>rOuEt8}z zllVA5SI`Gfzb42-Ep^|x!>)oIfVlM>dqo){Dy3Wge(znsC+Tt+^@ikLv|#E|pP;Gt zBx)Lk)=5ZOEYG&y#<9HXmr(woMHDynNz?rszjAVjR4Og#OAD%In>`MvWb$cAR8+H<@Le z4JONMTIQX%73_s4x$lFCPk?=I)6D!0O2J%c*#wDg9yDK|rvE?ugmQ%yx3|lY;;%^- z|NE>&=P3Rbiicr+{U^074AA91L%A%_hh!~|``6gXrIb^Wr7W?*lp;2aRpV*c0W`WS zHX|sfjAgWpqD=}@&cOWJsYEFx5xieuP~Io!_v9o|g|7c~QJ%AI9#em@U6C~&8G}3z zl1E{20_kXAZ##iBaOO}O@m*{%S)R4CbkyT}00S4jK_yF3GRqe>m@HArB5dX^KB~I$ zF-Jax1I?5VA)?RdXXPN%e?b@3?q`rmXwQR=QX*1{SQPHmaktxX($@DcwA*@<4W`h~ zrO*LS2b>&^{cq}Rw zyP)yBK`--Di64Ur+2tus9pTH5vaASsmy5l_tyt3hkrcGyYWd0ES>;`plL9BYvz@ef zXA}N&M!-v5xHk=(Fwa7o63noEQ{rMF=loIxtGigrF(g@!eEC#4u&}(+ z*OZ2LE&AUXXxu-&DuF0*D{*>s9b8Io;n!E%V2sLR9v_Jo; zgzfQkQB{dW9xaqsUPSqdU?OIDhB=(F!meSyNPd8_g066;F&u-vFtyRb)QG97)qV4< zV~Z9s$j`H?s!{U1s%n(oV{O++f-EsgkoHG}Fy(DEy`2!ZtU@gygYgnFP*{-7U)TU5 zEfeS!B$MAv8Ls2bITC&y+*eAbn12jE=HUUmz}gRbSF(|3S943B<|+scCZU!B$J!*!ds*J!e4^pLCS<{|MN6dTIh&Z_yKZbLxE7 zYjuYr%rW7O1elr?19q3j-joDk^Y=*p(P@3du?2GHr?JfHfhtpF z8`r1E9j-%78-w|u;Q{J1Tyapsv{TIWOd90>r6~dE8+#nP3Dyt435sytMH9b`%LZT^ z4Xt-y!e4d8#h3{Cm|MnW_yY!Ip7%+mH*M}Z`GlCDB#~&eJ-#-EJq{;{F+EHzANar| z?~G1K(oB#3Qclc$7C$^^nm5ZQj%KfpyQCCR4)41)QHuDl_B=@{fR84Nj(MiC76CffCbVVJ3Ty89LTwy}vvCxu zEsz{JQGUs@I^b>;DFux&kH=7jd~2uDh2-l($iB;tuvRhCRV>ge?Pes|v|7(I#Y;~) z&0u1O*)XWXfqB^hAmY^3-5v3jK5`b7#+SK^Q|nUi$Xe~ZM;Y_=w5!vOYh>{Yh+9Iz zaBx{0wevvb8_Lcauyq-;R1ol?jVOp?IFm4@)+#X#{1{SDO!Kv@iu#m4FkrQ5O&K*A z^5j>1)xvgvSU2MU4}N#zx3vN^{a6FDt!?^pjWiS^f_qfs#rR?WIf7Sh{DAWw>1FaY zf+>I4TKq6WTCiWp%RQEIjp*H4%tFd+Wb5^J=Mn3u6iGvVE@3n1osTj%Ow=L&0< ztj^$)#6S#S+n2_sAx@ks z4EzOVf71qCHlpi^%MKf^rl-QjsY^*fzlDji4h@#YDj=8P!ovL=k18oVCjC<}oeEB8 z`DP+l$yTFSmh!m&OmqQ?XaNn-pf7JqfJ}EIGda4db@Yov`8%gy5PLn&l7nSW3cK=+ z)*=eS9B2b+;7+FdZTX0`Z!NN1x@!&2$6=6bct_DJc!4PV>~0IYb{OslR65Ul@?-e_ zEI)Do47<`q$C%B>U(8JOCwX^BPU7j*5DKt6^@uL);$&el&)pj2wLzvk9Z0fM!Q(n5 zB8Z3(4I+B{AOZIWvfP>l+tsQo-D|YF_j{sy%ZW;M@1H82r-RgM_#c-L`sEvKH0yDr zd&!|=)RN>V^9XC8n%!&+|iMDD@8GjTV8${SP>@`9=JbMWNmXwn&)&MHn)N zrQHdhfpPE=sQH~%3U^)X0?>0j3P>17dnN3dK~u8DM7@TDf^Xb$!ngZ z*oo^Hd1ccLNx49fcKjTRdCpj`27C$W?0MBoKngQY+ECbbxHR;k(lPmgW&mp%XK`WL^2tR>Ju(_gS-^QrPPRZ?>leYi$8bz|%-iUF6#c=HIm%B+YvDF@q1>?@UBWpXOF ztSk1Lg_E;_ibPB0+B{E4N3!TMD@>W9jZY>dTO@Dkb`9t6sBBNuHlQ`Ix+`&dcU5P4 z(T}z)wG*?{6efB`Gcyvsd%^BBcEFtLBPT};mdu0l&1C_jgOHwl(>K^O7}IP?SS~9` zK%Vy0%SlUjY+Aor-a)C%&Qe`5zZG|mLTsSSxM(t+lBwLsuAin|rU&-u^)1~S9FCPR zcITmIP+k0pJ-d}BWJR<77&b>{N*XgXovv$&FC0;XumIIn=-$~&n1TrFeyX%rTw)6u-_mK<^ zQ`f*&akjpn^2g&6RZSshKO4xa;Z+gSy{9Y8C+2?vlIPjknCD^Y;|%x_e#Bzf8(K%~ z{Q{KF#98aFYt(vF%b^}~cDRTKF@FVBM@*i4StVP$XNYV1T%2-uR96$=@*AujK{=v0 z6oz#?A?@YiQMQd6tPxTIbA!~wB#cb~8jbyxgYpU345 z^_@-y?CMhK5xrsH|`ui_J6fob~s@}2iOzWSVND^*31A-E|=8TXMz4P9nDUFZw zN7QQ#q1dpQ)}f1#2kyzPkwyvyM{j`t86|`H7YG~Y$^go^BPgy ze})YLKb=^u2V;?z6>hgGv9+eE?C^6 zV|K{AHcNQ-%t$Uzwg%J?j|giX@zFJj=0s;rPVvs~MPwxZ=cyS%^E+`!?+eCm;pFr^ z*ALA*d*QeGDDPx|zsE$0k&A7_PsxF0oyxM_*8|lVosn zjGH;hoApDI{Dd}`7mjz7A&tZ;SguyVU3wMVaa95#;Pm)q;&pc3R;Pn9crym86=Eb* zrIv^%TC(XSqCB}od}T*55M#`eERg|>R$5O!ianLaS#gGWb!QeykaBYiQq)rN%+FN& zH$_Z5Zm8v{%WOo!;!8PQjhH(TEUVJP<~6=j^J-Qge_!UcIf~aN3w=fAh|ZzdML0me z#Mitl)N4zmZf{m;J5C|pmy(K{GKn#qiHNEg^nu0@;&GNW`1>RZ)%u&jA!2?%!*f5% z%vgJ)Zm-MQ!^&rR?gBsv;c+5g)_Q=vsb{#aBa}C20)MAhhGRn(TV+gLwim;IP~YJU zYlsH)2Y|k3Die>}J+bx(DW2ZIBJy;zk&ekI8Xncc0c({P63|s- ze3&~}U1Htm@-Xo(5qfrIVU)Ow4A5( zhS?Z=TMpSZPwe(31oVrnrgdMl`0iwnW_=R@HoCJ}+BKtkFU+A<{86OTR&_S}*8U`& zUhlfOYkTW#*lE);UUM28$zMIgBZjEydG4v-rliccJ!lT)zCVRwb{I5T$A=Z&w_A*USBI+GcRCJc(kxHybEzdsT)z>YjQ-`m8q;f{)}r}JJK;Q zC&J-a`@zbPX}kn7L|hy2Jqrvt#rrpF%uZgFwTR(fPrBGYb`FZ?eb-vAZ{9|M)11Ig zxKGwH!DX+y{5lcpML*37BX5|ut`1^SjP_=5$mAZcJu)R%5c|aAM0osP zY4Kicz>cTID={I|wCFpY76;M`O^cnaC%#V5Vos74U3u=WzX69+|BDtg614c!eoc!` zB3ywrYmx|$?hzt;);q+F=5#fAtLWKPx!icG85CYF+3P6JJi2pwlEGE0= zhlw>ax!m;2{^^q`^fFPiAMoOU2Vbr@rNUi=!W^F_?ou=VpaA!IaFwh)~4`Db)@4g;{$ zCb(xPFE%RGC=;@?E=aP!veN)>;WHThVt>f!v60UKyPIwZMsM$)GN(9V2FpW6 zd3rFuGFs4s;~w6H5?J-%OeWcM-2J%U|5BK%06A2aThp#Oxw>S(!m&T(V!aRY&P6yw z3|^m&uVRPQnx>Yq$Oz;CnO_-&vGkJ+cWZiOPbkRazuxm|KIDl@H8qi7$GPrMv9#(u-=6KpIFhmEowh`>hCdY+)2s+G3$m6?mW1vRlF{L{nP{b>%H?aTTRLH_rR{wJFk=aK3%@&n|!mr z93fW+vp$ilKL6LLH072}dH!qKvw7kroI>IQj@4Eb5tB={Lsy zT49XkFmr6PQPpgHi1xL~YmEH@z-LC)XI7C?k5$o+rUEW-utT9`GEFtsMa4op#RU** zBg$sWX^GF#0b3Do3K^^wG+)rJnl={!-}DBNyHaz@)<=vo=1Q4*hRD+y23);b2E9dM zPdoy5?YmmIIt-pf*y>1_Gp=tXnEX%6N~Zq-`aNKG$lT5Iir#szQ64t}may71-YsRv z>w?R31Za4k0+@G2_c;g%!^-OeD5r(shC#wgtvZ7HDS@6m+gRn6FPuvSx^vo&eQQH3 zy^S~25Uo2ay7#w`YfCWivhH)Z$~vq(9>~CwI9^v~1_p}+{WjI)Q;o!hlsyP*OL>Mg zZ9bN%+z6N5?p|2_aI-VdQv&8Pzgme}UYSHMD|&Fxa`=9(XDNS8_owpLpTRVWH{`B! zHAD+e6V7OO4kM^k&R`#z{ub57{jo6#vCH)Ti#$ZM(-D;|5r5PXopi*NEfHZIaf*%@ z))H|)wNO-+j_6}YAbTXOXSjrFkiEJQofJls(Z-RLo~16@Sbg{v{#Lq`exQX3NFVXw zB%52TZGtfFbxS2{IChbbXERGVu{F}HX9a0X(Z78=cWVmPVp?*i7{){rD#Wy zNL2F|5H2;p4awt;M|rJjhWROxD@^yZax}v8oJD58pxHh<_TOW+Q+G2ehq^6!?7+W9AT^r0rzVjB= z4Ue^Ns~?hkbEx!vENr(7$+cb{&h!?pv6gZ^E42?e7|H8D{Q_clz|kJ(rCxdH?Ok?f zXgl%-W>4?TGd#T2#dF~qRT;drn?EFb>VC<|`=O5uB4X*MX!h1A|8SK%uj=KhHWcYy z@V(L$6n$2WKpn>(zUp<+YUK_(2+4uhB?kjAw=TlOK;;(|M%6dQRi9ahL|=zh+t}xT zzGz(aoK=CkEO7$K%ZLNsx8{2lACf^mmJivC=J-9C)2}KQ^~%g2)lkb(lfHNu%Db++ z_nzNmq< z8`HyeUnyl`SFlnMO1-roo27E^l9ByNQ~Uk_tv{L=bxkwXo%0<`F0c1mIZQF!XAoC; zv3}#)bJ1dIi~FaRC#FGDUdVV>n@mUwo6_t7x;gB&Afv>RKoS1I( zeH1}T+G0yRa&Tc?K1_r}KG$0ZI!K3TvU@Tqji5YXdmHxk*LRY?k=GR1A1?DAt+1LuhL-ZF|k7C)Jm9 zmVJe4TsU1SncXVa)ASV;k3t)^HsoErGH7n42{&{P88fo1rATqg1ZC72*4IPmx11zb z7_F@mG~eFE*KneIDNLt?hk94_2}i&9EvT-1c$ciI2t-!wm9(|aK2NfVHTtID z!qw>4+T%htJq`a08-meQu$`9OL`?}^antkl9>dG!#6 za~oLub}Okiui#0}V=DXQ6%3+C@BD9Bxj`e^k)r+eMSJ8$)cT??4W0(BFS6t*)cT_D zTFj9T^LViDRUo)3(o9WjZE-7BjdVg=8| ziC|@AhJBe`bhiF8o4THZt(xJ&44 zgpcxIa`TVU$ZGdzQjL&SY(^k4IZAp8exhek-Aj9jH5SOssk}TfxBmGCspI}G_8>F` zA{?t@PY9i0_%b6PS?SiE=yQ^fKEON+*^(fdp%Y`HYW)D0!oQ|iyNQ(^7ALiN?!#iu zV2o|R&u**?qZ;Ifv3pp8fB%d*lJTj?3}YKW9uugrTy1E~aJqr0!S18NxU^rR7N;-H zQ57mlMT8PHM+50hP{|h^pTY1Ws+cp=BY4FWyu30Ply^`iR-|6q&$TX`>fam}&0M=w z&nkEn>eN*C8X(aEG3n&4RjJvEmJI+CrLL8Nmk8IuK}u?Af-==ahVHW1S5)p~<%%s* zj}2;POyOQD*=RJgqp*sMv$JW0&1H622jP3sf=Q~L%xFP{d{lYOd%pvfF3+L8jK>J> z7Rn-cNZ9$}HiDVQvTKQFC7;~F)A1GqqgjK1h$#6uH!vhP>U9-dBtdn@!~Y8j4UUYJO)x;2IEaKgY&FSv9A^;ER0^DZgPKEJ|nd6$s00%>PqDEq9M!gPMlsVQ{x z)32tm6+h?I6t?DPU=3bi&D!R@{HgoaRWrIx^Im=vbADl6?Vhx>hP1UcBQS$3MQ#T@ z4`qO!=;}a=iLQMvYTHcI2eIdDn=*jKSuxonQKk*cp_lK1ddN47kG>!Tl$l_n_|Uk$ zyLFU(ODI-+vNRh{EI#;UVO#6BvxQ$4X2dS>1{U&y{FUtkHM5|+^=Y`|*ce?IuR18Z z;lXqgA2n2Bn^v}ni9C$Hb&dO+Jt&LVU*_-|J(4;-E4VP!HZ@oyS4q=?3)As0b8#B? z$l}4+u+;pOQ<*95UzsV6au`Ei^`j3AW9Ih6FwWCPa33jKMXPZUPORK3$(O4b3e_u80%$8S>Uv=wUQvDXa`yo=T*n}jIG+l)bb1 z=doR16$Hz{HHGO~i;#vYwpJwKgTb27f_dQ&dU{1r=CCkb*?8X{Y*Igwu4}9)p%bU% zdJ*`~#&{gNG55b@ryld%k04BmY9-;#LyXA+^yEPzjq=O^Tk8YeT`8`V`hegoC0rlK zmS1masrDpsu0)iY`(i&o?^m2_4s{<7gHsJxw~UR>ys><2LKKeL8NBgmT=e4dqiZTxgdDOc}9ZkWWb?6k`gYGo6yDm-0j>ep-LS}%F z>5+HoT%H~LHOvPjeu?LYU6}ty7ZH%eeP5S2ccqL6Tnexm=5maZJ!wac5x_UXGtHq$IS9 zp}d(H-g$k}A)VNa)VBl&LA->ow?1DlbaJRPHW6X%?%WU`+sPdC@) zdTNlO#NV{JPFg9~vhPAs>h-z8vHLADBB!vriISYR=nH*8Z^t4$`DF!-BA;29ZIonV zt74Son1yE>C1)ey_CrYMr$a2qau7e5-vGa1@=vCm1vQjsMn!Zm7C`7Q3>C0WLlhOk z`ZJkF$vFZ1g0bei8=+S3 zl5j?aF{+(--y@%I`|?J<3j(#~miZBEsIH%~oql3mHr1f>j#yAVc8oxZrse@;szM z_lk@aiT;L>QmOG=1A&mS0-UA<-}OmA2rAZ{83L}RAURZ?A_!#eTNFdxasOw-C{=vc zkm8|3e9v1=MoCpYIHxt?1qf9LTIZ3Qp`V#v*+o3$#ysy*0{I`e^Cu{eJvkObR*pi? z$jicJpD?CBXN#!WysO*p=54`VpUSzRSzqSjaGYt`V0FXnB5d9=7}XTd6zr{tj_L_L zD?-k#V+PT*H&`z<`Bmb5=Mu3oyh=CVRJ#Gy?x$gBGOih}IlxSs;@|?i9n2T3c^%SS))mR0c~Mh^TOBf=}+g{*x^UW%mUYh9Saw zV^sU#!cC!?JJZuLVE@7B8unl{qlhBKW$C7S#}3fs+8M@8JKgx62_)7GVr%oxa|(f1 z2NMI36gg#5%~f{f9DxUdJiDfJf0@5)I2=7_gY_PmPKJcjL$rkB{?UZFr}reLdVlSccx)kgPl(Qmbp zhO)EsQglTk{<*B!xAFM98Io4?qU>Gxoz~V`c)ErtwWu1+SVabtCAjdtAZk<2q(e1l zp(ibKeWvuJHEA;N-dH!v4dwM+zeRJY65&$Ao=I@2Jd}$GF4gx(&akCiv6+W-SJ8s% z!?M-)E?B}hWh|f!C#yP%VqjH27bFTPjlF1*5+1|>0#=CD9m?`)l!IGs6mE5}`NLo@ zT-0w=+zOIV-0BuI0*YI$NpPzXJzcn>;uzad3nL9^C7pmzVTT&?y!o`MeY#zHwfk2Y zGBBr|f0i1P0!>-wu=Jp-9z($Ku%`*ap2i!m!{gb4N2Re#(W=3FTvivX1?)Y}QYomy zrK{Ckiak$8mZao1noKa^QmX{-3pa$2ebO>;ycvwH7A`e{C{oOXOZ7(+!Zkm9BEY5k zmOy91rG(9&tXscyNCI~@m*N<9ll76hCFDHAJ~5X{+Ib&y_uv?je)mdtCjM8UIpoww zpQJhFPBtX?`t!$E8vcigSdIf!8OQE+TiDM&yonb+ln&<9s5P?ES0KcT2x+=U{!@vN zrn^i&S_3KN1C#2r=~Zo|{&lbKJMULE%(q2-k@NRiCtBRgQdiQ zR7inZZT?F-aybyLf3^#of2R^)3Mx98fM0hA~w+P`W;@59Hv z$@A?BA^2M87qo2QC%J=#?1Qcykl=`?q%(oehW`=bdB!Ej6IP&bHnC+ob|BD;H8f;B zbcUp(z`0Cl3Iq)n+CRNJjd>QnNA&l{knw5zgqz7&l#xY~@ky*KGP*Y~x)%V2jK?q# zL)7Pp2|$AyD#Tr^K5gO-tB_6H!*yJOxJz~18=CY+>NrK*OFWy`%lgLPD#rLfZ3|y} zQq5`hhw>rY!aaPjEnL=03hfvbekglG(|zeibQ*iw8PP+4nEM2c=x^$~pM0Bg_zI;6 zZ>=z16il&}a)BXJh`F=wp^rpBzD(5+=EQ}QNHlGzn zJL@)%iGoZ2qe4!F)Fe~@!kkY;d9Y@sDEU92yyRx|n#Qqxob<kMIGy*;W>2 zYCJb1nFNjK+X}NkNC5tsgCsDRe*ylL^Y1cJ)RIC@K}h}9Qhq@5DoP`HRMCLXvznkt z7Jy8l1S^;0_7m!x&Oi$xQU_T4&{jCrOiOO;6KD*cNZ+Ise4_CaaT@=hIW5Rb&fVkh zn_wHH(1>8H@p#VLVm=Wv3R0!RTJse1v?su-6&=qtod8S^Tlv<#67zAtp5P3I^;1vs z#4hzSOBX&$`0q{j3|udXVwav~-G^`>6R-$m|rEU@UHR$gehws4Sgi_qUQi*=N*(v2j$5tc{;lKI z=(v}4T!W5#RmZKZnCD_KfudQ&iybDL8H5#QF*j>Mjq^8)n_ zSa6Ke54#Ik+?EL+&vjqd0G{0A`D-;>u)H4q`D9n!71JVhh=5y*^;S7L3iVOX1wHj~ zM>=Xti7MkTL49yq0mnR8ui&0<`HiKw&0jVBqH%^u!@DV{-TUKxsd4W{3|K&lfPjaJ0_Lt%e+9ayUA^oUwk2(qM5c zyzaj-YfbmRzXSj$V1{`f0Yc$!9o9yL;R^P66?J=D{1%p~6K64Xv6i1id~9}hhNQ<%U#a&wAQPfG zZ!2n4*P5huU(=PjUKIPNC#~f@6KJeM8P48#jYi{({2q(OL0H+CJsy(y9x?uc*<0;F zc>z;8H5OS|im8unX{wy{*0b!}6y#b}{xym6NB>v(+y5!$4^`z4lJfoXo&V9aHo4oV zYq5&Xk%;xy?cb1A4`Y0lRk&DDIP)#b`rGdRfw=$L$tLc#_Hv}>oFGT$TrfH5@OKHF zf*_YV2+;>lYCV#fr*u5y8t*#Yo^;7I$#J(nY5R*ukxa;mH+BC4*+&cHDhZr@R=KG8 zSgt+t9u9gNxcs4W;5D)cgiU`X$>bb{gDUJaDhOF`qWNNnbOql^JI>{|)UY>H7cIC8 z`eN7Q9!iwl;A^c7G`)8}FL1N9I;IU_Lv;MR6;_)!rA)GHdG2bwNuqz>9&({cY`_LUQr|L|Ck|x4y*01z^CaWZ zT-lxGJwPMk{;qcKOwSEW0?ylA7#Dq@Xz=_j$uAGs4sIGAy|a7D>_D_&0!5@$c2#PG znCGMiZ8UA^YojT8r%(0QUrbWj>)t2Z{T&jCjmwOr3bv#Kk8v`NrF77;J zsj&SnuDtLdgB%b=9*QNo!@)>9jOJ}s-iglZ-g{jR=G~93QW9Hqd}oHY+_$tft;aTv z>y0v-F&n#`1lDgmg*;_GtEsJz=6?0sr1}4LG}nBpO^S|lTFrNr8?%L}k=W$apt21K z*6<4K+W0!`$cAK8_8;P_Oy_#-1g`#Z>+En5p7H+RU6P7@W94}j1{YE4uy$FK7OhVU z<{z5+RZ|ZV1@pH|_b*JHS6k_=X+>cX*N;Kh;rt_0oAQrL>zuoTHOu@cWO7_@y(mXf zuAc%m7h>;lqIrbJuH=7-yCLW^YQfY;$Ztq$18Nz#sxETZZO^+3VpU2E4>mUOP!{)q z#HEki*|Kl%sq*amCbAB(1abC*Pd9r~axH5LtLR}a3w!6uW}q~7ZNIQNN-k+Zse^M8 z1Qs#RFU$YA(yQ-U-oAoX&8!txb5QQ3&AW@7^5ly5?oSy{RM~RXIdNC(=Q9&!nC{D2 zBtU1|`UUU-S^H9=E95JsswZ0VEV=7DUR?&F>K=C0BEPB2rRJ^ZS4K@VukIdpeL{*{ zJ4M)hXc2{k%>^Q#h4a6~VNCu`F8;r!gC)SXVL5 z&`PqVr-zM_EDoy@fK2b*7s-6(N@HVKKFm?$>415L%@vr)6J;W^NGI<3jZ=={%;GFe zHfS}M*W`G>CuL%zpM#A4;Qg%gA*^g(Vkxl+@;JU8GQ#NYFHzUqSp>%KscHf;9&`^PdO8|wp`0R)O-L3e$iAzkBgOYdY056Q)4yu8;o{#~d~d$-$Uz0TH4 z-4Wg-=P@^hV^_tgA`&a%6|&DbauZUS8Sb?cT9?J!%A(0L>3g$XGNsDsi4TR{HVo?@ zF)$fmhfB@%R2V%p**iZ%<&A^*W4*Up5NR<+=Gz3XMr35}G2pn!ldf13-cpbz<$+5e z!uB^HFGl21cOyTH>w5!NFSL~{jyfMSCS`?tZLTj=ZVNEn=*Iy9FBUUdIl?RqSidx| zL6czE`j*ecv#f>X*2jbZUuKyIXnc&f?vjtF(#KU@DN) zcp)cf>exHUkj;Po!pgqZn(+oiLvRN{&@xeiiT_&UV9_waWCrzQTc+4YwKT%KTQ$;@ zwW{(e*1G?mWuus7B^YptU)xa`aesfNi_Ef7iCOlS*QBAkoS0`Dq!>0&6UDHRX{}Ym z_N%barxR(S&nldSjk{}A1JtrtsgBL%)?(tnDTzsrog~-$&S8se$LQbx>Q{m2k)#v1 z!jW{J`q9nG;cyPR&C4DmyK_!XA2=9IS>Ww;%!8TB1=)f#eaX|tN?`QT0KDDmjwBw=-GiL=5k#nrz~*K5BZlWl)}*n} zU;rl5xF5X)824X)dZH3G^83zJoCG+@#3X%Vb|P}=xN$`Bk3%0aW6wv5^GI=zodP9% zs!Gtr+dDeMk%3-i1spXa^ zt}*Cv8u}l^YTe<+mmM8WlMW9!SYe#!=(2cLqUxDhEnQC6T_(9S+B$qC=#{VP+1dTZ zrHo6d3SuwD35|c-pH<%OP@O?;cT`#ugwwoBb~L#aR*1RL zj;Syvr`hO`cCNREj}y{39uLHUhlP8Oswd{8x7roTH14!~(K1z(%%wbqjAz)t_)h{0 zoLvv7<;t`;>VX)GO3fboSpUjcVDnf+Ctg`ze|Pmup;$Q6_He#F*@UaesvN z&aa)>mSd(;7;#VK9Eb^q1??tFW*9&ZGaFB@bb-Wl1z)Ms<`4HUcIIQ*H3E#T9^cZ~ zrI#_D)^s0mMWqAn=FZEOkyZ$`&K0vL7JKlE{h$mW9Gf|!kS0ln$QT8{X_-Bgq?YUE z{j>+8dvsy6q*Pi`y;^Eb@)p_v;T%Bd)opm?-+YO=q_jaOfkCzI|37ZSmeUd>@!xIG zBiQg+q77*+Z8&aiPx?daS0v8R4yn7;jf|Uj-a^4)%romvW`D6_wQ5~#C-01pgwxA9 zDJOyA7$_XQJ`2VqHi{t@44x3jtAQ_sGZg+IY)s22f+e18bwYJPY?d(-eptvQ)O~z% zL$*l!L`XR0DGP^C3v(LSor=o5B%(p6VmZC4BJ%a+G{f)aEmHg-+) zYk%C7avLvZQO4Gl#Ss#3O?yPJiz>?sx>S-?dFryPR3vTjNsG@aQ~AYMWS7!3SR^Ik zSK}2SaA`zHfUbXKCxJFkBHY^!E0-iy5ixj|4GH=P{3F>7Zk(cM#}PHij*-ry>jL=H|+?zHiPx_5Zt?l!Kz!?I_TQgYo)oac}uX@x^@jgS3^;(`jRE} zII|g*LCz3`v=7$Rwhy_uf5S6|war_4tqk^BPg=7!=vrG8Tey32R(8m|lq73IyfiwO zf`fH+9gBGNuoqS1s74iS)&*VbiemTwu<@O`5MD{Rbs1tAPY>3u>{7%HOp4X*Xppjb zpKE<6_UOyr*}sHbyMlGAS{J!KqEkV0y|i_0yN2qzv(_vqk>{f5AT2a6%`9?(j2Yc& zXfy9S+?hk4%-i}Io$-0X74uc9&8~IaOFyZ&-}A05v_18~;@@d|R^7^uf*Z!ZvyBeA zD6QB?x9Con5E&EQ;kLRImFUmThv(i%f3g$(@dc|_z1$o!=@v~+c1vTICsD3BTcMRx zMQJpN-`z3JC~Cp3;6b`alclK-y^56O+M?TMH%*PydPl`B(koMjBfbGq3WU`yp+{;mxDfUq87swC3tQ5U8cr1qC1jgrV9{!}RvMh!~_r0@4mq%+>%R zn0UP_9ZzR$Ib5&Dwsim9q+VOLfG4{kiIj21mixjFUG|^H6;L#9eHgwb8S`fboImvf zI4lS!T7Zp<*p?YvzHKrp!~X*!1~TL(rag?vexi1NivNcoiC3F6Z%cIm2=NDk>Wub# zsnnmIyYL$*CiN!^0h+GvXTkjYgJQqx1=O) zow4PCtj_cOKO#YIlH$KVace+ouV3)mpLf&!Avs$UAtcpWDmJk?V8)f(?}MWA`iD|U zbGP6*9z^M%EW^tQVYl|8ln7o54Aj!}uQn}9N!&#xRl~f!u;;TO0bxDQ{0{w}Fy!qk z{_i0@cGqof&Pz_*1s;-h6g)(!$5Ilv0WYqqK}INS*n4+99wVi3?hYz^TZ;dCf+7^V zBPDSs6}Am!|8ny)U-?5iX3W-II0$vNzq5H06}N>Kw=Z#P;x2GlXcY?B4`!gKDd`ZJ zE!$Ak1HJYhJW8ey&4x4LQPfr_&vZ^6QG?>Pr6lg)Tnq?kJx2?5@!!jl??p|xB*}Ks zCZgeXfwmc2&OG|bS^tkR=0Eh)v}fC<&!1@;_VRWZ+$~%1qC}96V&*@b9@Xh`O5zs( z_rXq}2SbTUq5wx$+`r^n=QI$CRO!Pat#@ z<@Kss_!~4Fy|>^O`V-{c5(2_N#SbtU<*p!nGw1#J#il-JNK@YHnN5&1hpiYqY^mVjzINh-c@iF z)S@v%uI{CF3`KKo4QP_4d5&5N!n-wVZea(ztm_A%TX0%#;4{tEwVrsX^I&AF-csE(#XnUGE@|?^QtnUHVq6;IUMlVV+H0>l z48AHWg^!`Pd>x1#8nod`40FzP#~$rLv)=DdJ8HincMQW6b;*e8>4-BDvgfA2yWWL& zhMj8&As5jH14|f=_)-`8*ZYF!~ zZ6NLvA5xtMi5RhE(#GAESdFgD^got0KTUgX6uHG2+7886j&SO4+JE(!|K8aJS{F7- zRP{SFVB`_Z+gpQ3`27uWBJ@yxYci(ZScjfh=ci(c(@-NEa+%6(m2+@S3}U>&9o zPO1?vZ|LC+4CRADDYawJvZT|0KXn|a<3Jq;>NrrxfjSPgY}h$bbABc>XHOk&^;{&2;vm;{Fr~FH49)n)sA&p%K@A`{#(H z1LH6LnJ$0Nk?ld&lh&XI7bgsUaoF5wXgFG(19MC5NNVMhsjN;p`; zVG>T1aH@n0Bz#Q5l@hL(aJz)ZBs?qO9}Il5o9*OC_8pVX1^U684rbK|)o& z9LELTyCj?=;UWpEBz#%I^%7P~xJ$zQ5+0ZEw1nSC_=|*rpNjIDNZ3Zg7zuR}_LQ){ zgd-$0N@$gEvV=1wd`QBlBwQt7wS+q)+%Mr-2`@?bn}kgypV~-hm+df4)+1lSK@#?p zFiFDB61I`Bk%S=b>FWM4$SP&4hAO)+zf>zU?JZ$#~ z0uo$dNpuj%Lg0z6lzI4b5qkiFEe3 zdaKoJEm54da)-gBxEv;v5)+--J;|sPn=K}%Vzw&cr_t;%8C*7p+2rh`s0bv?El5kx z%pRyXOt+UKnNt~Vwi;~}P9>*MNs7}cHi!F8f==i2dqiG%2n!F%$j{Hs@2w2A>WeHO z!=@NbE|a6oY{d_AnMs*y!&Q-4??h^b^tBT1rs@XI4Yo471$h5P4S6vrCkxIp zDY0c7DeCM1XLzyUAvre1>>T=($PV6(dPW~&pzP-1rJEsE1zV%59K z9VSt($}h;DV4=!WAuLY)WK`CRq^>?K6BBJj;kIJIA!0yyNJ=r(zz0iLZwC6dEhmCn zEj(m^*$VQ!SY1m>m0C(aJS9ITGiP9LrLYw3EAqK(OP0W@FN5&tt;TMU8ILZA+pbc* zOVJY-l$_i`B`r5QFQqUuH7i4@FuO|Kx({oR7?&I$r(_m$9(z=Tk|DE~*`S09NRcMR z*i|8!a+N}^tS-fg42Dw0p~nq~aH-yk+~T2p2C?z9$^Vu5m6=OQT~IQV1m+qHCa2RZ zja7X2*djAHV7FV$2Hw^nyj)n;a;p&}desaD5h$p}wsIFtgJZH8mN!ptn4~0hiBnRn zimk|LfJ`YxVg_8o^qW^vBOpdK`}{l4x4GRmY12pBFLPuYMP=qnhcNzixO3CHN&_Un@x@=l2LkIVzLVS zK;kU5Ib0k8npSFw)n<+5G?)#Fp;YhCL$MuBB}T6lms<_oeo9QX;$o+XXpz4?0*0Ex zKoPgV2`be6s8gH}R=dN7W$pR98TixEy8?^V z=Bgb9aaeKM!IfgvO7hiUusOJS0&=}#F*{wT2(Wk*$5{?>)jO3k8=gtJP~&pDkI=*^ z13-2enRx1CfI(kGLW0UW6}#TyG8@WaYoQm;a#L5uRHiqhWemnL{Uk6p$}RH+c0EK& zn42P#K~Jg!&YH@KOh%%!D{7#3IMIAgC-ni|{fW|7i7xl34mT3D>ra`!66&CoTg#oi z*9HS2s=cNt#&X_;+ig-qL}7wi9J3d`%GwP(vp4^QoU)-`>p)0xTbsbq5E<2KK&lba#$LmEEk=#5a?nXtQMIb zDiejs=jqY~tb})Fhg~n>-M6s6O0-e2z%W^ys0`uu{>c1=a23k*R%G}1l2poMn+29i ziBWG?DzF+w)bABTogk@Tkvk9RIC-s5P}3BH2~6ysoSc{pNfdGpI}BwZ7Y2`jT(7Dd zOqa#jiBlInLQvXPhD7xaCz|VJXB(aaE{IfyygzpR7=QSYfhiWTcAC4%iW}oQpwM^c2LP z;$o8{JOo{_(*~05HZ#~(WU92GEy?^zdufo)BA7$62Y*y=5g5Qa(aFJkr+y4w9XFfg z(h9>YNt2@mAuQlF%%7v&?&?h~uS6Gc0q}M-gV}JVXAWj%W_(LnZ>B)*Y^0#6;{9|0lyvpL@5fOi$592 z@n#{X6L&I@%fa);uujP5;7`i|t+*n3qVYElCljlm+UPI*$25wPZbz-nyiBJoNnr-y zBL3)ctJ!BR`HbD?+Hpr3*g3+e=_?L_Cjbw`?i1{{Z zPw~9llqx8kVwDUBgoQH%Ocmydy9&7uG6-Z`D4{fs;gGEilxlz!mII157qX`ZeMO*3 zkNcBwZQ<=lREu_0Y0pJ%j9gX*$XZYjAU?I}makO&nZ6Kpz8@j$q$diORFbM9{36aN zoKl5TBD6}Sl+x=#qpFR6M!CW&&^A+9D)>>1f20F_xn^Ha4P$~H1?^pv2SUyX8|k{o zvKY86q1HDtfsxt^aR)2RA?zS^7J8+~qPI?h{|0*p`66xL%}1@rnd^}QDTcn{Dq9!y zVN?S58U9|83GSjE-X^IEAw`!dJVhVmigRjeIhpUid@xE{<1U$`y#lC6Nevbo+zWR( z!&oLuha}~)@!&~;yU{%N#jRoTX$pG$bmYmEDO2Qql6rw54o?TTpQ{Kl5`_g%fp+EK zc@7)MwJZnHtMa>yOM#wSaI(n)i-MLE8s=#cvf3o`!opJT$9Oxd82^`;jNbW4cX=Aoe~H{~g+zZt84#JHQt=v7xc+di z%r4%q=q(nT7{$Y#gHII8-E_0H90d#2D>9dq5ZOSZT%TG*Psmx64r-Zx3Ma;`w_g5U zY-O@KoHQZGL5`f&ri?Ks_U!I)d4ULHN;UQw%@v)-G=h3;pN9n_f@}!362j1C)X1SsZ?;a>Tg-6kWwA8$!QcZq2)V&M z4&%i-c{E-j@*tmHHNlXRVpAp%Bk^WS9?5Z*MPFpHV6bK_fs+SjB_?<|V7&6>#$rek zWATVl$0x%&=yZbd@~^~8QEz9t-A<7ov(;cJH-Zf^#_i-0Zj71Zl677ApgSRsBL5f| ztJ3Li$Lw+pW<*S-65$B42wX7CWo0I#8RHN>m<9_gNM>Ry5f~AK)Tp0VRz7I+R54mK zs!X3L`CM$#mnc!O(FPjh(nmfYPC?7q@`SGHK$C~Ftz9Yfh(A!%*opD<2Px32$J)%k z`D5MkO9(_TfC42H8K6iO;T9E;e}_7`GQg$wj-$!&8ci5fkbM&4TQSU|5wR!ahESf3 zLNQ(eIgVM@NBX0@78Ey%EqBtNVs{V{^za(gmVUBVs(4;qnb^ZGAN(Rcm4Pp!wJ3)3 zNI?lV#t-LzUhA|BCxs%sgp3AE~lV#Fc=mI{0 zm!?K);?1+@c}xdt%_Wt08^bcwGjhil7Vvy2L(?<)4>@Clh!4ij(y8Qfs+vC{!MA+G z1-b9(%@8$QY=ZcZIVksO3g7&qoq1qSZDh)Tf@(Gu{{C8>*9ivKB<54q6KQ|p`H`KJ42uJ6J>hRN~j%`?4!3- zPifm_KGiM`wpq;J`B1CbU^AN3a8yk*8Q;C8nN;~H=q20WU9ML@;zQ>o-(;0Nq!4=a z>Cfw5S){}y$0zX64@N9D!z3r4Ec4`teh8z(>pv002X1sGx)n*%!oP6(d;xh+ey4?J9+mH zdL;>oF#V=fnh**XBxCA;44zD{+IN~c?v3G-o53~f@{K6s1Pv|-U*61nHZX%QB7icZh_J>E>TR^bQ1X?zJHQmIF^W1 z!&Nbmbs=jcFoXA;cT}%n1)m%-OGl)8Cb315;8^2zbXJ%g20gHOhz+6fuj*gO2_5%S z#cqM1!HC^3foTfDl6;!nSqcM7C6g{oUpi6erG@TzsJlUUInGMN^vmKD#eExI4i!nW zFNCiG5mopUY7OCoN-|xgv;aas8Is7SG`!GZ0*1%((UwJ(m`vak7cu~aNzV)}1DMIS zx;n|0^%4UJxfB5+BPQ0UrU_v}CW!l@S3K!Dop4N0jY*=QoI;QT>u3SNmnR=2c5*n zHOe~!_j;g26`0J2ObA^k;rD7d(gVulg-yz_kZ)O@!`1w<%o+niB8aJQ4Na z#nF_69`iTF`f>{l0hCR&quye|^dgKi(F4)o-WOR4NQxLUnVq%a^XLjlq;@ICaD{|` zrXl3mK#=6cG4RXj%P$(a(lQYtKG&01Q-LNXaJxtLN{TcZI%A5S7WnjrXYMrg9z&tF zGE#yNdw<9Y&pp2Y;iOh_Rr zv~~gnl=G1W)iMS)LA64P(FV?wKzSkp9^V!XOBuKnh(;`|ncry!<16_v7quxOyWv$; zG^$ORY&KO;0*;H1S_NLB51sxb!t8BF(ZZ^+l3tb15Q?S|y*g1r7jE!o_ImJlyJok= zy3Tk4V=(#K|AGA^dWaut0}FjrO(&n8tKDXz6^Ykw;=Guu;-U%*eE-B;`WVNWMUonW z^D3K@@73Oazp_MUEQYz)*B8|gjyYLv86ifOWpJ47SZ+W;0QjAHto|q#u^BfD1s%2L zA_*(xZYS1tnaS^klP1o;$g2&X=tr=&&O}Rnu#U}Q=R*bWmAmMDhzD{xkXXIjEv4LOmMc_gayb=)L8>u9 zsTa;#IuupJshg8JNg-P9nWd$7BNBM$>2{!~y^3vWKvVWO2q`1_NehQmS*2ky_174m z@Q^P>nz8(t*3XjXVx%0rO{nKaCb%G8gH7ro%i!dhW4$tqg_F?I5O-sue!;OtzTyty z;T{(%q{d~*KybC=enibqK}5DxoLt^{sUk`pgC*lqrg>NI?Wz^Q@~PT1#$cpeaj1og ziVIwDtlgJBxd2bPi-?+w6=$TNJkS7I5uj$w;+n?E1wU(;%QBN5YE8`qY@AAq z&2FcKP|itMmWM@sd^Mzu54tH+Ddy#EI+E~pcpk6EQH`sCFq9obG`J{DnJ=} ztZuwc*1$lg$u3u*PB!Z??r4wtPcm8I!TOFD-Rr$Xjoku^c@^0zs*+IiVxpcDQm6w3 zmueORMJUsYqIj!t`gk5W{4Mj2C{dg8hdlZxGDvxI<%nKwSRpPf80zQK-TbHe2X*nm_iyTpuY5xtGN{v#y1)ld z83Qt7i!jPCs(lo%Sun)kr~Lm^{$0RVAQs(9opaW9)4BU5EyUe@&vWGL{lUai}FPcRPTVZ zMlDW`OVDSc`$TtcfH{+0G1m;)1v$!TL!7{XCL|PmYJ=AMdyj80yN)FoggoD!!!tEa z53mJ>x^T};j2DPaC?4ge

Cznqr}Ot?5i8M6|ToikJ#5SCfoMyg_;%<)l@-oMv>% z-kCsWQk=rONdDMOipo=FTs$Vl-?66w$h4!K#$B_jDR@QD_o9Vfg*3b}&E zSbpw3r42<@vBLUusl+0Ceyh7Te!jBQ6C(1SD9KJ4F+LA(4a1%(zC3}HLN0>fWvciG zz^TAq7ZE(fP4pqg-f%{RU9{NXvtW53wLK5l^;YwF5{-!;6Yq&MdfiVLlThpZ#4(9C zx<5Wyed2{j%&T%qR(I;Csc@<-h}XE@7Aq>^ilYbg=mjVi~pWV88NX*>Wov9A&ds3%6Oq2_Rw>lrt4wP6v%TjWzU zfTKhIT|U{@{;Re_a-2rmUi)Kt7v@0NJioKJRo&%jTUVT z%2i5u_r}Sm31Y95-Z({nSF2#K-6E&dApaqdnj;bFCE3>^J3q&*cBE=#oidqo5zsW#R-#_Iag~DieCEwQQLn$e; zWS+ny;?%MW4oTdb-gu&Q2jJ6b$IecaM4|c&MvU6^PF^Q~llQ$RCN?W}BQPRAGWD(X}hI z0Rvu}>UeYYt{_Y3Z8*@b=zc3mwS!|T;(f#igFeUydLKw5?dl|@L!U{PaxRTj+G5rt zM8a9bnc}W6ZzrS|GgTpkKjBaDtCPGnG0H|p{=^&RpK5a0V&&35ZuC8pfqY4|<}*q;gO`3bKop%g=Lw**m7 z^xK?1^z-o!wf=RZEk3;9K~3stsCX}S-H)F>iwYSI>9Y zlP@D_B>ofs)S!S8Yss!0# zV5@hruK0v*iSga&#Eh=-$-Q;)y>&W4L2zt|uY4d9JPEQ#Wl`}?beuGH=A(px*@c28 zuif(0kZSo9d==T;ViFu%>WiPthg{;zODQ!Q;l6le&Rg2#CP-0)kT>F|+%(AD^&9kC zJTaF~LoMZ#sid)yM^SyITyitAy`H%1LO7wX-M!_VbBgBORUN6s5Qp|~lP5wVg~5Qq z#V52e2q!0yM}F1j7xF=aFq-M%>#&82p_~fuav)Jy%B0p@C@5EdF*1g)Njr~yNaZXD zj-BLNe=(~7vQ_P&BLEaQqgVzD8;X~&{9uLJJO6Z$+ z7T&qvLIt@O2?%Ob`B7=|szxx*{_w#M<>LMdxGSR?WJ%Pu`+PM%UoJtNO6~Z>4gepd zwa>x&AVvGsf=;v_$t3W>DU*v~#54j()hj)cuoKpbr7T$J1#u?h!DowPJ!m}X76y_p zj*I?Ol$z0#@C9*HLlrgh!Qgn4CR{>=m+403!J`@!BPOqe!E(o4g;r;$g5RF>9%Cg} zX7*0f_3Dlh4%VQEHWgME4L}cgZZ2w4-fB#5qc5{rCc}<6E6a+oSjGTM)=6B-P%SeC zEPRC|Vz2Nd;Wo;)7k-lH1+c)Rtdp15#oM0?zvv3+xoFf*UXmkd8UQhnsk}TCaRf*# zpUo49-20MYY1P>@a&0N(M+P>S{1pBXG^x=WFTa;}`oe=mdg;t4YEQ;3I5nhv;FB8d zPA*}s_}#vuidyiQBE;9Fr@*S5D^%l{L@otbedr*Ls4koknc!T$Sppcn>*pRQ5aHbD zr~(#DPULmv)6L27Qn2gPeCLjVcRoJu zHrk*CI#Hdb3+tSJs8~ zVf|P)oM8~fZf2ty9^w<%u6>8-aUEki#g4z@&bt^Jot~LbPom>>{3t6oOvctAu|1vV zbKh6f(R0soVV;KmgopI4?L((PsGeAX^u%gQ*O$(sQS$W_N&&TLs$~+tz`a=Y40U3+Q!;lo%5OJW%9{XDyt=k9vdj=@t8{`@)&D*ggj zd6C%jO^!~EXOtwG)2UWybe^7{$3k8Qc7Bymc-<39fMX~pdT`n zKP)$a0u>-DKZXjjh5Z0(G8UcSmVY17xV~KJ%!p3nh6RsS%gyAoQ`Z&ikz&sk$#YFT z8(o-NIM(|hEV2jUToW$_cusKg+F#&4kE0-pmOqG)`HfCv`a9=wq^0Y0@lw;XGt=^O z3vvh05mxzmx%oK6DmMquYQ5i8$<4`7JdcK_jO?o9XQXH6=A-FrJ5ZhDNQ*NX4KBq>B(ZzSef4KR{N?|rXbPXQA&xgp1?v}wkXUL@492k-FzL)4z zw^S@(U=hyKy?Xt=%-^qGu&GD)S6Fk|0DmQt9TpIMlz6y#;3We&(p6E#=&iMY2H z3Kx^4oA-qBco=oxh4(&BtQX>^_c`5(xtFKrkmZU~|G2ui5sH1g@R(?uC3f0EfFvC^ zNJj&HvBg8C8vu`(CL7hg_8uC1&$IcfbSc=NiJ_4=HxH+?b>iI@&N!s;60Hiky&SV} z@W<#GQE(ld6b2Dz$8ZnOg-tJF>xMgA!U_NDd~U1|Zkp&*8^d zUbk=6b6TZ)txY+dl7`{G=QK3x0aTx3d^9$x( zdV6h?R^?2UU-c+6YB{Pm-;Ssn(n_z4RsOAu|E?j}R5Yt5i8E&$Zz5^f7#7 z&mBDKuHgHN854Py5JC=O6z!>McnD3Qh&|yv&Z$RkatP%XW(1@7$z0^edaC2ZFqKDY z;YRuvA?4LKIafiq8t?`Bs_c11h`jw%K3l2}51~_yOinxI-ifi%SVpTJQ-hvIoZl2f z3-Y3!VpV;tfs;jH3fgajcBgG2X#en#;&Mc0)M9yTl-rAc#CNZD!saxtrd-IqMo4_P z;x?on1(fB)(IG$oB%_Dvj1gKcEclZ}Q;@PJ<|8o-ZfPS97kkcdv>**Bc&l=Pgeu~M zD41Yzs2K3z9D?pT_}lK&C&fl+y#>7o92z<@$74ZBk&tRjrGwVUlwlJnu*i`-Egs;)4wFxlPb3L==r+gVP&psuwbkpdv^*g>*^5*k zT_>Jj$EUx-SF6>y0Uqj-JPl3!c9;J*%JoT4OFM{ObtZ(a>7&l3iC@@%BWKRk-?f%Q zbdl)zlpu1{nx3ra-%URNc-{T7PRvMrPaX?M~ zchpj5;S5kMiCc~f#zey(t|9;N@!oqSJ=Or{{>h!rHS+(*dQcz>xsHEw+*R&duFA>y zgr365BEj>n=MCkfc6@I7)q^zL2Ag-E9?UnQ&!Yz7fJ2qQgd|<91YU*dOG z{*v!`O@nc^QW_hAlbi~13XkXXp<3|^IV|`yIh6jS#~#$1%7rz324p z>oR$}@iHGDtIMIP8?oDs_qgY(-}2|_-3Lm0BvzKAs*CE^Uq_ody7*`5|FN4d=DW;> zeA?_W(B#U+5)KPI0+TV{{YW8M(ww}Gt-e7C$eH5`VN!*KL>ow}Vwd|v2 zeVFT~>A$rq|KY2P*Vsj(Z|!}1e$7q&YQm#q9-O)8@yD*to;5NwGUH0o+pffa-TwHS z-SXWdwIY7XT20x^6G!G?J1h-a;dsci8@xOdDu%^4)q^{U!Ro0C)UQg3(Z{3vWDI!5Gt)(o6LxH1yah|E#j$lYJ?LVJvcJP6x`}vTJ{G5!e#Duu?tSrKi zQ-}-o2YzQd(@i)m8V3aA!DGcbXi*HyaotvKa>&WcOwY0PB!85ohAd(nTL2ffxVSIH zVn&bv_KhAvbD6GkC$8KTzCIrgl=&O^Bw4J6VdBy%boYjX3!dh03@&&&3@gGz{$yOC z&iVf1VFh95_SfCj{I?G%FqnW|*D|2+xGy*0uc!aJG5fae_o;PU z+4;eM{KRTDATwR0>8*^0wY5wcD+Ceud0;$;A1htsA&SW02ctuVk&w?3B1yExIaWP~ zCYK*iPyRI-M$hT!<(51;l$~Zk3($$Wdh@w8dDs~68Y>FXIa+wMoD%>&P|$m;>QQb< z!QKsnXyqvB9vVQP3Y*JfV+ zlr9Pdz)7YO)bTmai@%ZVV5zP9?HuL8*_Xmc@*(5Y;`Co4hwrHd2e=2s*Yoo2fwT&c z&!qC#!0_1=Dm%5@Y%vz_+@5O7;1yw@)jN_@AsSs&t@Y60bH$(go+0P+Jhz}Q1#|*7g5$}!_`}7nEjd5epU(Ri=lRpy0BU~P zMWiYQ-97!6=e;-KOMB3aP7e=$X3}f(w!E@$_vaVBk8c#==S;|tT9>~l^{V4=QLlw9 zX5F!7)N>mTJhAQC51*YX>X4SCXf;jF8sB#19 zN5_WEbb%jFzEZq+*xCW3-GMD1iR$X#XF^y?t5x4V`1>~>ee`MPS3)u$zAKMhsIsbY1}U% z?zT4e`cGfmbm7wzzwNncbMIG2K0W2ZIS;=uW7lh6KNGeuc1zCpw$G7xjB@^D9wRGXH&mCLScU!9icb^*f!)tyIHTofHe?oFzu)KM1064Qe>iY; zv*E>)CpR6CG%V|A+0ObucRRo1(ew8|@a9V|q>nHS3Y>CtX?2UwgJ$-8F6Pb;#(Z+? z*KL0NdG3+N-+t+_x620?j_NV7+0^et_O@Kp`H|jnzc={S@@e)*FK(Rs%DE?Z&hI#_ zp2avOBkS2dv$~#awI!_Wg?`t@?wNMt@mJs4eDuMeo^EdKe%H_(*SLjoulL(m|6&`G zhJWemRdm(Y|L(2Zf*+0CURLkH%M;O(Di-cj~1?HqCF!u_*fyS?qY^?}PzZ+<%Q z;D&S0?yNT@>1Wnp!OGx&wOCsJ^S8q%-W}VwENF?v_^@V-;q2wxCQT~RTUs5_nP%s( zqD$W{4z%2{TyxWw%Rw`TZ*TD9dq-EB^3K1}=&KEz=1!aQ=5Hrje_E6od#vdX(+LO0#3gzb!8S2}#nY?~5%u=vfV zPwRKr|M|0VOLrda6t#5k>a{CBe!qF&H6v$)uZ_E9%*HofvAk8S%-Znn`Zb#$3;SZd z|6}`KbM+c{=&M&N_CMLQ<0sl#&5k=8g&I!XbBl3NzlmkxD@RS78oH*Sjb{&BL)f%`{I zJr?od;7?0zC*J(|=L?$_q-}bm`Jn}?C!Blk@Zq}_?t5nY)+0UhFP+H!zU1wFCBxrY z@oC_?TZeRiebBKk;YYG=3VHR)VE^tDrfO5RU6^oU=!ue*7ZzCKD>s=3%v+=XpyjOM zcdGW=qPu@ln!mUr>_h*7p>Mz0%rB~2$AF=mZh7n7n9z-{KQd}<7wyC~W1heE@z(e~ zd)Li<>S)*2t3DgOdaLpAj+YGIJn`Jb@{omPelG+DKXGgK`d`m3spn`soCVArym@hx zsT;mn)#bH2dfv1??C}Nr9|_-d=*$}zj!$cM;*-#W`w!fk`o+QTe_Hctsdd(|wjVXy zG-GtfH?MqNvD#KK@QoH{M+MEXPi$~)*DZm?V?s3zuRUdY(7dYXrvuj}=`;3Nnoap4 zr0To<;U5>y(&lVkg~_&-t+pv^VintT3y<>@qw*x?b0n=Q?TN>wH*Sw?|o}w;Kv_z8va?~=8~iB z3-8&fTlsXo&eY%aA-r!OX2%4 zzR%i8elHox8Q#;2Gu&}cr!y2|XGj%()9W7N z(((&Cj7UqNG%IV|qnoRJ?~S5#8+`6%^1RhG?$OO1zV}8_-o3u}I6l0qm$kyPxDrz- zMNcRl-XqN4Mif_4Y&POF^Sogiw%U#~yq-vacCG@D^`30AxXO(9O|m-$?IiC{ojTQ6 zL>pmR?1F5f!f{iGCya$1(6AWFFL;!IOO}Lt5DWDl4UO3#-1FjP65XSB1h*nwA}^oU zVkb3hFP_DDnt|=by@xdN9-dA30zbNHSzM75HNqz%kl6{3UC_joKsEul;~Y+hp@Ud@ zGy(T^K>p-CPN#x2HD&7lngp>XMtlqFu_mCoNdlfV2xJY6^;iS^Zjcaa7i9#o zko-Wq25l7qToJ$(;Ru@$nHa*NG|l^mUkp7NytiI;fL%MmU+0%MJ%!}bkBR4zN^Q?q zgJYun5R@N`@;y!#pWlQR!6oY9%QoyngMu|tfzd%5BWG>!B6CAfjlh|BwvYl;H59`xGYSFj1OmR zjXA7sVK!@c(+%{)Ylb2y5T~|7&YQPewvl8oBDTM&M1OM?!g93?jZX4}si3e)4^}8rjT`)q`9U|6oa3WK+n$ z!%s)Qd(!WlfnO8Je7Gmuc!T?S+ghKW#B)t!v{gdb#gLOhdjqSrc9IWGvmn;&kp?Hj z_l8yn+k+<5(*@>5CWNyNuI{XZF`0EpN@5)}aUTB2wx2+4uM1;Qu1FSTY{8C z067g-8fyZTKoBR=knBV5(H_t_A1UXun(D)CA*-#zSS#pqE9hS<$VRIKH#K%mfFBDm z0w?JwbT^_9Fd?j3(=3EFD-2`Jl0sRt1k~~*uceel$RPOB7W`?eN%!zt(ilNm|4+oXEj{s~>~3|&@g)#ZyMA4Gc+ zXm1q68bO~LL5>?GK=19L6C&FNz)r@oa7|~X@~%H*Koc6kLNy&2q-g@z zS<6~zZe|Vb5nO&1O3U>p0=n7&x>}#Lctq+d)$KIu=0e@TGg-HbqFo}$7WuXd$uaof z7`$wpFKmvmU$9+;uwAPCjrDut8|k)@ak# z`P}yG6*R+U7sAFMy=q^CE;g@K*H)6;b6ss%>vJ?K({LFIhYUfEP!As&azCp@zG|0) zy*H4Li;*|^vtUg}=GF;n2i^yx?**@$f>%uw8lJ4>UUg(N*{K$+`F>yilirk49ozar z9zy%m@BY-sbgqX!F1$Z@-M@t6&0Xr5E`XkzXVAH%K8` z)qG*dM=u+vd<5fhC3LAibSa!Q%lGJ#rWJG%eNij4cPq4aD+kw0dt@Z}0S#Hm>w$JE zD-XB?zhJW=2a%9<)n$z?UpCz^7MK5ca7YJH4ej3hSpk;nqf6&JQ zweVlaS5rTq;l1wU2d_Njxfg_Y%dal*{8rNvB%h8xQzV=t;Zg}#OSoOaBNAScFz|@T z-%`Sk684mEu!O@ToG9T`2^UECn1m}OTrc5v36Dv5R>D6d45L8^K2Z|(lyHEA`4Uc$ z@Gc1#Ncfb5YbD$+;b95SN_a^^zhkn#5++DEK*CWHPL}Wy30Fz@j)Vs#{6fOZ5(c9E z=+j8TC<%2E_LDGALZgH(2^UECtc2?&+$CX$69Ruf3F}Mv6J&%wpGmk&!u1j^m2jGb zr4r^y*jvH`2{|(SaU2(T?~-tigo`AslJI2-*GpI};VudHOL$zu(-M9o;V%*fek#gq zB4HZ|V!n%uvo&W5~}T&;*S~J zVK{UO6M7j_QrN(N0+V>lWj1zG!+z590=^}y5ZkO-b%5tbp^YXc_-!_r^3l%}yV+T2 zU@gTpGMz0ZM4-h_D%Bz-v9Cz}2>bpG|yRT*%;IR8++mU?$ ze`nhfpWIH085V4xo$RybC@Q$8M_Cx2@V$8Jbc9} zUrjoHZ5U@LYoz7V<*AjJP`3@oWLp|mWwRcE>SdwL{hXC>jsYpn$g`zdb)Fw5-l=C*LLB^qEqG~AfB;Aty>(S-4-|FtLD% zi^xrcB@HJH*(|0sh^i>s!KP?3rkGXqtXhM05SZ=7hEv)@3d#<8QAYB{n1#z7-*d^X z1;{eQPo`DN%)pa!W_Zo1hyiTHroUjwR@aoxS)%)PqHXt5xcs4cc* z*MqB=4bT=B<7Fvu3SZR9TkKXX-kk?s*{_A#8|;vzu4pyJ;8A>5>yLn2wdQa;VD3K{PphBW=O(`9ebcz3XT$%|HJ3+bl-9V00+-=0M z3JSvcwV>b>rN$|*hynsfF|9mhL$t*uCRYXMOV<{gY{iJqYK!^1OcC?biZq!#jgy_% zIwd(&p9o$emJNfDw*1;rvXgzl^;r`*D>XkA#bkK+_stQPx7&5Z5TI&l=5k$taq zk(p-W*!b~jc>_lZ4pNpis*m#4;^QcIJy&@#_ z*z*Ev?$?Z`V_;|zBBDU!i_3VQ^9l0cI9q;Q=A3MBxZ=2+v?rc(J}0qTDGy(`*uVeC zlo2CFv9$pO7L&=&e$?i>ENOZ>y=f3iNO5P>8uzkrj9a;V0FHtpLjvRCsANnVfG1M1 zhFbBqJp^0N1`M?dh8Z*PzIA?#i(~^^Mw)QL$J+x6RkBnQ#1@nMd)pxNId&~yrI?3z zSCS3Dp=em2#!X}*rS`RAnMT&b>#k5k++-oXeRGPF%r3X?T}3Zzn8eXC_5gTqwiS&p zM&%iMN{eNdT+W~7S9b8>Il4j`7X_tNrrxfjSPwL=0yS9VLhY~_hSItVr|zLT+@2T z`|+i`Re&4hHLZVCnj`W`=>e_y5}uQQu~_FdkMIKy!g|QnxTf`yEAXW>v_`T=OL5&F z@I1ax><0aSvuOjvufTMdLR*!2VV1r(aoyK(wz!SZZ9yredF6<-jKLOaVuc%`Sz~T7*1Ue@G zJ}R%P07LqTG!cMT`=c%>m!)9F17G6#Jiu#M-=W3*pft=3;M)S%2LTJxv91m@i~)RK zUhf4QK9I2{$U6b>Fuqwxe;jbhAaPv<=)x&KbblIPi^1Yr0X&2+(Rmzj(hza&0-TE7 z#dLoee1ERaAS0UhYMx??0mjShi4wr)FFu)2#MVI1wI^g3|F>jCSWq=*0 zF?JExT>-T?@9{G5hXJ0R#n^FNe*?Jb9>MeNfQ@Gh8d?Ef_=0G|36^jIZ)fe#GdO`C=z$dq14L8bN2AKRFbQo#+0KT{bYnXAp8t{)@;4QATA3%Tc zrFP5%T=og>qmC~FPX82ma6Jd`Lwul31^4uHq;rM#yBFP;?i`~=wM3vs^# z;3#}KKLMY`m+gfN06I@05AaU|bev}F2(G6CF2tA0dIE6!8Q1}&{}8azS#iGw;NAFA zxpM$Vekp9o1i;Sc1P^t9_0J0(ZvvQ&FX1c%oF}gr0j7N=(q{o~!k2Jv2XuWc?oR_e z`VC{PK*LGEmEU3wF|Jnwp7{47x3&4z(Z*OJN*dTi)$TV z=oRo9*G&Mk@a41tUc;B{Qp8o9qk}Ku83VZFCt-i80KfPdvVpwk09*bl?kj+qzk#*5 zp9h%uyO7mBfECvuAGkjquz+c}437Z}(Lis&lm398$?MaAC;efE_5nX&??ALIm-IQJ&3$wc}^fT3;BKj3~7z(H*V{yac)l!o))4){I3g#RbN&!RPK1Ja)c z+<7zbdlaj1@I)kdvX69;0_&h3)g!AkH>4+Z$ty&{RyZC?mq+=o`^DW-30Jqe7`}OrGU?2 zUEoUGe;M$%WN{sVeF-=96!a_t?3x0+NRtFO1z+Mbt+#p-UuwH$fY=?JyBB-mo5WK2KE^E840-9)m@;N(dZe!eHG2Fq@iMZnJC8=; zsU1j7XUXVMsu@>Sq}E|l9-cAo+HfXKInJ?h`QXY0jp7`eY=&Vpi(>)Tr5}cJ9XPE< z#hHLq$*eo4#l<=zy;`?)q;&GLa?GH`Lj}emwbGo9cN&OQ0t%6ehQLY4x3 z7|73N%)xawu7*Q)3!zaNz*306Ic|MnkcLp;CD|5jC-8ctwl;i3PddIDXdj(^q*6gx zgoe<*V<<67BdI1nSpdD|DpHmy<`IP0;m(N-L(DIebtC#Osj&vtA7%_?T zF;%*%ys8mZ_Npn!wX|w=)rKm1RQIXlKph9_I8eudIu6uvppFA|9H`?!9S7<-P{)Bf z4%Bhre-{VNMS~tcKc<@*eLOI@^Sy)ay&A5m=T|i|`Xk)h>8H`eH_(L#22Z$mkjCV% z_0t3}-I&0TE`c~KbY>4fjkYRBm!)g&b*F(Y*dJ^Cwa@xZXS(C9!m(q3*8uP+f4K|4?mUW51yV@r`v2=|@oGkl}h~DNdeo*{tyq zy83jpUgLW5Rn_rrbgk%4NaLnnFQ4$d<~lw`*O8w4H*V|w+-Tx&MW@%B<)x)438VdvGGURwF;ukV-K6_<3d>gZ?3ZrZkHKyF;*!|C7m zZC>`twz2hJ)aDgs*WccKZ?9$NR_-7U9|yPSBcLzfTgKlstl)3&W% ze`)`?wzGZ-i@9>VBDQc{i<5J=G+4Irt8KsgK~Oc%&D7ipj#TQ}qODs;Yg_1=xuv;p zpe8T~vK|mn&);9yniAC4Hq$oAU0F8v3(LYzclDn?KK!A17v6mO(=NI~dfZT(tsAl| zQ#UX^R@a4uC$w<~kMLwVOcr`yU9NZ?HjXY*vdm?8^N2CNnXU;X4`>{okf`g~J-JI# z_a2G8dI_r96IIijoc(S59dAdm5vLtF>n^u*wNE&E;bq-0Dz>dQSBHYDGOGsOn^Ed= z*?V{EW^h>I%GB4l$Kj-xZuUuLy4%g}z)?+j9aJ|^mS!^+m`fnY<4KTXbvB5NS#v08vt)Gs0izsv%BC25{EsNf~ z+9PS>n++TjmPReDbPiwr+ZWUSxbsZbvYQ>PN}AXIu+KZ|7uhCWIDS+4Q*SitIkWk- zka|BJuGi*C7TojJF^lGXIX`IT)CWHfpO>EW?mNA{`odUm-16ZsZrpojMM&QsA0NB_ zK&#&CJFb1D&6umP;X|_e9_rS6_x`QtE?ivmP4^SoyF*OjZTnlwe(g75Uh7Rg10E=9 zHTb!rFe)`4D+tXNHOTfaH`N7B;ahgy%#yz+YIxI?qw9(n6e53TJo%eAY^np*~( zx;P+nOY`Ewovk*u-afQwxZ|giH=~uL&&IA;zIfbAG1EUf^!ih0{MQ){yxwHTmK_gt z3>kTMy>G77|8{z#oqO@Sxf5dp#!Pr`ZRgQX zv~M*&<5bHgZEQV0h)kS5@&4@RCKel}EIg#!v$(Bl4Nt)up3p@E2Fp&qsYZ)_n0cAM zTJ2DzJ3|vcZCINSELH;SOCH_Q8Yao*h$E zy07n|hem(A`>__=|5FPGxrNk1Sfz#Q9-EN(f6Kz%0Jlpw<4LNfqMfl=H{%iAj0fG! ziSyUZn4#;d8dE<_v-let)4U;>-HbMavs+qTK{unRSdU}G;!0g*y8iC$e!8SK2}*0P z)pzukUwZc*y-%+at1M}KB(3M7b$?=wTAb3lh8gjni3V=zx-dMq(;eHJ&7QI$??BXV z!B4(CbIDIh*E)AyvbfQi)0_8fUby2_(hHx=*l@fJ+q6H~_Uf6tD;HOs@jLka*GE3e zX>*hQ*{!46x4bxSWzlUJB|)cd?bBxAPrBL7cl7GN;^X>j+I2d!{2BASsD&T8mVWun zz_d#RFIP9vneYB%f3#9&(;qld@6b^P>uSDta^KrNStS`1cJ^R?e#G(h6?R+?K{OxV}zq-`4 zGwNJwyXXg6#ZEZdAJhesDAxZR@-|NFdlhKFsa9VQ2#H-ZM}Mjjs>4!}GhTuA3*LHa<$LEKciNz3Z!H z11g%WY~c6vJ$)(vfUIo=P}^>Jqp@oyC$7uMC8H?qf+ywo10g~=t! zg9bT9x_Ua&vkJ0%4J#j&Up{=4-c+1mN=V3eCMWfUKjkSrEFS(;Rfp+OwXS^~4&Ak4 zt*VVxFy}K-)0G<<2s%g4R^jy4W;prUnHo0k?E2U%hWc;Mc=Gl2PKV=S!&&z@bN;pM ztCi7Dw0__Z`i=cwTHSHdg_y-1Z#%hd%8Q)_ja_hc;{CgRp1$%C$KW~Nzu7JAvG?Dx zI!1onbNjmQo_F+W`}N#sm95vZ_I$WuqeY2p`sTq;)_ho~={x_brrv`w`q%&lDBu6d_d9{Jt0^;^U6RUci9+&=Rb+tbH3-S)|#`KQ^z&lj~%y4X2vNxz%7 zE_-HX^Dy1a=0R?z`}=F+XEysuH?!Ggce~R#x7iuo`rJ?BfBiUjreaGgy}RpD(_%9cdnU#v zbWco*nuC#4*U>1fVXgT>E=7~+kd(9w}Zh?_4&2q#pj)8&hCGGxJDy|()gThq15yo0x#T6JaG@ivogF%Dcc^oQ7uZ!i4d*!!0cKfTJ)d~NY}v4dm! zwcOs@6ny9U#C@6vueQ?-4F96Vu3z36Rk88cHKlzv+#cTkt;vUeozUf>Q#~5r>bmFL z2U|Yhl>I=^*!90e4qegV@X+(~(@#t;S~)&X^U~qiu?`k>#wZRaA39eI^~Z|z&(wc_xOW5u@*eEH?wuTOll<;b~b+F7S7 zkM^Fq=HolxjXvG7$@|R%7R^je>>n^;bgO$(8;^Op)$Q*b?@{_>My?U;VsE) zerIdGdZo*pFK#j@oBbzD$Qx|EdM$m|!~<*EclqSE{TEBpcdqR<`i;w@-srNl>Tbg; zn`SLLJMHv4-4FHaHsZai=LVdwf7{|q_Tme{zc(1WWY%jt9IHOq+;6M(zSZNt^Xq#4 zwbH4dX0)t&b$4XYjGLU9zYKi(%$XOSy0XEzX}h7zw6pV$yg2NY z9lw^fUq3nO&31`>0yge>VPC!16WSL)SE4bU`~K3+{=MFfst8*VKA>}p?{CpH=(cwG z8+U&BNajpSP-a}-g$wFvp*yT$g4fufcVW9*etYj<&u;uNGrZgPt9}c))Z>Vci~scV zO~?${@#HPH)sD~&(-l_bSLNNCbHhFlK@6MS$>SJqm5ol& zdCUxcKyC4t0va*#ow%=WQ9WivGbZT9A%-dAI*4ZE{bgBdK*M2k+KOF&Ra(vXMq{d6 zv^Go^q892ORKvP)2Yh<<_alWrCDvG8!_{d1}J}YT=?t-r%<6zpQ5*%9Cb1oNUU^tIX;wTW31t ziduDVHwbDe5E2k52Ak6@PyG@Nyp~U-1&rj;9fGf4OOHZ@yGui>a#Gg8uPg_{Vje0* zCf*m8tab?%AE0-_?l;`96z;BUT6&mWNS4mz=2$pVg4iY*YVRzoanGoZYP=zIiJ4eB z1q?{o``8>!l1M&Sg+5!h?pBDscu4HawEbp>d2cc#kiH3WAVDufB#5b9vUD@T+a<-Q zcN!5to2VCdVmbVJIr|cqfELfCc+Qn+n7Qf=@+A!@{{Te&)J2t#4&tqhSxK#_zT4FX zA+t_^lFdmT^Tji>BSkUd^CnM^*GCCeAP-Fe3-E;LmJ#JbdBBH?={S?w0M zO8!G^y$Ywq8lmuB3H>zYhOgKYUh=;*7x4EIIWVQQmL?qTHsIj3vM0*g7aoY5+)NUA zuJLqm8jYh^q+BzWq1J=Gyi7&%o@2f{QFn~HnnRnHB;!&mRA>BHp+&MaM-$&@z{6q~ zFS?jJ(cBKbAU(UZ6h{$tAvQ5<$0xtfRclRJOc3mH8E5nnuf5s+=|awVucAlKfmvzs zDL{(3mZ6%)#2^6AboxI`q~q_H^~nR>I7Qp>gLd%$sn`6&?9Z+NhXFL@t*EF>10)Ri zmWAzR|7Lvu70qTQON?jlqs8}x7xoTHg_Aj7<6mwq-(+TfLG(2Z>F!asTc?llMNCYQ zA7}`;z;+zXx;#E!wF+{W!Xg~D8{nP^`jYH*X?y!Z6(4d7&bdUREaP#Q?IKQq~6`*|I|u1{Vns*HfBRP_EDr#Gwb-=p~YVItsYCO73) z^Yp<~TJlU*1wEpvC5R}1^mO^<(`CW|QS~jczTjxB>-r&2A2}CRkEl&0}W zl~dd5>!DzE9n)5rnsGX)S=&pVdm-LJf2yC15_E8-5AN|SbQ+X751N7rq6hDYt+ajS zWg9#j!2THSei4~p5+{Df8Nd)SGlw3SZ|q5NU4?^{1>+4yMn(F!YF_Q{@L6}Xv^c{% za;UM&oGHS$gGUtoHf_W5QG&pghbQ<)gjKp&_ysk?%JoPe4kS6f$;jJ>_U^2VtgqKV zP08Q=on~V+nhgWI-)#-eeKCE#M*Fe-?!!R4ApqGsmfP-+uD9R`C-jveecU?=jLSb@ z@TZh>+y#LcqYYpMSb*7o(`&|Y(X<7(7NGe%9B4`i_E$vG-L*oN=K=$Qy)gmk@UK$n zr>vCjt!KilLZs{-jNMvISMOZ)8b7yQ zWLx&}DoMuX@N+5h$$W|siIjQZh;lUb@2A2%Q=?acz!)(P6Ro9uZPg;Hi$_MmWW zI3aBz%a9B3Hqmz1V0k&8NPkT^)-b+#LJbi)e(E-cy?K!k`$C z*OSgluBEp-W$iv3JQ#BTsY{>kAVl!txK$)G>M0~6)u?K8-T#ZYwGT><$AI{*zOs8R z#mOx9#dG8Hb#~UQ_q^$Ku~7xCzQNmUO^aF{>fT$uty-tB*efl)pN`Me^Hc6W(4CWW*q}a2y%VbBygybBFy1?fhzE= z00^aN^>2=i=42S@p$fF2&-Pmby8#R~+6e@b)&4x_f5=fYjH^ zK6&r$2E{XS(DVxH*Is?)@BN}*P43U^&L2%K0ucT#=4d9D;}7cXzhv$3c$%|v~yxmM}cW7wV2Nhk<^En z4y$)(u)n5R_b&5Y1d_9k1w^prjyK{5_d$EGEq2ZjBfS>0q41he z9d5TC@FyKY-o;rcqiecu7R7nG9QNu-qAuKaApj1EtB`9f@-2<0Zah#skQKKNp#)2( zwx8}@6BrTS#G4}GsVA=+7!GTo^riBNS68dvd3;cKFIlo953#5`yLsTNkvR{S&aCoKNGX_b0ycMh%E`%mY5p4Juo16lMI*fFp6t z0-d0$8(ZUKTeLyRuN^3etmMC#;ooMFS{}+eM7|y^$(c(n+o!U5o}J Date: Tue, 21 May 2024 23:34:02 +0300 Subject: [PATCH 40/63] replace max compression with recovery compression --- tiny11maker.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 5a159a37..caba846b 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -362,7 +362,7 @@ Write-Host ' ' Write-Host "Unmounting image..." & 'dism' '/English' '/unmount-image' "/mountdir:$ScratchDisk\scratchdir" '/commit' Write-Host "Exporting image..." -& 'dism' '/English' '/Export-Image' "/SourceImageFile:$ScratchDisk\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$ScratchDisk\tiny11\sources\install2.wim" '/compress:max' +& 'dism' '/English' '/Export-Image' "/SourceImageFile:$ScratchDisk\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$ScratchDisk\tiny11\sources\install2.wim" '/compress:recovery' Remove-Item -Path "$ScratchDisk\tiny11\sources\install.wim" -Force >null Rename-Item -Path "$ScratchDisk\tiny11\sources\install2.wim" -NewName "install.wim" >null Write-Host "Windows image completed. Continuing with boot.wim." From 5153812f23519a59b857814a1442d9bffcaf38b0 Mon Sep 17 00:00:00 2001 From: Kichura <68134602+Kichura@users.noreply.github.com> Date: Fri, 27 Sep 2024 23:03:21 +0200 Subject: [PATCH 41/63] Disable device encryption by default. --- tiny11Coremaker.ps1 | 2 ++ tiny11maker.ps1 | 2 ++ 2 files changed, 4 insertions(+) diff --git a/tiny11Coremaker.ps1 b/tiny11Coremaker.ps1 index 40316479..0f58e007 100644 --- a/tiny11Coremaker.ps1 +++ b/tiny11Coremaker.ps1 @@ -394,6 +394,8 @@ Write-Host "Enabling Local Accounts on OOBE:" Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null Write-Host "Disabling Reserved Storage:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null +Write-Host "Disabling BitLocker Device Encryption" +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Disabling Chat icon:" & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' & 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index caba846b..7ef954de 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -220,6 +220,8 @@ Write-Host "Enabling Local Accounts on OOBE:" Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null Write-Host "Disabling Reserved Storage:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null +Write-Host "Disabling BitLocker Device Encryption" +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Disabling Chat icon:" & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' >null & 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' >null From 1fe45e2e8086d33a372c621a286c0d8bfb458c68 Mon Sep 17 00:00:00 2001 From: qtqgyt <104375741+qtqgyt@users.noreply.github.com> Date: Sun, 3 Nov 2024 12:22:50 -0700 Subject: [PATCH 42/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index a9280f8b..f39750bc 100644 --- a/README.md +++ b/README.md @@ -81,7 +81,7 @@ Note: You might have to update Winget before being able to install any apps, usi 3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. Features to be implemented: -~~- disabling telemetry~~ Implemented in the 04-29-24 release! +- ~~disabling telemetry~~ (Implemented in the 04-29-24 release!) - more ad suppression - improved language and arch detection - more flexibility in what to keep and what to delete From bba078c34bd2108188a09653ea1de32edffe7a93 Mon Sep 17 00:00:00 2001 From: Karl Wester-Ebbinghaus <45657752+Karl-WE@users.noreply.github.com> Date: Thu, 7 Nov 2024 00:25:16 +0100 Subject: [PATCH 43/63] Update tiny11maker.ps1 - use dism with PowerShell commands The idea of the release of this project is using PowerShell instead of commandline in the previous version, which is a great move and make it easier to maintain and read. For sake of easier syntax and readability I have attempted using PowerShell commandlets for dism. There are few remaining areas that need to be reworked (invoking dism.exe) to become fully consistent. --- tiny11maker.ps1 | 23 ++++++++++++----------- 1 file changed, 12 insertions(+), 11 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 7ef954de..f115e6e0 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -49,12 +49,12 @@ $DriveLetter = $DriveLetter + ":" if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { if ((Test-Path "$DriveLetter\sources\install.esd") -eq $true) { Write-Host "Found install.esd, converting to install.wim..." - & 'dism' '/English' "/Get-WimInfo" "/wimfile:$DriveLetter\sources\install.esd" + Get-WindowsImage -ImagePath $DriveLetter\sources\install.esd $index = Read-Host "Please enter the image index" Write-Host ' ' Write-Host 'Converting install.esd to install.wim. This may take a while...' - & 'DISM' /Export-Image /SourceImageFile:"$DriveLetter\sources\install.esd" /SourceIndex:$index /DestinationImageFile:"$ScratchDisk\tiny11\sources\install.wim" /Compress:max /CheckIntegrity - } else { + Export-WindowsImage -SourceImagePath $DriveLetter\sources\install.esd -SourceIndex $index -DestinationImagePath $ScratchDisk\tiny11\sources\install.wim -Compressiontype Maximum -CheckIntegrity + } else { Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." Write-Host "Please enter the correct DVD Drive Letter.." exit @@ -69,10 +69,10 @@ Write-Host "Copy complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Getting image information:" -& 'dism' '/English' "/Get-WimInfo" "/wimfile:$ScratchDisk\tiny11\sources\install.wim" +Get-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." -$wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" +$wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" & takeown "/F" $wimFilePath & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" try { @@ -81,7 +81,7 @@ try { # This block will catch the error and suppress it. } New-Item -ItemType Directory -Force -Path "$ScratchDisk\scratchdir" > $null -& dism /English "/mount-image" "/imagefile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" "/mountdir:$($env:SystemDrive)\scratchdir" +Mount-WindowsImage -ImagePath $($env:SystemDrive)\tiny11\sources\install.wim -Index $index -ScratchDirectory $($env:SystemDrive)\scratchdir $imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" $languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default system UI language : ([a-zA-Z]{2}-[a-zA-Z]{2})' } @@ -358,13 +358,14 @@ reg unload HKLM\zSCHEMA >null reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Cleaning up image..." -& 'dism' '/English' "/image:$ScratchDisk\scratchdir" '/Cleanup-Image' '/StartComponentCleanup' '/ResetBase' >null +Repair-WindowsImage -ScratchDirecory $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase Write-Host "Cleanup complete." Write-Host ' ' Write-Host "Unmounting image..." -& 'dism' '/English' '/unmount-image' "/mountdir:$ScratchDisk\scratchdir" '/commit' +Dismount-WindowsImage -ScratchDirectory $ScratchDisk\scratchdir -Save Write-Host "Exporting image..." -& 'dism' '/English' '/Export-Image' "/SourceImageFile:$ScratchDisk\tiny11\sources\install.wim" "/SourceIndex:$index" "/DestinationImageFile:$ScratchDisk\tiny11\sources\install2.wim" '/compress:recovery' +# Compressiontype Recovery is not supported with PShell https://learn.microsoft.com/en-us/powershell/module/dism/export-windowsimage?view=windowsserver2022-ps#-compressiontype +Export-WindowsImage -SourceImagePath $ScratchDisk\tiny11\sources\install.wim -SourceIndex $index -DestinationImagePath $ScratchDisk\tiny11\sources\install2.wim -CompressionType Fast Remove-Item -Path "$ScratchDisk\tiny11\sources\install.wim" -Force >null Rename-Item -Path "$ScratchDisk\tiny11\sources\install2.wim" -NewName "install.wim" >null Write-Host "Windows image completed. Continuing with boot.wim." @@ -375,7 +376,7 @@ $wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath >null & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -& 'dism' '/English' '/mount-image' "/imagefile:$ScratchDisk\tiny11\sources\boot.wim" '/index:2' "/mountdir:$ScratchDisk\scratchdir" +Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\boot.wim -Index 2 -ScratchDirecotry $ScratchDisk\scratchdir Write-Host "Loading registry..." reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default @@ -405,7 +406,7 @@ $regKey.Close() reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Unmounting image..." -& 'dism' '/English' '/unmount-image' "/mountdir:$ScratchDisk\scratchdir" '/commit' +Dismount-WindowsImage -ScratchDirectory $ScratchDisk\scratchdir -Save Clear-Host Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." Write-Host "Copying unattended file for bypassing MS account on OOBE..." From 3ef0c7efd9d1f883502c818daa6b88ddb9ecc9fe Mon Sep 17 00:00:00 2001 From: Karl Wester-Ebbinghaus <45657752+Karl-WE@users.noreply.github.com> Date: Thu, 7 Nov 2024 00:27:04 +0100 Subject: [PATCH 44/63] Update tiny11maker.ps1 small corrections --- tiny11maker.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index f115e6e0..7baece7b 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -54,7 +54,7 @@ if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$Driv Write-Host ' ' Write-Host 'Converting install.esd to install.wim. This may take a while...' Export-WindowsImage -SourceImagePath $DriveLetter\sources\install.esd -SourceIndex $index -DestinationImagePath $ScratchDisk\tiny11\sources\install.wim -Compressiontype Maximum -CheckIntegrity - } else { + } else { Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." Write-Host "Please enter the correct DVD Drive Letter.." exit From d53ba61bd40bb35bcca08ac8b00a13102cb38e1b Mon Sep 17 00:00:00 2001 From: Karl Wester-Ebbinghaus <45657752+Karl-WE@users.noreply.github.com> Date: Thu, 7 Nov 2024 00:42:52 +0100 Subject: [PATCH 45/63] Update tiny11maker.ps1 typo -ScratchDirectory --- tiny11maker.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 7baece7b..8ae5088f 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -358,7 +358,7 @@ reg unload HKLM\zSCHEMA >null reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM >null Write-Host "Cleaning up image..." -Repair-WindowsImage -ScratchDirecory $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase +Repair-WindowsImage -ScratchDirectory $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase Write-Host "Cleanup complete." Write-Host ' ' Write-Host "Unmounting image..." From a5a4d979941e39c55bb5e9ee3cc66e96a7e7d094 Mon Sep 17 00:00:00 2001 From: Karl Wester-Ebbinghaus <45657752+Karl-WE@users.noreply.github.com> Date: Thu, 7 Nov 2024 00:45:53 +0100 Subject: [PATCH 46/63] Update tiny11maker.ps1 fixed typo -ScratchDirectory (2) --- tiny11maker.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 8ae5088f..64f215b2 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -376,7 +376,7 @@ $wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath >null & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\boot.wim -Index 2 -ScratchDirecotry $ScratchDisk\scratchdir +Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\boot.wim -Index 2 -ScratchDirectory $ScratchDisk\scratchdir Write-Host "Loading registry..." reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default From 5ca27c740e325c042a00a29e21ba11a43e291558 Mon Sep 17 00:00:00 2001 From: Karl Wester-Ebbinghaus <45657752+Karl-WE@users.noreply.github.com> Date: Thu, 7 Nov 2024 02:07:18 +0100 Subject: [PATCH 47/63] Update tiny11maker.ps1 - error handling param error handling for param as we will later make the script agnostic to execution on OSDrive / $env:systemdrive --- tiny11maker.ps1 | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 64f215b2..fe018247 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -29,11 +29,19 @@ if (! $myWindowsPrincipal.IsInRole($adminRole)) exit } -param ($ScratchDisk) -if ($Null -eq $ScratchDisk) { - $ScratchDisk = $env:SystemDrive +param ( + [ValidatePattern('^[c-zC-Z]$')] + [string]$ScratchDisk +) + +if (-not $ScratchDisk) { + $ScratchDisk = $PSScriptRoot -replace '[\\]+$', '' +} else { + $ScratchDisk = $ScratchDisk + ":" } +Write-Output "Scratch disk set to $ScratchDisk" + # Start the transcript and prepare the window Start-Transcript -Path "$PSScriptRoot\tiny11.log" From 8c1a8d104587f1438387ec7231e79b251f3a0ed5 Mon Sep 17 00:00:00 2001 From: Karl Wester-Ebbinghaus <45657752+Karl-WE@users.noreply.github.com> Date: Thu, 7 Nov 2024 02:19:39 +0100 Subject: [PATCH 48/63] Update tiny11maker.ps1 last corrections - to replace wrong command -ScratchDirectory with -Path - putting param to the top - make sure $Scratchdisk is $PSScriptRoot remove :\ or trailing \ - param will now have error handling for drive letters c-z and C-Z - all references to $env:systemdrive or $($env:systemdrive) now generalized to $ScratchDisk - tested the modified script and review log for errors --- tiny11maker.ps1 | 293 +++++++++++++++++++++++++----------------------- 1 file changed, 151 insertions(+), 142 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index fe018247..1c30b468 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -1,6 +1,19 @@ # Enable debugging #Set-PSDebug -Trace 1 +param ( + [ValidatePattern('^[c-zC-Z]$')] + [string]$ScratchDisk +) + +if (-not $ScratchDisk) { + $ScratchDisk = $PSScriptRoot -replace '[\\]+$', '' +} else { + $ScratchDisk = $ScratchDisk + ":" +} + +Write-Output "Scratch disk set to $ScratchDisk" + # Check if PowerShell execution is restricted if ((Get-ExecutionPolicy) -eq 'Restricted') { Write-Host "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" @@ -29,30 +42,26 @@ if (! $myWindowsPrincipal.IsInRole($adminRole)) exit } -param ( - [ValidatePattern('^[c-zC-Z]$')] - [string]$ScratchDisk -) -if (-not $ScratchDisk) { - $ScratchDisk = $PSScriptRoot -replace '[\\]+$', '' -} else { - $ScratchDisk = $ScratchDisk + ":" -} - -Write-Output "Scratch disk set to $ScratchDisk" # Start the transcript and prepare the window -Start-Transcript -Path "$PSScriptRoot\tiny11.log" +Start-Transcript -Path "$ScratchDisk\tiny11.log" $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host Write-Host "Welcome to the tiny11 image creator! Release: 05-06-24" $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE -New-Item -ItemType Directory -Force -Path "$ScratchDisk\tiny11\sources" >null -$DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" -$DriveLetter = $DriveLetter + ":" +New-Item -ItemType Directory -Force -Path "$ScratchDisk\tiny11\sources" | Out-Null +do { + $DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" + if ($DriveLetter -match '^[c-zC-Z]$') { + $DriveLetter = $DriveLetter + ":" + Write-Output "Drive letter set to $DriveLetter" + } else { + Write-Output "Invalid drive letter. Please enter a letter between C and Z." + } +} while ($DriveLetter -notmatch '^[c-zC-Z]:$') if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { if ((Test-Path "$DriveLetter\sources\install.esd") -eq $true) { @@ -70,7 +79,7 @@ if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$Driv } Write-Host "Copying Windows image..." -Copy-Item -Path "$DriveLetter\*" -Destination "$ScratchDisk\tiny11" -Recurse -Force > null +Copy-Item -Path "$DriveLetter\*" -Destination "$ScratchDisk\tiny11" -Recurse -Force | Out-Null Set-ItemProperty -Path "$ScratchDisk\tiny11\sources\install.esd" -Name IsReadOnly -Value $false > $null 2>&1 Remove-Item "$ScratchDisk\tiny11\sources\install.esd" > $null 2>&1 Write-Host "Copy complete!" @@ -80,7 +89,7 @@ Write-Host "Getting image information:" Get-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim $index = Read-Host "Please enter the image index" Write-Host "Mounting Windows image. This may take a while." -$wimFilePath = "$($env:SystemDrive)\tiny11\sources\install.wim" +$wimFilePath = "$ScratchDisk\tiny11\sources\install.wim" & takeown "/F" $wimFilePath & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" try { @@ -89,9 +98,9 @@ try { # This block will catch the error and suppress it. } New-Item -ItemType Directory -Force -Path "$ScratchDisk\scratchdir" > $null -Mount-WindowsImage -ImagePath $($env:SystemDrive)\tiny11\sources\install.wim -Index $index -ScratchDirectory $($env:SystemDrive)\scratchdir +Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim -Index $index -Path $ScratchDisk\scratchdir -$imageIntl = & dism /English /Get-Intl "/Image:$($env:SystemDrive)\scratchdir" +$imageIntl = & dism /English /Get-Intl "/Image:$($ScratchDisk)\scratchdir" $languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default system UI language : ([a-zA-Z]{2}-[a-zA-Z]{2})' } if ($languageLine) { @@ -101,7 +110,7 @@ if ($languageLine) { Write-Host "Default system UI language code not found." } -$imageInfo = & 'dism' '/English' '/Get-WimInfo' "/wimFile:$($env:SystemDrive)\tiny11\sources\install.wim" "/index:$index" +$imageInfo = & 'dism' '/English' '/Get-WimInfo' "/wimFile:$($ScratchDisk)\tiny11\sources\install.wim" "/index:$index" $lines = $imageInfo -split '\r?\n' foreach ($line in $lines) { @@ -122,7 +131,7 @@ if (-not $architecture) { Write-Host "Mounting complete! Performing removal of applications..." -$packages = & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Get-ProvisionedAppxPackages' | +$packages = & 'dism' '/English' "/image:$($ScratchDisk)\scratchdir" '/Get-ProvisionedAppxPackages' | ForEach-Object { if ($_ -match 'PackageName : (.*)') { $matches[1] @@ -135,120 +144,120 @@ $packagesToRemove = $packages | Where-Object { $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "$_*" }) } foreach ($package in $packagesToRemove) { - & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" + & 'dism' '/English' "/image:$($ScratchDisk)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" } Write-Host "Removing Edge:" -Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force >null -Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force >null -Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force >null +Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force | Out-Null +Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force | Out-Null +Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force | Out-Null if ($architecture -eq 'amd64') { $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "amd64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName if ($folderPath) { - & 'takeown' '/f' $folderPath '/r' >null - & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' >null - Remove-Item -Path $folderPath -Recurse -Force >null + & 'takeown' '/f' $folderPath '/r' | Out-Null + & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null + Remove-Item -Path $folderPath -Recurse -Force | Out-Null } else { Write-Host "Folder not found." } } elseif ($architecture -eq 'arm64') { - $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName >null + $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName | Out-Null if ($folderPath) { - & 'takeown' '/f' $folderPath '/r'>null - & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' >null - Remove-Item -Path $folderPath -Recurse -Force >null + & 'takeown' '/f' $folderPath '/r'| Out-Null + & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null + Remove-Item -Path $folderPath -Recurse -Force | Out-Null } else { Write-Host "Folder not found." } } else { Write-Host "Unknown architecture: $architecture" } -& 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' >null -& 'icacls' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null -Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force >null +& 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' | Out-Null +& 'icacls' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null +Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force | Out-Null Write-Host "Removing OneDrive:" -& 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" >null -& 'icacls' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null -Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" -Force >null +& 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" | Out-Null +& 'icacls' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null +Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" -Force | Out-Null Write-Host "Removal complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Loading registry..." -reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS >null -reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default >null -reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat >null -reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE >null -reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM >null +reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS | Out-Null +reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default | Out-Null +reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat | Out-Null +reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE | Out-Null +reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM | Out-Null Write-Host "Bypassing system requirements(on the system image):" -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Disabling Sponsored Apps:" -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f'>null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' >null -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f'| Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Enabling Local Accounts on OOBE:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' >null -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force | Out-Null Write-Host "Disabling Reserved Storage:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null Write-Host "Disabling BitLocker Device Encryption" -& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Disabling Chat icon:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null Write-Host "Removing Edge related registries" -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f >null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f | Out-Null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f | Out-Null Write-Host "Disabling OneDrive folder backup" -& 'reg' 'add' "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" '/v' 'DisableFileSyncNGSC' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" '/v' 'DisableFileSyncNGSC' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Disabling Telemetry:" -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' | Out-Null ## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. function Enable-Privilege { param( @@ -343,48 +352,48 @@ Write-Host "Registry key permissions successfully updated." $regKey.Close() Write-Host 'Deleting Application Compatibility Appraiser' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f | Out-Null Write-Host 'Deleting Customer Experience Improvement Program' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f >null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f >null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f | Out-Null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f | Out-Null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f | Out-Null Write-Host 'Deleting Program Data Updater' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f | Out-Null Write-Host 'Deleting autochk proxy' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f >null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f | Out-Null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f | Out-Null Write-Host 'Deleting QueueReporting' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f >null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f | Out-Null Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() -reg unload HKLM\zCOMPONENTS >null -reg unload HKLM\zDRIVERS >null -reg unload HKLM\zDEFAULT >null -reg unload HKLM\zNTUSER >null -reg unload HKLM\zSCHEMA >null +reg unload HKLM\zCOMPONENTS | Out-Null +reg unload HKLM\zDRIVERS | Out-Null +reg unload HKLM\zDEFAULT | Out-Null +reg unload HKLM\zNTUSER | Out-Null +reg unload HKLM\zSCHEMA | Out-Null reg unload HKLM\zSOFTWARE -reg unload HKLM\zSYSTEM >null +reg unload HKLM\zSYSTEM | Out-Null Write-Host "Cleaning up image..." -Repair-WindowsImage -ScratchDirectory $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase +Repair-WindowsImage -Path $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase Write-Host "Cleanup complete." Write-Host ' ' Write-Host "Unmounting image..." -Dismount-WindowsImage -ScratchDirectory $ScratchDisk\scratchdir -Save +Dismount-WindowsImage -Path $ScratchDisk\scratchdir -Save Write-Host "Exporting image..." # Compressiontype Recovery is not supported with PShell https://learn.microsoft.com/en-us/powershell/module/dism/export-windowsimage?view=windowsserver2022-ps#-compressiontype Export-WindowsImage -SourceImagePath $ScratchDisk\tiny11\sources\install.wim -SourceIndex $index -DestinationImagePath $ScratchDisk\tiny11\sources\install2.wim -CompressionType Fast -Remove-Item -Path "$ScratchDisk\tiny11\sources\install.wim" -Force >null -Rename-Item -Path "$ScratchDisk\tiny11\sources\install2.wim" -NewName "install.wim" >null +Remove-Item -Path "$ScratchDisk\tiny11\sources\install.wim" -Force | Out-Null +Rename-Item -Path "$ScratchDisk\tiny11\sources\install2.wim" -NewName "install.wim" | Out-Null Write-Host "Windows image completed. Continuing with boot.wim." Start-Sleep -Seconds 2 Clear-Host Write-Host "Mounting boot image:" -$wimFilePath = "$($env:SystemDrive)\tiny11\sources\boot.wim" -& takeown "/F" $wimFilePath >null +$wimFilePath = "$ScratchDisk\tiny11\sources\boot.wim" +& takeown "/F" $wimFilePath | Out-Null & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\boot.wim -Index 2 -ScratchDirectory $ScratchDisk\scratchdir +Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\boot.wim -Index 2 -Path $ScratchDisk\scratchdir Write-Host "Loading registry..." reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default @@ -392,33 +401,33 @@ reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM Write-Host "Bypassing system requirements(on the setup image):" -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() -reg unload HKLM\zCOMPONENTS >null -reg unload HKLM\zDRIVERS >null -reg unload HKLM\zDEFAULT >null -reg unload HKLM\zNTUSER >null -reg unload HKLM\zSCHEMA >null +reg unload HKLM\zCOMPONENTS | Out-Null +reg unload HKLM\zDRIVERS | Out-Null +reg unload HKLM\zDEFAULT | Out-Null +reg unload HKLM\zNTUSER | Out-Null +reg unload HKLM\zSCHEMA | Out-Null $regKey.Close() reg unload HKLM\zSOFTWARE -reg unload HKLM\zSYSTEM >null +reg unload HKLM\zSYSTEM | Out-Null Write-Host "Unmounting image..." -Dismount-WindowsImage -ScratchDirectory $ScratchDisk\scratchdir -Save +Dismount-WindowsImage -Path $ScratchDisk\scratchdir -Save Clear-Host Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." Write-Host "Copying unattended file for bypassing MS account on OOBE..." -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\tiny11\autounattend.xml" -Force >null +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\tiny11\autounattend.xml" -Force | Out-Null Write-Host "Creating ISO image..." $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" $localOSCDIMGPath = "$PSScriptRoot\oscdimg.exe" @@ -454,8 +463,8 @@ if ([System.IO.Directory]::Exists($ADKDepTools)) { Write-Host "Creation completed! Press any key to exit the script..." Read-Host "Press Enter to continue" Write-Host "Performing Cleanup..." -Remove-Item -Path "$ScratchDisk\tiny11" -Recurse -Force >null -Remove-Item -Path "$ScratchDisk\scratchdir" -Recurse -Force >null +Remove-Item -Path "$ScratchDisk\tiny11" -Recurse -Force | Out-Null +Remove-Item -Path "$ScratchDisk\scratchdir" -Recurse -Force | Out-Null # Stop the transcript Stop-Transcript From 9b70166776e0e29ab41f040017ad5db9c7489846 Mon Sep 17 00:00:00 2001 From: Karl Wester-Ebbinghaus <45657752+Karl-WE@users.noreply.github.com> Date: Thu, 7 Nov 2024 03:03:19 +0100 Subject: [PATCH 49/63] Update tiny11maker.ps1 - prevent outlook and devhome sideloading added changes from #203 --- tiny11maker.ps1 | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 1c30b468..03dfeddc 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -258,6 +258,13 @@ Write-Host "Disabling Telemetry:" & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null & 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' | Out-Null +## Prevents installation or DevHome and Outlook +Write-Host "Prevents installation or DevHome and Outlook:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\DevHomeUpdate' '/f' | Out-Null + ## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. function Enable-Privilege { param( From 9ca84542f3a40036f385cbc25299797a0ac2e624 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sun, 17 Nov 2024 20:51:22 +0200 Subject: [PATCH 50/63] Fixes for 24H2 --- tiny11Coremaker.ps1 | 21 ++++++++++++--------- 1 file changed, 12 insertions(+), 9 deletions(-) diff --git a/tiny11Coremaker.ps1 b/tiny11Coremaker.ps1 index 40316479..18b94909 100644 --- a/tiny11Coremaker.ps1 +++ b/tiny11Coremaker.ps1 @@ -1,5 +1,5 @@ # Enable debugging -#Set-PSDebug -Trace 1 +Set-PSDebug -Trace 1 # Check if PowerShell execution is restricted if ((Get-ExecutionPolicy) -eq 'Restricted') { @@ -220,10 +220,8 @@ Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webvi Write-Host "Removing WinRE" & 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Recovery" '/r' & 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Recovery" '/grant' 'Administrators:F' '/T' '/C' -Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Recovery" -Recurse -Force -& 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' >null -& 'icacls' "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null -Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force >null +Remove-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Recovery\winre.wim" -Recurse -Force +New-Item -Path "$mainOSDrive\scratchdir\Windows\System32\Recovery\winre.wim" -ItemType File -Force Write-Host "Removing OneDrive:" & 'takeown' '/f' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" >null & 'icacls' "$mainOSDrive\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' >null @@ -391,9 +389,10 @@ Write-Host "Disabling Sponsored Apps:" & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Enabling Local Accounts on OOBE:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' >null -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force >null Write-Host "Disabling Reserved Storage:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null +Write-Host "Disabling BitLocker Device Encryption" +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' >null Write-Host "Disabling Chat icon:" & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' & 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' @@ -419,6 +418,12 @@ Write-Host "Disabling bing in Start Menu:" & 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' & 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'ShowRunAsDifferentUserInStart' '/t' 'REG_DWORD' '/d' '1' '/f' & 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'DisableSearchBoxSuggestions' '/t' 'REG_DWORD' '/d' '1' '/f' +## Prevents installation or DevHome and Outlook +Write-Host "Prevents installation or DevHome and Outlook:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\DevHomeUpdate' '/f' | Out-Null ## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. function Enable-Privilege { param( @@ -707,6 +712,7 @@ Write-Host "Bypassing system requirements(on the setup image):" & 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null & 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null & 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKEY_LOCAL_MACHINE\zSYSTEM\Setup' '/v' 'CmdLine' '/t' 'REG_SZ' '/d' 'X:\sources\setup.exe' '/f' >null Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() @@ -723,9 +729,6 @@ Write-Host "Exporting ESD. This may take a while..." & dism /Export-Image /SourceImageFile:"$mainOSDrive\tiny11\sources\install.wim" /SourceIndex:1 /DestinationImageFile:"$mainOSDrive\tiny11\sources\install.esd" /Compress:recovery Remove-Item "$mainOSDrive\tiny11\sources\install.wim" > $null 2>&1 Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." -Write-Host "Copying unattended file for bypassing MS account on OOBE..." -Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$mainOSDrive\tiny11\autounattend.xml" -Force >null - Write-Host "Creating ISO image..." $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" $localOSCDIMGPath = "$PSScriptRoot\oscdimg.exe" From 5da84b9737816348e982537b3d15731c57c6eea0 Mon Sep 17 00:00:00 2001 From: Miiraak Date: Sun, 31 Aug 2025 12:27:32 +0200 Subject: [PATCH 51/63] Update documentation and enhance tiny11maker script *merge from my old different pr. ## New parameter and improvement - Updated script parameters to include a new $p_IsoDisk parameter. - Renamed $ScratchDisk to $p_ScratchDisk throughout the script. - Added logic to handle $p_IsoDisk, prompting user if not provided. - Removed output of scratch disk setting. - Change the ordre to match iso then scratch - Rename parameter - Adding pattern for second one too - Adding synopsis with some informations on the script and calling exemples. ## New Functions for optimisation - Introduced Remove-RegistryValue and Set-RegistryValue functions to replace direct reg commands for registry modifications. ## Auto Dismount - Dismounting the iso image after process completion. ## SKU validation - Added validation to ensure the entered index is valid by checking against available indices in the Windows image file. - Introduced a loop to repeatedly prompt the user until a valid index is provided. ## Others - Updated `.gitignore` to exclude Visual Studio files. - Revised `README.md` for clarity and added new features. --- .gitignore | 6 ++ README.md | 167 +++++++++++++++++++-------------- tiny11maker.ps1 | 245 ++++++++++++++++++++++++++++++------------------ 3 files changed, 258 insertions(+), 160 deletions(-) create mode 100644 .gitignore diff --git a/.gitignore b/.gitignore new file mode 100644 index 00000000..eff87e7a --- /dev/null +++ b/.gitignore @@ -0,0 +1,6 @@ +################################################################################ +# This .gitignore file was automatically created by Microsoft(R) Visual Studio. +################################################################################ + +/.vs/Tiny11builderDEV/CopilotIndices/17.14.1091.29919 +/.vs diff --git a/README.md b/README.md index f39750bc..c7168835 100644 --- a/README.md +++ b/README.md @@ -1,86 +1,111 @@ -# tiny11builder - -Scripts to build a trimmed-down Windows 11 image - now in **PowerShell**! -
-Tiny11 builder, now completely overhauled. -
-After more than a year (for which I am so sorry) of no updates, tiny11 builder is now a much more complete and flexible solution - one script fits all. Also, it is a steppingstone for an even more fleshed-out solution. -
+# tiny11builder +*Scripts to build a trimmed-down Windows 11 image - now in **PowerShell**!* + +## Introduction : +Tiny11 builder, now completely overhauled.
After more than a year (for which I am so sorry) of no updates, tiny11 builder is now a much more complete and flexible solution - one script fits all. Also, it is a steppingstone for an even more fleshed-out solution. + You can now use it on ANY Windows 11 release (not just a specific build), as well as ANY language or architecture. This is made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release. -
-Since it is written in PowerShell, you need to set the execution policy to `Unrestricted`, so that you could run the script. -If you haven't done this before, make sure to run `Set-ExecutionPolicy unrestricted` as administrator in PowerShell before running the script, otherwise it would just crash. - -This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny11. +This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny10. My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is **oscdimg.exe**, which is provided in the Windows ADK and it is used to create bootable ISO images. Also included is an unattended answer file, which is used to bypass the Microsoft Account on OOBE and to deploy the image with the `/compact` flag. It's open-source, **so feel free to add or remove anything you want!** Feedback is also much appreciated. Also, for the very first time, **introducing tiny11 core builder**! A more powerful script, designed for a quick and dirty development testbed. Just the bare minimun, none of the fluff. -This script generates a significantly reduced Windows 11 image. However, it's not suitable for regular use due to its lack of serviceability - you can't add languages, updates, or features post-creation. tiny11 Core is not a full Windows 11 substitute but a rapid testing or development tool, potentially useful for VM environments. +This script generates a significantly reduced Windows 11 image. However, **it's not suitable for regular use due to its lack of serviceability - you can't add languages, updates, or features post-creation**. tiny11 Core is not a full Windows 11 substitute but a rapid testing or development tool, potentially useful for VM environments. + +--- -Instructions: +## ⚠️ Script versions: +- **tiny11maker.ps1** : The regular script, which removes a lot of bloat but keeps the system serviceable. You can add languages, updates, and features post-creation. This is the recommended script for regular use. +- ⚠️ **tiny11coremaker.ps1** : The core script, which removes even more bloat but also removes the ability to service the image. You cannot add languages, updates, or features post-creation. This is recommended for quick testing or development use. -1. Download Windows 11 from the Microsoft website () +## Instructions: +1. Download Windows 11 from the [Microsoft website](https://www.microsoft.com/software-download/windows11) or [Rufus](https://github.com/pbatard/rufus) 2. Mount the downloaded ISO image using Windows Explorer. -3. Select the drive letter where the image is mounted (only the letter, no colon (:)) -4. Select the SKU that you want the image to be based. -5. Sit back and relax :) -6. When the image is completed, you will see it in the folder where the script was extracted, with the name tiny11.iso - -What is removed: - -- Clipchamp -- News -- Weather -- Xbox (although Xbox Identity provider is still here, so it should be possible to be reinstalled with no issues) -- GetHelp -- GetStarted -- Office Hub -- Solitaire -- PeopleApp -- PowerAutomate -- ToDo -- Alarms -- Mail and Calendar -- Feedback Hub -- Maps -- Sound Recorder -- Your Phone -- Media Player -- QuickAssist -- Internet Explorer -- Tablet PC Math -- Edge -- OneDrive - -For tiny11 core: -- all of the above + -- Windows Component Store (WinSxS) -- Windows Defender (only disabled, can be enabled back if needed) -- Windows Update (Windows Update wouldn't work anyway without WinSxS, so enabling it would only put the system in a state where it would try to update but fail spectacularily) -- WinRE -
-Keep in mind that **you cannot add back features in tiny11 core**! -
-
+3. Open **PowerShell 5.1** as Administrator. +5. Change the script execution policy : +```powershell +Set-ExecutionPolicy Bypass -Scope Process +``` +> Using `-Scope Process` you keep your original policy intact as this change only lasts for the current PowerShell session. + +6. Start the script : +```powershell +C:/path/to/your/tiny11/script.ps1 -ISO -SCRATCH +``` +> You can see of the script by running the `get-help` command. + +6. Select the drive letter where the image is mounted (only the letter, no colon (:)) +7. Select the SKU that you want the image to be based. +8. Sit back and relax :) +9. When the image is completed, you will see it in the folder where the script was extracted, with the name tiny11.iso + +--- + +## What is removed: + + + + + + + + + + + +
Tiny11makerTiny11coremaker
+
    +
  • Clipchamp
  • +
  • News
  • +
  • Weather
  • +
  • Xbox
  • +
  • GetHelp
  • +
  • GetStarted
  • +
  • Office Hub
  • +
  • Solitaire
  • +
  • PeopleApp
  • +
  • PowerAutomate
  • +
  • ToDo
  • +
  • Alarms
  • +
  • Mail and Calendar
  • +
  • Feedback Hub
  • +
  • Maps
  • +
  • Sound Recorder
  • +
  • Your Phone
  • +
  • Media Player
  • +
  • QuickAssist
  • +
  • Internet Explorer
  • +
  • Tablet PC Math
  • +
  • Edge
  • +
  • OneDrive
  • +
+
+
    +
  • all from regular tiny +
  • +
  • Windows Component Store (WinSxS)
  • +
  • Windows Defender (only disabled, can be enabled back if needed)
  • +
  • Windows Update (wouldn't work without WinSxS, enabling it would put the system in a state of failure)
  • +
  • WinRE
  • +
+
+ +Keep in mind that **you cannot add back features in tiny11 core**!
You will be asked during image creation if you want to enable .net 3.5 support! -
-Known issues: - -1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`. -
-Note: You might have to update Winget before being able to install any apps, using Microsoft Store. -
-
-2. Outlook and Dev Home might reappear after some time. -
-
-3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. - -Features to be implemented: + +--- + +## Known issues: +- Although Edge is removed, there are some remnants in the Settings, but the app in itself is deleted. +- You might have to update Winget before being able to install any apps, using Microsoft Store. +- Outlook and Dev Home might reappear after some time. +- If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. + +--- + +## Features to be implemented: - ~~disabling telemetry~~ (Implemented in the 04-29-24 release!) - more ad suppression - improved language and arch detection diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 03dfeddc..217fe692 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -1,19 +1,76 @@ # Enable debugging #Set-PSDebug -Trace 1 +<# +.SYNOPSIS + Scripts to build a trimmed-down Windows 11 image. + +.DESCRIPTION + This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny10. + My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. + The only executable included is oscdimg.exe, which is provided in the Windows ADK and it is used to create bootable ISO images. + +.PARAMETER ISO + Drive letter given to the mounted iso (eg: E) + +.PARAMETER SCRATCH + Drive letter of the desired scratch disk (eg: D) + +.EXAMPLE + .\tiny11maker.ps1 E D + .\tiny11maker.ps1 -ISO E -SCRATCH D + .\tiny11maker.ps1 -SCRATCH D -ISO E + .\tiny11maker.ps1 + + *If you put only the value in parameters the first one must be the iso mounted. The second is the scratch drive. + prefer the use of "-ISO" as you can put in the order you want. + +.NOTES + Auteur: ntdevlabs + Date: 05-06-24 +#> + +#---------[ Parameters ]---------# param ( - [ValidatePattern('^[c-zC-Z]$')] - [string]$ScratchDisk + [ValidatePattern('^[c-zC-Z]$')][string]$ISO, + [ValidatePattern('^[c-zC-Z]$')][string]$SCRATCH ) -if (-not $ScratchDisk) { +if (-not $SCRATCH) { $ScratchDisk = $PSScriptRoot -replace '[\\]+$', '' } else { - $ScratchDisk = $ScratchDisk + ":" + $ScratchDisk = $SCRATCH + ":" } -Write-Output "Scratch disk set to $ScratchDisk" +#---------[ Functions ]---------# +function Set-RegistryValue { + param ( + [string]$path, + [string]$name, + [string]$type, + [string]$value + ) + try { + & 'reg' 'add' $path '/v' $name '/t' $type '/d' $value '/f' | Out-Null + Write-Output "Set registry value: $path\$name" + } catch { + Write-Output "Error setting registry value: $_" + } +} + +function Remove-RegistryValue { + param ( + [string]$path + ) + try { + & 'reg' 'delete' $path '/f' | Out-Null + Write-Output "Removed registry value: $path" + } catch { + Write-Output "Error removing registry value: $_" + } +} +#---------[ Execution ]---------# # Check if PowerShell execution is restricted if ((Get-ExecutionPolicy) -eq 'Restricted') { Write-Host "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" @@ -54,7 +111,11 @@ Write-Host "Welcome to the tiny11 image creator! Release: 05-06-24" $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE New-Item -ItemType Directory -Force -Path "$ScratchDisk\tiny11\sources" | Out-Null do { - $DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" + if (-not $ISO) { + $DriveLetter = Read-Host "Please enter the drive letter for the Windows 11 image" + } else { + $DriveLetter = $ISO + } if ($DriveLetter -match '^[c-zC-Z]$') { $DriveLetter = $DriveLetter + ":" Write-Output "Drive letter set to $DriveLetter" @@ -86,8 +147,11 @@ Write-Host "Copy complete!" Start-Sleep -Seconds 2 Clear-Host Write-Host "Getting image information:" -Get-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim -$index = Read-Host "Please enter the image index" +$ImagesIndex = (Get-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim).ImageIndex +while ($ImagesIndex -notcontains $index) { + Get-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim + $index = Read-Host "Please enter the image index" +} Write-Host "Mounting Windows image. This may take a while." $wimFilePath = "$ScratchDisk\tiny11\sources\install.wim" & takeown "/F" $wimFilePath @@ -192,78 +256,79 @@ reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat | Out-Nul reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE | Out-Null reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM | Out-Null Write-Host "Bypassing system requirements(on the system image):" -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV2' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' 'SV2' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassCPUCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassRAMCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassSecureBootCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassStorageCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassTPMCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\MoSetup' 'AllowUpgradesWithUnsupportedTPMOrCPU' 'REG_DWORD' '1' Write-Host "Disabling Sponsored Apps:" -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f'| Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' | Out-Null -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'OemPreInstalledAppsEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'PreInstalledAppsEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SilentInstalledAppsEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' 'DisableWindowsConsumerFeatures' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'ContentDeliveryAllowed' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' 'ConfigureStartPins' 'REG_SZ' '{"pinnedList": [{}]}' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'ContentDeliveryAllowed' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'ContentDeliveryAllowed' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'FeatureManagementEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'OemPreInstalledAppsEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'PreInstalledAppsEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'PreInstalledAppsEverEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SilentInstalledAppsEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SoftLandingEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContentEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-310093Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-338388Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-338389Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-338393Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-353694Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-353696Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContentEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SystemPaneSuggestionsEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' 'DisablePushToInstall' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' 'DontOfferThroughWUAU' 'REG_DWORD' '1' +Remove-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' +Remove-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' +Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' 'DisableConsumerAccountStateContent' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' 'DisableCloudOptimizedContent' 'REG_DWORD' '1' Write-Host "Enabling Local Accounts on OOBE:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force | Out-Null Write-Host "Disabling Reserved Storage:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' 'ShippedWithReserves' 'REG_DWORD' '0' Write-Host "Disabling BitLocker Device Encryption" -& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Set-RegistryValue 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' 'PreventDeviceEncryption' 'REG_DWORD' '1' Write-Host "Disabling Chat icon:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' 'ChatIcon' 'REG_DWORD' '3' +Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' 'TaskbarMn' 'REG_DWORD' '0' Write-Host "Removing Edge related registries" -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f | Out-Null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f | Out-Null +Remove-RegistryValue "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" +Remove-RegistryValue "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" Write-Host "Disabling OneDrive folder backup" -& 'reg' 'add' "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" '/v' 'DisableFileSyncNGSC' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Set-RegistryValue "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" "DisableFileSyncNGSC" "REG_DWORD" "1" Write-Host "Disabling Telemetry:" -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' | Out-Null +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' 'Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' 'TailoredExperiencesWithDiagnosticDataEnabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' 'HasAccepted' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' 'Enabled' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' 'RestrictImplicitInkCollection' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' 'RestrictImplicitTextCollection' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' 'HarvestContacts' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' 'AcceptedPrivacyPolicy' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' 'AllowTelemetry' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' 'Start' 'REG_DWORD' '4' ## Prevents installation or DevHome and Outlook Write-Host "Prevents installation or DevHome and Outlook:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' '/f' | Out-Null -& 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\DevHomeUpdate' '/f' | Out-Null +Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' 'workCompleted' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' 'workCompleted' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' 'workCompleted' 'REG_DWORD' '1' +Remove-RegistryValue 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' +Remove-RegistryValue 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\DevHomeUpdate' ## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. function Enable-Privilege { @@ -359,18 +424,18 @@ Write-Host "Registry key permissions successfully updated." $regKey.Close() Write-Host 'Deleting Application Compatibility Appraiser' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f | Out-Null +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}' Write-Host 'Deleting Customer Experience Improvement Program' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f | Out-Null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f | Out-Null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f | Out-Null -Write-Host 'Deleting Program Data Updater' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f | Out-Null +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}' +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}' +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}' +Write-Host 'Deleting Program Data Updater' +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}' Write-Host 'Deleting autochk proxy' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f | Out-Null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f | Out-Null +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}' +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}' Write-Host 'Deleting QueueReporting' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f | Out-Null +Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}' Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() @@ -408,16 +473,16 @@ reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM Write-Host "Bypassing system requirements(on the setup image):" -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV2' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' 'SV2' 'REG_DWORD' '0' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassCPUCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassRAMCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassSecureBootCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassStorageCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassTPMCheck' 'REG_DWORD' '1' +Set-RegistryValue 'HKLM\zSYSTEM\Setup\MoSetup' 'AllowUpgradesWithUnsupportedTPMOrCPU' 'REG_DWORD' '1' Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() @@ -472,8 +537,10 @@ Read-Host "Press Enter to continue" Write-Host "Performing Cleanup..." Remove-Item -Path "$ScratchDisk\tiny11" -Recurse -Force | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir" -Recurse -Force | Out-Null +Write-Output "Ejecting Iso drive" +Get-Volume -DriveLetter $DriveLetter[0] | Get-DiskImage | Dismount-DiskImage +Write-Output "Cleanup complete!" # Stop the transcript Stop-Transcript - -exit +exit \ No newline at end of file From 9af52a8206f725f2888e06293241251fadbaec93 Mon Sep 17 00:00:00 2001 From: Miiraak Date: Sun, 31 Aug 2025 12:32:36 +0200 Subject: [PATCH 52/63] Add autounattend.xml download if missing Implement a check for the existence of `autounattend.xml`. If the file is not found, download it from a specified URL using `Invoke-RestMethod` and save it to the script's root directory. This ensures the configuration file is available for the script's execution. --- tiny11maker.ps1 | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 217fe692..2741ffd7 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -99,7 +99,9 @@ if (! $myWindowsPrincipal.IsInRole($adminRole)) exit } - +if (-not (Test-Path -Path "$PSScriptRoot/autounattend.xml")) { + Invoke-RestMethod "https://raw.githubusercontent.com/ntdevlabs/tiny11builder/refs/heads/main/autounattend.xml" -OutFile "$PSScriptRoot/autounattend.xml" +} # Start the transcript and prepare the window Start-Transcript -Path "$ScratchDisk\tiny11.log" From ca2f2dff7efec56c902125080fafe2d64ddbd8f6 Mon Sep 17 00:00:00 2001 From: Old Character <167513064+Miiraak@users.noreply.github.com> Date: Sun, 31 Aug 2025 12:34:09 +0200 Subject: [PATCH 53/63] Delete .gitignore --- .gitignore | 6 ------ 1 file changed, 6 deletions(-) delete mode 100644 .gitignore diff --git a/.gitignore b/.gitignore deleted file mode 100644 index eff87e7a..00000000 --- a/.gitignore +++ /dev/null @@ -1,6 +0,0 @@ -################################################################################ -# This .gitignore file was automatically created by Microsoft(R) Visual Studio. -################################################################################ - -/.vs/Tiny11builderDEV/CopilotIndices/17.14.1091.29919 -/.vs From cc7e53647eed9af81fc4f8267e8ebcb965f57667 Mon Sep 17 00:00:00 2001 From: Miiraak Date: Sun, 31 Aug 2025 14:58:20 +0200 Subject: [PATCH 54/63] Refactor registry removal and enhance cleanup process Updated `tiny11maker.ps1` to replace `Remove-RegistryKey` with `Remove-RegistryValue` for specific registry values. Expanded the cleanup section to include detailed checks and messages for the existence and removal of temporary files and directories, improving script robustness and user feedback. --- tiny11maker.ps1 | 68 ++++++++++++++++++++++++++++++++++++++++++------- 1 file changed, 59 insertions(+), 9 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 2741ffd7..419e1a0f 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -426,18 +426,18 @@ Write-Host "Registry key permissions successfully updated." $regKey.Close() Write-Host 'Deleting Application Compatibility Appraiser' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}' Write-Host 'Deleting Customer Experience Improvement Program' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}' Write-Host 'Deleting Program Data Updater' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}' Write-Host 'Deleting autochk proxy' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}' Write-Host 'Deleting QueueReporting' -Remove-RegistryKey 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}' +Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}' Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." $regKey.Close() @@ -541,7 +541,57 @@ Remove-Item -Path "$ScratchDisk\tiny11" -Recurse -Force | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir" -Recurse -Force | Out-Null Write-Output "Ejecting Iso drive" Get-Volume -DriveLetter $DriveLetter[0] | Get-DiskImage | Dismount-DiskImage -Write-Output "Cleanup complete!" +Write-Output "Iso drive ejected" +Write-Output "Removing oscdimg.exe..." +Remove-Item -Path "$PSScriptRoot\oscdimg.exe" -Force -ErrorAction SilentlyContinue +Write-Output "Removing autounattend.xml..." +Remove-Item -Path "$PSScriptRoot\autounattend.xml" -Force -ErrorAction SilentlyContinue + +Write-Output "Cleanup check :" +if (Test-Path -Path "$ScratchDisk\tiny11") { + Write-Output "tiny11 folder still exists. Attempting to remove it again..." + Remove-Item -Path "$ScratchDisk\tiny11" -Recurse -Force -ErrorAction SilentlyContinue + if (Test-Path -Path "$ScratchDisk\tiny11") { + Write-Output "Failed to remove tiny11 folder." + } else { + Write-Output "tiny11 folder removed successfully." + } +} else { + Write-Output "tiny11 folder does not exist. No action needed." +} +if (Test-Path -Path "$ScratchDisk\scratchdir") { + Write-Output "scratchdir folder still exists. Attempting to remove it again..." + Remove-Item -Path "$ScratchDisk\scratchdir" -Recurse -Force -ErrorAction SilentlyContinue + if (Test-Path -Path "$ScratchDisk\scratchdir") { + Write-Output "Failed to remove scratchdir folder." + } else { + Write-Output "scratchdir folder removed successfully." + } +} else { + Write-Output "scratchdir folder does not exist. No action needed." +} +if (Test-Path -Path "$PSScriptRoot\oscdimg.exe") { + Write-Output "oscdimg.exe still exists. Attempting to remove it again..." + Remove-Item -Path "$PSScriptRoot\oscdimg.exe" -Force -ErrorAction SilentlyContinue + if (Test-Path -Path "$PSScriptRoot\oscdimg.exe") { + Write-Output "Failed to remove oscdimg.exe." + } else { + Write-Output "oscdimg.exe removed successfully." + } +} else { + Write-Output "oscdimg.exe does not exist. No action needed." +} +if (Test-Path -Path "$PSScriptRoot\autounattend.xml") { + Write-Output "autounattend.xml still exists. Attempting to remove it again..." + Remove-Item -Path "$PSScriptRoot\autounattend.xml" -Force -ErrorAction SilentlyContinue + if (Test-Path -Path "$PSScriptRoot\autounattend.xml") { + Write-Output "Failed to remove autounattend.xml." + } else { + Write-Output "autounattend.xml removed successfully." + } +} else { + Write-Output "autounattend.xml does not exist. No action needed." +} # Stop the transcript Stop-Transcript From 35aa44d4e39ff3e0c095b2084f2c8978b9cebbed Mon Sep 17 00:00:00 2001 From: Old Character <167513064+Miiraak@users.noreply.github.com> Date: Sun, 31 Aug 2025 16:56:02 +0200 Subject: [PATCH 55/63] Update PackagesToRemove with new ones - Add new packages in `$packagePrefixes`. - Change disposiition of `$packagePrefixes` to better lisibility. - Modify the `where-object` query param from `-like "$_*"` to `-like "*$_*"` --- tiny11maker.ps1 | 58 ++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 55 insertions(+), 3 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 419e1a0f..bcaa33d7 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -203,11 +203,62 @@ $packages = & 'dism' '/English' "/image:$($ScratchDisk)\scratchdir" '/Get-Provis $matches[1] } } -$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_' + +$packagePrefixes = 'AppUp.IntelManagementandSecurityStatus', +'Clipchamp.Clipchamp', +'DolbyLaboratories.DolbyAccess', +'DolbyLaboratories.DolbyDigitalPlusDecoderOEM', +'Microsoft.BingNews', +'Microsoft.BingSearch', +'Microsoft.BingWeather', +'Microsoft.Copilot', +'Microsoft.Windows.CrossDevice', +'Microsoft.GamingApp', +'Microsoft.GetHelp', +'Microsoft.Getstarted', +'Microsoft.Microsoft3DViewer', +'Microsoft.MicrosoftOfficeHub', +'Microsoft.MicrosoftSolitaireCollection', +'Microsoft.MicrosoftStickyNotes', +'Microsoft.MixedReality.Portal', +'Microsoft.MSPaint', +'Microsoft.Office.OneNote', +'Microsoft.OfficePushNotificationUtility', +'Microsoft.OutlookForWindows', +'Microsoft.Paint', +'Microsoft.People', +'Microsoft.PowerAutomateDesktop', +'Microsoft.SkypeApp', +'Microsoft.StartExperiencesApp', +'Microsoft.Todos', +'Microsoft.Wallet', +'Microsoft.Windows.DevHome', +'Microsoft.WindowsAlarms', +'Microsoft.WindowsCamera', +'microsoft.windowscommunicationsapps', +'Microsoft.WindowsFeedbackHub', +'Microsoft.WindowsMaps', +'Microsoft.WindowsSoundRecorder', +'Microsoft.WindowsTerminal', +'Microsoft.Xbox.TCUI', +'Microsoft.XboxApp', +'Microsoft.XboxGameOverlay', +'Microsoft.XboxGamingOverlay', +'Microsoft.XboxIdentityProvider', +'Microsoft.XboxSpeechToTextOverlay', +'Microsoft.YourPhone', +'Microsoft.ZuneMusic', +'Microsoft.ZuneVideo', +'MicrosoftCorporationII.MicrosoftFamily', +'MicrosoftCorporationII.QuickAssist', +'MSTeams', +'MicrosoftTeams', +'Microsoft.WindowsTerminal', +'Microsoft.549981C3F5F10' $packagesToRemove = $packages | Where-Object { $packageName = $_ - $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "$_*" }) + $packagePrefixes -contains ($packagePrefixes | Where-Object { $packageName -like "*$_*" }) } foreach ($package in $packagesToRemove) { & 'dism' '/English' "/image:$($ScratchDisk)\scratchdir" '/Remove-ProvisionedAppxPackage' "/PackageName:$package" @@ -595,4 +646,5 @@ if (Test-Path -Path "$PSScriptRoot\autounattend.xml") { # Stop the transcript Stop-Transcript -exit \ No newline at end of file + +exit From 13b88eeea7ce3060ccee2c42fd44ade0ab2a4af8 Mon Sep 17 00:00:00 2001 From: Old Character <167513064+Miiraak@users.noreply.github.com> Date: Sun, 31 Aug 2025 18:08:10 +0200 Subject: [PATCH 56/63] Fixes for PSScriptAnalysis report - Fix `PSAvoidTrailingWhitespace` - Fix `PSAvoidUsingWriteHost` - Fix `PSAvoidUsingEmptyCatchBlock` - Fix `PSUseShouldProcessForStateChangingFunctions` > False positive, it does not touch the running system registry. For `PSAvoidUsingPositionalParameters` i can add named parameters but it's not mandatory if positional is repected. --- tiny11maker.ps1 | 154 ++++++++++++++++++++++++------------------------ 1 file changed, 76 insertions(+), 78 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index bcaa33d7..f2fde030 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -3,11 +3,11 @@ <# .SYNOPSIS - Scripts to build a trimmed-down Windows 11 image. + Scripts to build a trimmed-down Windows 11 image. .DESCRIPTION - This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny10. - My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. + This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny10. + My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is oscdimg.exe, which is provided in the Windows ADK and it is used to create bootable ISO images. .PARAMETER ISO @@ -73,12 +73,12 @@ function Remove-RegistryValue { #---------[ Execution ]---------# # Check if PowerShell execution is restricted if ((Get-ExecutionPolicy) -eq 'Restricted') { - Write-Host "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" + Write-Output "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" $response = Read-Host if ($response -eq 'yes') { Set-ExecutionPolicy RemoteSigned -Scope CurrentUser -Confirm:$false } else { - Write-Host "The script cannot be run without changing the execution policy. Exiting..." + Write-Output "The script cannot be run without changing the execution policy. Exiting..." exit } } @@ -91,7 +91,7 @@ $myWindowsPrincipal=new-object System.Security.Principal.WindowsPrincipal($myWin $adminRole=[System.Security.Principal.WindowsBuiltInRole]::Administrator if (! $myWindowsPrincipal.IsInRole($adminRole)) { - Write-Host "Restarting Tiny11 image creator as admin in a new window, you can close this one." + Write-Output "Restarting Tiny11 image creator as admin in a new window, you can close this one." $newProcess = new-object System.Diagnostics.ProcessStartInfo "PowerShell"; $newProcess.Arguments = $myInvocation.MyCommand.Definition; $newProcess.Verb = "runas"; @@ -104,11 +104,11 @@ if (-not (Test-Path -Path "$PSScriptRoot/autounattend.xml")) { } # Start the transcript and prepare the window -Start-Transcript -Path "$ScratchDisk\tiny11.log" +Start-Transcript -Path "$ScratchDisk\tiny11.log" $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host -Write-Host "Welcome to the tiny11 image creator! Release: 05-06-24" +Write-Output "Welcome to the tiny11 image creator! Release: 05-06-24" $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE New-Item -ItemType Directory -Force -Path "$ScratchDisk\tiny11\sources" | Out-Null @@ -128,40 +128,41 @@ do { if ((Test-Path "$DriveLetter\sources\boot.wim") -eq $false -or (Test-Path "$DriveLetter\sources\install.wim") -eq $false) { if ((Test-Path "$DriveLetter\sources\install.esd") -eq $true) { - Write-Host "Found install.esd, converting to install.wim..." + Write-Output "Found install.esd, converting to install.wim..." Get-WindowsImage -ImagePath $DriveLetter\sources\install.esd $index = Read-Host "Please enter the image index" - Write-Host ' ' - Write-Host 'Converting install.esd to install.wim. This may take a while...' + Write-Output ' ' + Write-Output 'Converting install.esd to install.wim. This may take a while...' Export-WindowsImage -SourceImagePath $DriveLetter\sources\install.esd -SourceIndex $index -DestinationImagePath $ScratchDisk\tiny11\sources\install.wim -Compressiontype Maximum -CheckIntegrity } else { - Write-Host "Can't find Windows OS Installation files in the specified Drive Letter.." - Write-Host "Please enter the correct DVD Drive Letter.." + Write-Output "Can't find Windows OS Installation files in the specified Drive Letter.." + Write-Output "Please enter the correct DVD Drive Letter.." exit } } -Write-Host "Copying Windows image..." +Write-Output "Copying Windows image..." Copy-Item -Path "$DriveLetter\*" -Destination "$ScratchDisk\tiny11" -Recurse -Force | Out-Null Set-ItemProperty -Path "$ScratchDisk\tiny11\sources\install.esd" -Name IsReadOnly -Value $false > $null 2>&1 Remove-Item "$ScratchDisk\tiny11\sources\install.esd" > $null 2>&1 -Write-Host "Copy complete!" +Write-Output "Copy complete!" Start-Sleep -Seconds 2 Clear-Host -Write-Host "Getting image information:" +Write-Output "Getting image information:" $ImagesIndex = (Get-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim).ImageIndex while ($ImagesIndex -notcontains $index) { Get-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim $index = Read-Host "Please enter the image index" } -Write-Host "Mounting Windows image. This may take a while." +Write-Output "Mounting Windows image. This may take a while." $wimFilePath = "$ScratchDisk\tiny11\sources\install.wim" -& takeown "/F" $wimFilePath +& takeown "/F" $wimFilePath & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" try { Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -ErrorAction Stop } catch { # This block will catch the error and suppress it. + Write-Error "$wimFilePath not found" } New-Item -ItemType Directory -Force -Path "$ScratchDisk\scratchdir" > $null Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim -Index $index -Path $ScratchDisk\scratchdir @@ -171,9 +172,9 @@ $languageLine = $imageIntl -split '\n' | Where-Object { $_ -match 'Default syste if ($languageLine) { $languageCode = $Matches[1] - Write-Host "Default system UI language code: $languageCode" + Write-Output "Default system UI language code: $languageCode" } else { - Write-Host "Default system UI language code not found." + Write-Output "Default system UI language code not found." } $imageInfo = & 'dism' '/English' '/Get-WimInfo' "/wimFile:$($ScratchDisk)\tiny11\sources\install.wim" "/index:$index" @@ -186,16 +187,16 @@ foreach ($line in $lines) { if ($architecture -eq 'x64') { $architecture = 'amd64' } - Write-Host "Architecture: $architecture" + Write-Output "Architecture: $architecture" break } } if (-not $architecture) { - Write-Host "Architecture information not found." + Write-Output "Architecture information not found." } -Write-Host "Mounting complete! Performing removal of applications..." +Write-Output "Mounting complete! Performing removal of applications..." $packages = & 'dism' '/English' "/image:$($ScratchDisk)\scratchdir" '/Get-ProvisionedAppxPackages' | ForEach-Object { @@ -265,7 +266,7 @@ foreach ($package in $packagesToRemove) { } -Write-Host "Removing Edge:" +Write-Output "Removing Edge:" Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force | Out-Null @@ -277,7 +278,7 @@ if ($architecture -eq 'amd64') { & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null Remove-Item -Path $folderPath -Recurse -Force | Out-Null } else { - Write-Host "Folder not found." + Write-Output "Folder not found." } } elseif ($architecture -eq 'arm64') { $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName | Out-Null @@ -287,28 +288,28 @@ if ($architecture -eq 'amd64') { & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null Remove-Item -Path $folderPath -Recurse -Force | Out-Null } else { - Write-Host "Folder not found." + Write-Output "Folder not found." } } else { - Write-Host "Unknown architecture: $architecture" + Write-Output "Unknown architecture: $architecture" } & 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' | Out-Null & 'icacls' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force | Out-Null -Write-Host "Removing OneDrive:" +Write-Output "Removing OneDrive:" & 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" | Out-Null & 'icacls' "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\OneDriveSetup.exe" -Force | Out-Null -Write-Host "Removal complete!" +Write-Output "Removal complete!" Start-Sleep -Seconds 2 Clear-Host -Write-Host "Loading registry..." +Write-Output "Loading registry..." reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS | Out-Null reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default | Out-Null reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat | Out-Null reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE | Out-Null reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM | Out-Null -Write-Host "Bypassing system requirements(on the system image):" +Write-Output "Bypassing system requirements(on the system image):" Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV2' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' @@ -319,7 +320,7 @@ Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassSecureBootCheck' 'REG_DW Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassStorageCheck' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassTPMCheck' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSYSTEM\Setup\MoSetup' 'AllowUpgradesWithUnsupportedTPMOrCPU' 'REG_DWORD' '1' -Write-Host "Disabling Sponsored Apps:" +Write-Output "Disabling Sponsored Apps:" Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'OemPreInstalledAppsEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'PreInstalledAppsEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SilentInstalledAppsEnabled' 'REG_DWORD' '0' @@ -349,22 +350,22 @@ Remove-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Con Remove-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' 'DisableConsumerAccountStateContent' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' 'DisableCloudOptimizedContent' 'REG_DWORD' '1' -Write-Host "Enabling Local Accounts on OOBE:" +Write-Output "Enabling Local Accounts on OOBE:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force | Out-Null -Write-Host "Disabling Reserved Storage:" +Write-Output "Disabling Reserved Storage:" Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' 'ShippedWithReserves' 'REG_DWORD' '0' -Write-Host "Disabling BitLocker Device Encryption" +Write-Output "Disabling BitLocker Device Encryption" Set-RegistryValue 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' 'PreventDeviceEncryption' 'REG_DWORD' '1' -Write-Host "Disabling Chat icon:" +Write-Output "Disabling Chat icon:" Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' 'ChatIcon' 'REG_DWORD' '3' Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' 'TaskbarMn' 'REG_DWORD' '0' -Write-Host "Removing Edge related registries" +Write-Output "Removing Edge related registries" Remove-RegistryValue "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" Remove-RegistryValue "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" -Write-Host "Disabling OneDrive folder backup" +Write-Output "Disabling OneDrive folder backup" Set-RegistryValue "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" "DisableFileSyncNGSC" "REG_DWORD" "1" -Write-Host "Disabling Telemetry:" +Write-Output "Disabling Telemetry:" Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' 'Enabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' 'TailoredExperiencesWithDiagnosticDataEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' 'HasAccepted' 'REG_DWORD' '0' @@ -376,7 +377,7 @@ Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' 'Ac Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' 'AllowTelemetry' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' 'Start' 'REG_DWORD' '4' ## Prevents installation or DevHome and Outlook -Write-Host "Prevents installation or DevHome and Outlook:" +Write-Output "Prevents installation or DevHome and Outlook:" Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' 'workCompleted' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' 'workCompleted' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' 'workCompleted' 'REG_DWORD' '1' @@ -407,13 +408,11 @@ function Enable-Privilege { $definition = @' using System; using System.Runtime.InteropServices; - public class AdjPriv { [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] internal static extern bool AdjustTokenPrivileges(IntPtr htok, bool disall, - ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); - + ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] internal static extern bool OpenProcessToken(IntPtr h, int acc, ref IntPtr phtok); [DllImport("advapi32.dll", SetLastError = true)] @@ -425,7 +424,6 @@ function Enable-Privilege { public long Luid; public int Attr; } - internal const int SE_PRIVILEGE_ENABLED = 0x00000002; internal const int SE_PRIVILEGE_DISABLED = 0x00000000; internal const int TOKEN_QUERY = 0x00000008; @@ -466,31 +464,31 @@ $regACL = $regKey.GetAccessControl() $regACL.SetOwner($adminGroup) $regKey.SetAccessControl($regACL) $regKey.Close() -Write-Host "Owner changed to Administrators." +Write-Output "Owner changed to Administrators." $regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) $regACL = $regKey.GetAccessControl() $regRule = New-Object System.Security.AccessControl.RegistryAccessRule ($adminGroup,"FullControl","ContainerInherit","None","Allow") $regACL.SetAccessRule($regRule) $regKey.SetAccessControl($regACL) -Write-Host "Permissions modified for Administrators group." -Write-Host "Registry key permissions successfully updated." +Write-Output "Permissions modified for Administrators group." +Write-Output "Registry key permissions successfully updated." $regKey.Close() -Write-Host 'Deleting Application Compatibility Appraiser' +Write-Output 'Deleting Application Compatibility Appraiser' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}' -Write-Host 'Deleting Customer Experience Improvement Program' +Write-Output 'Deleting Customer Experience Improvement Program' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}' -Write-Host 'Deleting Program Data Updater' +Write-Output 'Deleting Program Data Updater' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}' -Write-Host 'Deleting autochk proxy' +Write-Output 'Deleting autochk proxy' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}' -Write-Host 'Deleting QueueReporting' +Write-Output 'Deleting QueueReporting' Remove-RegistryValue 'HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}' -Write-Host "Tweaking complete!" -Write-Host "Unmounting Registry..." +Write-Output "Tweaking complete!" +Write-Output "Unmounting Registry..." $regKey.Close() reg unload HKLM\zCOMPONENTS | Out-Null reg unload HKLM\zDRIVERS | Out-Null @@ -499,33 +497,33 @@ reg unload HKLM\zNTUSER | Out-Null reg unload HKLM\zSCHEMA | Out-Null reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM | Out-Null -Write-Host "Cleaning up image..." +Write-Output "Cleaning up image..." Repair-WindowsImage -Path $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase -Write-Host "Cleanup complete." -Write-Host ' ' -Write-Host "Unmounting image..." +Write-Output "Cleanup complete." +Write-Output ' ' +Write-Output "Unmounting image..." Dismount-WindowsImage -Path $ScratchDisk\scratchdir -Save -Write-Host "Exporting image..." +Write-Output "Exporting image..." # Compressiontype Recovery is not supported with PShell https://learn.microsoft.com/en-us/powershell/module/dism/export-windowsimage?view=windowsserver2022-ps#-compressiontype Export-WindowsImage -SourceImagePath $ScratchDisk\tiny11\sources\install.wim -SourceIndex $index -DestinationImagePath $ScratchDisk\tiny11\sources\install2.wim -CompressionType Fast Remove-Item -Path "$ScratchDisk\tiny11\sources\install.wim" -Force | Out-Null Rename-Item -Path "$ScratchDisk\tiny11\sources\install2.wim" -NewName "install.wim" | Out-Null -Write-Host "Windows image completed. Continuing with boot.wim." +Write-Output "Windows image completed. Continuing with boot.wim." Start-Sleep -Seconds 2 Clear-Host -Write-Host "Mounting boot image:" -$wimFilePath = "$ScratchDisk\tiny11\sources\boot.wim" +Write-Output "Mounting boot image:" +$wimFilePath = "$ScratchDisk\tiny11\sources\boot.wim" & takeown "/F" $wimFilePath | Out-Null & icacls $wimFilePath "/grant" "$($adminGroup.Value):(F)" Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\boot.wim -Index 2 -Path $ScratchDisk\scratchdir -Write-Host "Loading registry..." +Write-Output "Loading registry..." reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM -Write-Host "Bypassing system requirements(on the setup image):" +Write-Output "Bypassing system requirements(on the setup image):" Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' 'SV2' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' 'SV1' 'REG_DWORD' '0' @@ -536,8 +534,8 @@ Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassSecureBootCheck' 'REG_DW Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassStorageCheck' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSYSTEM\Setup\LabConfig' 'BypassTPMCheck' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSYSTEM\Setup\MoSetup' 'AllowUpgradesWithUnsupportedTPMOrCPU' 'REG_DWORD' '1' -Write-Host "Tweaking complete!" -Write-Host "Unmounting Registry..." +Write-Output "Tweaking complete!" +Write-Output "Unmounting Registry..." $regKey.Close() reg unload HKLM\zCOMPONENTS | Out-Null reg unload HKLM\zDRIVERS | Out-Null @@ -547,36 +545,35 @@ reg unload HKLM\zSCHEMA | Out-Null $regKey.Close() reg unload HKLM\zSOFTWARE reg unload HKLM\zSYSTEM | Out-Null -Write-Host "Unmounting image..." +Write-Output "Unmounting image..." Dismount-WindowsImage -Path $ScratchDisk\scratchdir -Save Clear-Host -Write-Host "The tiny11 image is now completed. Proceeding with the making of the ISO..." -Write-Host "Copying unattended file for bypassing MS account on OOBE..." +Write-Output "The tiny11 image is now completed. Proceeding with the making of the ISO..." +Write-Output "Copying unattended file for bypassing MS account on OOBE..." Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\tiny11\autounattend.xml" -Force | Out-Null -Write-Host "Creating ISO image..." +Write-Output "Creating ISO image..." $ADKDepTools = "C:\Program Files (x86)\Windows Kits\10\Assessment and Deployment Kit\Deployment Tools\$hostarchitecture\Oscdimg" $localOSCDIMGPath = "$PSScriptRoot\oscdimg.exe" if ([System.IO.Directory]::Exists($ADKDepTools)) { - Write-Host "Will be using oscdimg.exe from system ADK." + Write-Output "Will be using oscdimg.exe from system ADK." $OSCDIMG = "$ADKDepTools\oscdimg.exe" } else { - Write-Host "ADK folder not found. Will be using bundled oscdimg.exe." - + Write-Output "ADK folder not found. Will be using bundled oscdimg.exe." $url = "https://msdl.microsoft.com/download/symbols/oscdimg.exe/3D44737265000/oscdimg.exe" if (-not (Test-Path -Path $localOSCDIMGPath)) { - Write-Host "Downloading oscdimg.exe..." + Write-Output "Downloading oscdimg.exe..." Invoke-WebRequest -Uri $url -OutFile $localOSCDIMGPath if (Test-Path $localOSCDIMGPath) { - Write-Host "oscdimg.exe downloaded successfully." + Write-Output "oscdimg.exe downloaded successfully." } else { Write-Error "Failed to download oscdimg.exe." exit 1 } } else { - Write-Host "oscdimg.exe already exists locally." + Write-Output "oscdimg.exe already exists locally." } $OSCDIMG = $localOSCDIMGPath @@ -585,9 +582,9 @@ if ([System.IO.Directory]::Exists($ADKDepTools)) { & "$OSCDIMG" '-m' '-o' '-u2' '-udfver102' "-bootdata:2#p0,e,b$ScratchDisk\tiny11\boot\etfsboot.com#pEF,e,b$ScratchDisk\tiny11\efi\microsoft\boot\efisys.bin" "$ScratchDisk\tiny11" "$PSScriptRoot\tiny11.iso" # Finishing up -Write-Host "Creation completed! Press any key to exit the script..." +Write-Output "Creation completed! Press any key to exit the script..." Read-Host "Press Enter to continue" -Write-Host "Performing Cleanup..." +Write-Output "Performing Cleanup..." Remove-Item -Path "$ScratchDisk\tiny11" -Recurse -Force | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir" -Recurse -Force | Out-Null Write-Output "Ejecting Iso drive" @@ -648,3 +645,4 @@ if (Test-Path -Path "$PSScriptRoot\autounattend.xml") { Stop-Transcript exit + From 6584d2f432b3acf83fc40bfc64da60b453eb9f09 Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 6 Sep 2025 00:24:22 +0300 Subject: [PATCH 57/63] September 2025 release Features Added removal of Copilot, the new Outlook client, and Microsoft Teams packages. Added registry keys to proactively disable Copilot and prevent app re-installations. Improvements Switched to Dism.exe with /Compress:recovery for significantly smaller final ISO file sizes. Reworked scheduled task removal to be simpler and more reliable. --- tiny11Coremaker.ps1 | 395 +++++++++++--------------------------------- tiny11maker.ps1 | 183 ++++---------------- 2 files changed, 128 insertions(+), 450 deletions(-) diff --git a/tiny11Coremaker.ps1 b/tiny11Coremaker.ps1 index 18b94909..439768ab 100644 --- a/tiny11Coremaker.ps1 +++ b/tiny11Coremaker.ps1 @@ -1,7 +1,3 @@ -# Enable debugging -Set-PSDebug -Trace 1 - -# Check if PowerShell execution is restricted if ((Get-ExecutionPolicy) -eq 'Restricted') { Write-Host "Your current PowerShell Execution Policy is set to Restricted, which prevents scripts from running. Do you want to change it to RemoteSigned? (yes/no)" $response = Read-Host @@ -30,7 +26,7 @@ if (! $myWindowsPrincipal.IsInRole($adminRole)) } Start-Transcript -Path "$PSScriptRoot\tiny11.log" # Ask the user for input -Write-Host "Welcome to tiny11 core builder! BETA 05-06-24" +Write-Host "Welcome to tiny11 core builder! BETA 09-05-25" Write-Host "This script generates a significantly reduced Windows 11 image. However, it's not suitable for regular use due to its lack of serviceability - you can't add languages, updates, or features post-creation. tiny11 Core is not a full Windows 11 substitute but a rapid testing or development tool, potentially useful for VM environments." Write-Host "Do you want to continue? (y/n)" $input = Read-Host @@ -120,7 +116,7 @@ $packages = & 'dism' '/English' "/image:$($env:SystemDrive)\scratchdir" '/Get-Pr $matches[1] } } -$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.SecHealthUI_', 'Microsoft.Windows.PeopleExperienceHost_', 'Microsoft.Windows.PinningConfirmationDialog_', 'Windows.CBSPreview_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_' +$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_', 'Microsoft.Windows.Copilot', 'MSTeams_', 'Microsoft.OutlookForWindows_', 'Microsoft.Windows.Teams_', 'Microsoft.Copilot_' $packagesToRemove = $packages | Where-Object { $packageName = $_ @@ -169,22 +165,18 @@ foreach ($packagePattern in $packagePatterns) { } } -Write-Host "Do you want to enable .NET 3.5? (y/n)" +Write-Host "Do you want to enable .NET 3.5? This cannot be done after the image has been created! (y/n)" $input = Read-Host -# Check the user's input if ($input -eq 'y') { - # If the user entered 'y', enable .NET 3.5 using DISM Write-Host "Enabling .NET 3.5..." & 'dism' "/image:$scratchDir" '/enable-feature' '/featurename:NetFX3' '/All' "/source:$($env:SystemDrive)\tiny11\sources\sxs" Write-Host ".NET 3.5 has been enabled." } elseif ($input -eq 'n') { - # If the user entered 'n', exit the script Write-Host "You chose not to enable .NET 3.5. Continuing..." } else { - # If the user entered anything other than 'y' or 'n', ask for input again Write-Host "Invalid input. Please enter 'y' to enable .NET 3.5 or 'n' to continue without installing .net 3.5." } Write-Host "Removing Edge:" @@ -241,7 +233,6 @@ $sourceDirectory = "$mainOSDrive\scratchdir\Windows\WinSxS" $destinationDirectory = "$mainOSDrive\scratchdir\Windows\WinSxS_edit" New-Item -Path $folderPath -ItemType Directory if ($architecture -eq "amd64") { - # Specify the list of files to copy $dirsToCopy = @( "x86_microsoft.windows.common-controls_6595b64144ccf1df_*", "x86_microsoft.windows.gdiplus_6595b64144ccf1df_*", @@ -341,195 +332,111 @@ Rename-Item -Path $mainOSDrive\scratchdir\Windows\WinSxS_edit -NewName $mainOSDr Write-Host "Complete!" Write-Host "Loading registry..." -reg load HKLM\zCOMPONENTS $mainOSDrive\scratchdir\Windows\System32\config\COMPONENTS >null -reg load HKLM\zDEFAULT $mainOSDrive\scratchdir\Windows\System32\config\default >null -reg load HKLM\zNTUSER $mainOSDrive\scratchdir\Users\Default\ntuser.dat >null -reg load HKLM\zSOFTWARE $mainOSDrive\scratchdir\Windows\System32\config\SOFTWARE >null -reg load HKLM\zSYSTEM $mainOSDrive\scratchdir\Windows\System32\config\SYSTEM >null +reg load HKLM\zCOMPONENTS $ScratchDisk\scratchdir\Windows\System32\config\COMPONENTS | Out-Null +reg load HKLM\zDEFAULT $ScratchDisk\scratchdir\Windows\System32\config\default | Out-Null +reg load HKLM\zNTUSER $ScratchDisk\scratchdir\Users\Default\ntuser.dat | Out-Null +reg load HKLM\zSOFTWARE $ScratchDisk\scratchdir\Windows\System32\config\SOFTWARE | Out-Null +reg load HKLM\zSYSTEM $ScratchDisk\scratchdir\Windows\System32\config\SYSTEM | Out-Null Write-Host "Bypassing system requirements(on the system image):" -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zDEFAULT\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV1' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Control Panel\UnsupportedHardwareNotificationCache' '/v' 'SV2' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassCPUCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassRAMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassSecureBootCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassStorageCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\LabConfig' '/v' 'BypassTPMCheck' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Disabling Sponsored Apps:" -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f'>null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' >null -& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableWindowsConsumerFeatures' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' '/v' 'ConfigureStartPins' '/t' 'REG_SZ' '/d' '{"pinnedList": [{}]}' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'ContentDeliveryAllowed' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'FeatureManagementEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'OemPreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'PreInstalledAppsEverEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SilentInstalledAppsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SoftLandingEnabled' '/t' 'REG_DWORD' '/d' '0' '/f'| Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-310093Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338388Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338389Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-338393Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353694Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContent-353696Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SubscribedContentEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' '/v' 'SystemPaneSuggestionsEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' '/v' 'DisablePushToInstall' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' '/v' 'DontOfferThroughWUAU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\Subscriptions' '/f' | Out-Null +& 'reg' 'delete' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager\SuggestedApps' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableConsumerAccountStateContent' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' '/v' 'DisableCloudOptimizedContent' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Enabling Local Accounts on OOBE:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'BypassNRO' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Copy-Item -Path "$PSScriptRoot\autounattend.xml" -Destination "$ScratchDisk\scratchdir\Windows\System32\Sysprep\autounattend.xml" -Force | Out-Null Write-Host "Disabling Reserved Storage:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' >null +& 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\ReserveManager' '/v' 'ShippedWithReserves' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null Write-Host "Disabling BitLocker Device Encryption" -& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' >null +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Control\BitLocker' '/v' 'PreventDeviceEncryption' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Disabling Chat icon:" -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' -Write-Host "Disabling Telemetry:" -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' -& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' -& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' -Write-Host "Disabling OneDrive folder backup" -& 'reg' 'add' "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" '/v' 'DisableFileSyncNGSC' '/t' 'REG_DWORD' '/d' '1' '/f' +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Chat' '/v' 'ChatIcon' '/t' 'REG_DWORD' '/d' '3' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced' '/v' 'TaskbarMn' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null Write-Host "Removing Edge related registries" -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f -Write-Host "Disabling bing in Start Menu:" -& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'ShowRunAsDifferentUserInStart' '/t' 'REG_DWORD' '/d' '1' '/f' -& 'reg' 'add' 'HKLM\zNTUSER\Software\Policies\Microsoft\Windows\Explorer' '/v' 'DisableSearchBoxSuggestions' '/t' 'REG_DWORD' '/d' '1' '/f' -## Prevents installation or DevHome and Outlook +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge" /f | Out-Null +reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Microsoft Edge Update" /f | Out-Null +Write-Host "Disabling OneDrive folder backup" +& 'reg' 'add' "HKLM\zSOFTWARE\Policies\Microsoft\Windows\OneDrive" '/v' 'DisableFileSyncNGSC' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Write-Host "Disabling Telemetry:" +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\AdvertisingInfo' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Privacy' '/v' 'TailoredExperiencesWithDiagnosticDataEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Speech_OneCore\Settings\OnlineSpeechPrivacy' '/v' 'HasAccepted' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Input\TIPC' '/v' 'Enabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitInkCollection' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization' '/v' 'RestrictImplicitTextCollection' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedDataStore' '/v' 'HarvestContacts' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' | Out-Null Write-Host "Prevents installation or DevHome and Outlook:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null & 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' '/f' | Out-Null & 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\DevHomeUpdate' '/f' | Out-Null -## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. -function Enable-Privilege { - param( - [ValidateSet( - "SeAssignPrimaryTokenPrivilege", "SeAuditPrivilege", "SeBackupPrivilege", - "SeChangeNotifyPrivilege", "SeCreateGlobalPrivilege", "SeCreatePagefilePrivilege", - "SeCreatePermanentPrivilege", "SeCreateSymbolicLinkPrivilege", "SeCreateTokenPrivilege", - "SeDebugPrivilege", "SeEnableDelegationPrivilege", "SeImpersonatePrivilege", "SeIncreaseBasePriorityPrivilege", - "SeIncreaseQuotaPrivilege", "SeIncreaseWorkingSetPrivilege", "SeLoadDriverPrivilege", - "SeLockMemoryPrivilege", "SeMachineAccountPrivilege", "SeManageVolumePrivilege", - "SeProfileSingleProcessPrivilege", "SeRelabelPrivilege", "SeRemoteShutdownPrivilege", - "SeRestorePrivilege", "SeSecurityPrivilege", "SeShutdownPrivilege", "SeSyncAgentPrivilege", - "SeSystemEnvironmentPrivilege", "SeSystemProfilePrivilege", "SeSystemtimePrivilege", - "SeTakeOwnershipPrivilege", "SeTcbPrivilege", "SeTimeZonePrivilege", "SeTrustedCredManAccessPrivilege", - "SeUndockPrivilege", "SeUnsolicitedInputPrivilege")] - $Privilege, - ## The process on which to adjust the privilege. Defaults to the current process. - $ProcessId = $pid, - ## Switch to disable the privilege, rather than enable it. - [Switch] $Disable - ) - $definition = @' - using System; - using System.Runtime.InteropServices; - - public class AdjPriv - { - [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] - internal static extern bool AdjustTokenPrivileges(IntPtr htok, bool disall, - ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); - - [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] - internal static extern bool OpenProcessToken(IntPtr h, int acc, ref IntPtr phtok); - [DllImport("advapi32.dll", SetLastError = true)] - internal static extern bool LookupPrivilegeValue(string host, string name, ref long pluid); - [StructLayout(LayoutKind.Sequential, Pack = 1)] - internal struct TokPriv1Luid - { - public int Count; - public long Luid; - public int Attr; - } - - internal const int SE_PRIVILEGE_ENABLED = 0x00000002; - internal const int SE_PRIVILEGE_DISABLED = 0x00000000; - internal const int TOKEN_QUERY = 0x00000008; - internal const int TOKEN_ADJUST_PRIVILEGES = 0x00000020; - public static bool EnablePrivilege(long processHandle, string privilege, bool disable) - { - bool retVal; - TokPriv1Luid tp; - IntPtr hproc = new IntPtr(processHandle); - IntPtr htok = IntPtr.Zero; - retVal = OpenProcessToken(hproc, TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, ref htok); - tp.Count = 1; - tp.Luid = 0; - if(disable) - { - tp.Attr = SE_PRIVILEGE_DISABLED; - } - else - { - tp.Attr = SE_PRIVILEGE_ENABLED; - } - retVal = LookupPrivilegeValue(null, privilege, ref tp.Luid); - retVal = AdjustTokenPrivileges(htok, false, ref tp, 0, IntPtr.Zero, IntPtr.Zero); - return retVal; - } - } -'@ - - $processHandle = (Get-Process -id $ProcessId).Handle - $type = Add-Type $definition -PassThru - $type[0]::EnablePrivilege($processHandle, $Privilege, $Disable) -} +Write-Host "Disabling Copilot" +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsCopilot' '/v' 'TurnOffWindowsCopilot' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Edge' '/v' 'HubsSidebarEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Explorer' '/v' 'DisableSearchBoxSuggestions' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Write-Host "Prevents installation of Teams:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Teams' '/v' 'DisableInstallation' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Write-Host "Prevent installation of New Outlook": +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Mail' '/v' 'PreventRun' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +$tasksPath = "C:\scratchdir\Windows\System32\Tasks" + +Write-Host "Deleting scheduled task definition files..." + +# Application Compatibility Appraiser +Remove-Item -Path "$tasksPath\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" -Force -ErrorAction SilentlyContinue + +# Customer Experience Improvement Program (removes the entire folder and all tasks within it) +Remove-Item -Path "$tasksPath\Microsoft\Windows\Customer Experience Improvement Program" -Recurse -Force -ErrorAction SilentlyContinue -Enable-Privilege SeTakeOwnershipPrivilege - -$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::TakeOwnership) -$regACL = $regKey.GetAccessControl() -$regACL.SetOwner($adminGroup) -$regKey.SetAccessControl($regACL) -$regKey.Close() -Write-Host "Owner changed to Administrators." -$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) -$regACL = $regKey.GetAccessControl() -$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ($adminGroup,"FullControl","ContainerInherit","None","Allow") -$regACL.SetAccessRule($regRule) -$regKey.SetAccessControl($regACL) -Write-Host "Permissions modified for Administrators group." -Write-Host "Registry key permissions successfully updated." -$regKey.Close() - -Write-Host 'Deleting Application Compatibility Appraiser' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f -Write-Host 'Deleting Customer Experience Improvement Program' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f -Write-Host 'Deleting Program Data Updater' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f -Write-Host 'Deleting autochk proxy' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f -Write-Host 'Deleting QueueReporting' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f +# Program Data Updater +Remove-Item -Path "$tasksPath\Microsoft\Windows\Application Experience\ProgramDataUpdater" -Force -ErrorAction SilentlyContinue + +# Chkdsk Proxy +Remove-Item -Path "$tasksPath\Microsoft\Windows\Chkdsk\Proxy" -Force -ErrorAction SilentlyContinue + +# Windows Error Reporting (QueueReporting) +Remove-Item -Path "$tasksPath\Microsoft\Windows\Windows Error Reporting\QueueReporting" -Force -ErrorAction SilentlyContinue + +Write-Host "Task files have been deleted." Write-Host "Disabling Windows Update..." & 'reg' 'add' "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" '/v' 'StopWUPostOOBE1' '/t' 'REG_SZ' '/d' 'net stop wuauserv' '/f' & 'reg' 'add' "HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce" '/v' 'StopWUPostOOBE2' '/t' 'REG_SZ' '/d' 'sc stop wuauserv' '/f' @@ -544,113 +451,6 @@ Write-Host "Disabling Windows Update..." & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU' '/v' 'UseWUServer' '/t' 'REG_DWORD' '/d' '1' '/f' & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\OOBE' '/v' 'DisableOnline' '/t' 'REG_DWORD' '/d' '1' '/f' & 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\wuauserv' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' -function Disable-Privilege { - param( - [ValidateSet( - "SeAssignPrimaryTokenPrivilege", "SeAuditPrivilege", "SeBackupPrivilege", - "SeChangeNotifyPrivilege", "SeCreateGlobalPrivilege", "SeCreatePagefilePrivilege", - "SeCreatePermanentPrivilege", "SeCreateSymbolicLinkPrivilege", "SeCreateTokenPrivilege", - "SeDebugPrivilege", "SeEnableDelegationPrivilege", "SeImpersonatePrivilege", "SeIncreaseBasePriorityPrivilege", - "SeIncreaseQuotaPrivilege", "SeIncreaseWorkingSetPrivilege", "SeLoadDriverPrivilege", - "SeLockMemoryPrivilege", "SeMachineAccountPrivilege", "SeManageVolumePrivilege", - "SeProfileSingleProcessPrivilege", "SeRelabelPrivilege", "SeRemoteShutdownPrivilege", - "SeRestorePrivilege", "SeSecurityPrivilege", "SeShutdownPrivilege", "SeSyncAgentPrivilege", - "SeSystemEnvironmentPrivilege", "SeSystemProfilePrivilege", "SeSystemtimePrivilege", - "SeTakeOwnershipPrivilege", "SeTcbPrivilege", "SeTimeZonePrivilege", "SeTrustedCredManAccessPrivilege", - "SeUndockPrivilege", "SeUnsolicitedInputPrivilege")] - $Privilege, - ## The process on which to adjust the privilege. Defaults to the current process. - $ProcessId = $pid, - ## Switch to disable the privilege, rather than enable it. - [Switch] $Disable - ) - $definition = @' - using System; - using System.Runtime.InteropServices; - - public class AdjPriv - { - [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] - internal static extern bool AdjustTokenPrivileges(IntPtr htok, bool disall, - ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); - - [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] - internal static extern bool OpenProcessToken(IntPtr h, int acc, ref IntPtr phtok); - [DllImport("advapi32.dll", SetLastError = true)] - internal static extern bool LookupPrivilegeValue(string host, string name, ref long pluid); - [StructLayout(LayoutKind.Sequential, Pack = 1)] - internal struct TokPriv1Luid - { - public int Count; - public long Luid; - public int Attr; - } - - internal const int SE_PRIVILEGE_ENABLED = 0x00000002; - internal const int SE_PRIVILEGE_DISABLED = 0x00000000; - internal const int TOKEN_QUERY = 0x00000008; - internal const int TOKEN_ADJUST_PRIVILEGES = 0x00000020; - public static bool EnablePrivilege(long processHandle, string privilege, bool disable) - { - bool retVal; - TokPriv1Luid tp; - IntPtr hproc = new IntPtr(processHandle); - IntPtr htok = IntPtr.Zero; - retVal = OpenProcessToken(hproc, TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, ref htok); - tp.Count = 1; - tp.Luid = 0; - if(disable) - { - tp.Attr = SE_PRIVILEGE_DISABLED; - } - else - { - tp.Attr = SE_PRIVILEGE_ENABLED; - } - retVal = LookupPrivilegeValue(null, privilege, ref tp.Luid); - retVal = AdjustTokenPrivileges(htok, false, ref tp, 0, IntPtr.Zero, IntPtr.Zero); - return retVal; - } - } -'@ - - $processHandle = (Get-Process -id $ProcessId).Handle - $type = Add-Type $definition -PassThru - $type[0]::EnablePrivilege($processHandle, $Privilege, $Disable) -} - -Disable-Privilege SeTakeOwnershipPrivilege -$everyone = New-Object System.Security.Principal.NTAccount('Everyone') -$accessRule = New-Object System.Security.AccessControl.RegistryAccessRule($everyone, 'ReadKey', 'Allow') -$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSYSTEM\ControlSet001\Services\wuauserv",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::TakeOwnership) -$regACL = $regKey.GetAccessControl() -$regACL.SetOwner($everyone) -$regKey.Close() -Write-Host "Owner changed to Everyone." -$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSYSTEM\ControlSet001\Services\wuauserv",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) -$regACL = $regKey.GetAccessControl() -$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ($everyone, 'ReadKey', 'Allow') -$regACL.SetAccessRule($regRule) -$regKey.SetAccessControl($regACL) -Write-Host "Permissions modified for Everyone group." -Write-Host "Registry key permissions successfully updated." - - -Write-Host "All users have been granted read-only access to the registry key." -$regKey.Close() -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2540477E-E654-4302-AD44-383BBFFBFF16}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{341B2255-6A6B-442A-AF5A-C610B7DBE12D}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{476E8CFA-78E2-4C51-854E-538F8643B4FD}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{764DDB74-CB08-4E0A-8580-B41F94F2C7BE}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{817CCFDD-4DD0-4102-AC6E-3F5D3B789FB8}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99CEDA8C-A866-4787-BBD3-6F3C9F61DD5C}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9B3CDCDA-4197-490B-AA5C-C9F5F42A9D88}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9CBBFAAE-DB9F-48B4-BAC0-4CFF482A4E01}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A31197EC-EAEE-4837-8A9C-3A17D358B9EB}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B4FBEFA9-6F7C-4C74-A891-3774B7BCD072}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B53BD60A-5823-411C-9C75-AA91DB3C35F8}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CECDC345-7460-4A15-9D8B-DAC3F9CC5368}" '/f' -& 'reg' 'delete' "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E0F10DCF-44AD-40E8-9370-FB5DA59F93FB}" '/f' & 'reg' 'delete' 'HKLM\zSYSTEM\ControlSet001\Services\WaaSMedicSVC' '/f' & 'reg' 'delete' 'HKLM\zSYSTEM\ControlSet001\Services\UsoSvc' '/f' & 'reg' 'add' 'HKEY_LOCAL_MACHINE\zSOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU' '/v' 'NoAutoUpdate' '/t' 'REG_DWORD' '/d' '1' '/f' @@ -670,7 +470,6 @@ foreach ($path in $servicePaths) { & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer' '/v' 'SettingsPageVisibility' '/t' 'REG_SZ' '/d' 'hide:virus;windowsupdate' '/f' Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." -$regKey.Close() reg unload HKLM\zCOMPONENTS >null reg unload HKLM\zDEFAULT >null reg unload HKLM\zNTUSER >null @@ -715,12 +514,10 @@ Write-Host "Bypassing system requirements(on the setup image):" & 'reg' 'add' 'HKEY_LOCAL_MACHINE\zSYSTEM\Setup' '/v' 'CmdLine' '/t' 'REG_SZ' '/d' 'X:\sources\setup.exe' '/f' >null Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." -$regKey.Close() reg unload HKLM\zCOMPONENTS >null reg unload HKLM\zDEFAULT >null reg unload HKLM\zNTUSER >null -$regKey.Close() -reg unload HKLM\zSOFTWARE +reg unload HKLM\zSOFTWARE >null reg unload HKLM\zSYSTEM >null Write-Host "Unmounting image..." & 'dism' '/English' '/unmount-image' "/mountdir:$mainOSDrive\scratchdir" '/commit' diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 03dfeddc..310f2159 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -1,6 +1,3 @@ -# Enable debugging -#Set-PSDebug -Trace 1 - param ( [ValidatePattern('^[c-zC-Z]$')] [string]$ScratchDisk @@ -41,15 +38,11 @@ if (! $myWindowsPrincipal.IsInRole($adminRole)) [System.Diagnostics.Process]::Start($newProcess); exit } - - - -# Start the transcript and prepare the window Start-Transcript -Path "$ScratchDisk\tiny11.log" $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host -Write-Host "Welcome to the tiny11 image creator! Release: 05-06-24" +Write-Host "Welcome to the tiny11 image creator! Release: 09-04-25" $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE New-Item -ItemType Directory -Force -Path "$ScratchDisk\tiny11\sources" | Out-Null @@ -95,7 +88,7 @@ $wimFilePath = "$ScratchDisk\tiny11\sources\install.wim" try { Set-ItemProperty -Path $wimFilePath -Name IsReadOnly -Value $false -ErrorAction Stop } catch { - # This block will catch the error and suppress it. + } New-Item -ItemType Directory -Force -Path "$ScratchDisk\scratchdir" > $null Mount-WindowsImage -ImagePath $ScratchDisk\tiny11\sources\install.wim -Index $index -Path $ScratchDisk\scratchdir @@ -137,7 +130,7 @@ $packages = & 'dism' '/English' "/image:$($ScratchDisk)\scratchdir" '/Get-Provis $matches[1] } } -$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_' +$packagePrefixes = 'Clipchamp.Clipchamp_', 'Microsoft.BingNews_', 'Microsoft.BingWeather_', 'Microsoft.GamingApp_', 'Microsoft.GetHelp_', 'Microsoft.Getstarted_', 'Microsoft.MicrosoftOfficeHub_', 'Microsoft.MicrosoftSolitaireCollection_', 'Microsoft.People_', 'Microsoft.PowerAutomateDesktop_', 'Microsoft.Todos_', 'Microsoft.WindowsAlarms_', 'microsoft.windowscommunicationsapps_', 'Microsoft.WindowsFeedbackHub_', 'Microsoft.WindowsMaps_', 'Microsoft.WindowsSoundRecorder_', 'Microsoft.Xbox.TCUI_', 'Microsoft.XboxGamingOverlay_', 'Microsoft.XboxGameOverlay_', 'Microsoft.XboxSpeechToTextOverlay_', 'Microsoft.YourPhone_', 'Microsoft.ZuneMusic_', 'Microsoft.ZuneVideo_', 'MicrosoftCorporationII.MicrosoftFamily_', 'MicrosoftCorporationII.QuickAssist_', 'MicrosoftTeams_', 'Microsoft.549981C3F5F10_', 'Microsoft.Windows.Copilot', 'MSTeams_', 'Microsoft.OutlookForWindows_', 'Microsoft.Windows.Teams_', 'Microsoft.Copilot_' $packagesToRemove = $packages | Where-Object { $packageName = $_ @@ -152,29 +145,6 @@ Write-Host "Removing Edge:" Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\Edge" -Recurse -Force | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeUpdate" -Recurse -Force | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir\Program Files (x86)\Microsoft\EdgeCore" -Recurse -Force | Out-Null -if ($architecture -eq 'amd64') { - $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "amd64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName - - if ($folderPath) { - & 'takeown' '/f' $folderPath '/r' | Out-Null - & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null - Remove-Item -Path $folderPath -Recurse -Force | Out-Null - } else { - Write-Host "Folder not found." - } -} elseif ($architecture -eq 'arm64') { - $folderPath = Get-ChildItem -Path "$ScratchDisk\scratchdir\Windows\WinSxS" -Filter "arm64_microsoft-edge-webview_31bf3856ad364e35*" -Directory | Select-Object -ExpandProperty FullName | Out-Null - - if ($folderPath) { - & 'takeown' '/f' $folderPath '/r'| Out-Null - & icacls $folderPath "/grant" "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null - Remove-Item -Path $folderPath -Recurse -Force | Out-Null - } else { - Write-Host "Folder not found." - } -} else { - Write-Host "Unknown architecture: $architecture" -} & 'takeown' '/f' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/r' | Out-Null & 'icacls' "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" '/grant' "$($adminGroup.Value):(F)" '/T' '/C' | Out-Null Remove-Item -Path "$ScratchDisk\scratchdir\Windows\System32\Microsoft-Edge-Webview" -Recurse -Force | Out-Null @@ -258,128 +228,44 @@ Write-Host "Disabling Telemetry:" & 'reg' 'add' 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' '/v' 'AcceptedPrivacyPolicy' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null & 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' '/v' 'AllowTelemetry' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null & 'reg' 'add' 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' '/v' 'Start' '/t' 'REG_DWORD' '/d' '4' '/f' | Out-Null -## Prevents installation or DevHome and Outlook Write-Host "Prevents installation or DevHome and Outlook:" & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null & 'reg' 'add' 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' '/v' 'workCompleted' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null & 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' '/f' | Out-Null & 'reg' 'delete' 'HKLM\zSOFTWARE\Microsoft\WindowsUpdate\Orchestrator\UScheduler_Oobe\DevHomeUpdate' '/f' | Out-Null +Write-Host "Disabling Copilot" +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\WindowsCopilot' '/v' 'TurnOffWindowsCopilot' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Edge' '/v' 'HubsSidebarEnabled' '/t' 'REG_DWORD' '/d' '0' '/f' | Out-Null +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Explorer' '/v' 'DisableSearchBoxSuggestions' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Write-Host "Prevents installation of Teams:" +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Teams' '/v' 'DisableInstallation' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +Write-Host "Prevent installation of New Outlook": +& 'reg' 'add' 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\Windows Mail' '/v' 'PreventRun' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null +$tasksPath = "C:\scratchdir\Windows\System32\Tasks" -## this function allows PowerShell to take ownership of the Scheduled Tasks registry key from TrustedInstaller. Based on Jose Espitia's script. -function Enable-Privilege { - param( - [ValidateSet( - "SeAssignPrimaryTokenPrivilege", "SeAuditPrivilege", "SeBackupPrivilege", - "SeChangeNotifyPrivilege", "SeCreateGlobalPrivilege", "SeCreatePagefilePrivilege", - "SeCreatePermanentPrivilege", "SeCreateSymbolicLinkPrivilege", "SeCreateTokenPrivilege", - "SeDebugPrivilege", "SeEnableDelegationPrivilege", "SeImpersonatePrivilege", "SeIncreaseBasePriorityPrivilege", - "SeIncreaseQuotaPrivilege", "SeIncreaseWorkingSetPrivilege", "SeLoadDriverPrivilege", - "SeLockMemoryPrivilege", "SeMachineAccountPrivilege", "SeManageVolumePrivilege", - "SeProfileSingleProcessPrivilege", "SeRelabelPrivilege", "SeRemoteShutdownPrivilege", - "SeRestorePrivilege", "SeSecurityPrivilege", "SeShutdownPrivilege", "SeSyncAgentPrivilege", - "SeSystemEnvironmentPrivilege", "SeSystemProfilePrivilege", "SeSystemtimePrivilege", - "SeTakeOwnershipPrivilege", "SeTcbPrivilege", "SeTimeZonePrivilege", "SeTrustedCredManAccessPrivilege", - "SeUndockPrivilege", "SeUnsolicitedInputPrivilege")] - $Privilege, - ## The process on which to adjust the privilege. Defaults to the current process. - $ProcessId = $pid, - ## Switch to disable the privilege, rather than enable it. - [Switch] $Disable - ) - $definition = @' - using System; - using System.Runtime.InteropServices; - - public class AdjPriv - { - [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] - internal static extern bool AdjustTokenPrivileges(IntPtr htok, bool disall, - ref TokPriv1Luid newst, int len, IntPtr prev, IntPtr relen); - - [DllImport("advapi32.dll", ExactSpelling = true, SetLastError = true)] - internal static extern bool OpenProcessToken(IntPtr h, int acc, ref IntPtr phtok); - [DllImport("advapi32.dll", SetLastError = true)] - internal static extern bool LookupPrivilegeValue(string host, string name, ref long pluid); - [StructLayout(LayoutKind.Sequential, Pack = 1)] - internal struct TokPriv1Luid - { - public int Count; - public long Luid; - public int Attr; - } - - internal const int SE_PRIVILEGE_ENABLED = 0x00000002; - internal const int SE_PRIVILEGE_DISABLED = 0x00000000; - internal const int TOKEN_QUERY = 0x00000008; - internal const int TOKEN_ADJUST_PRIVILEGES = 0x00000020; - public static bool EnablePrivilege(long processHandle, string privilege, bool disable) - { - bool retVal; - TokPriv1Luid tp; - IntPtr hproc = new IntPtr(processHandle); - IntPtr htok = IntPtr.Zero; - retVal = OpenProcessToken(hproc, TOKEN_ADJUST_PRIVILEGES | TOKEN_QUERY, ref htok); - tp.Count = 1; - tp.Luid = 0; - if(disable) - { - tp.Attr = SE_PRIVILEGE_DISABLED; - } - else - { - tp.Attr = SE_PRIVILEGE_ENABLED; - } - retVal = LookupPrivilegeValue(null, privilege, ref tp.Luid); - retVal = AdjustTokenPrivileges(htok, false, ref tp, 0, IntPtr.Zero, IntPtr.Zero); - return retVal; - } - } -'@ - - $processHandle = (Get-Process -id $ProcessId).Handle - $type = Add-Type $definition -PassThru - $type[0]::EnablePrivilege($processHandle, $Privilege, $Disable) -} +Write-Host "Deleting scheduled task definition files..." -Enable-Privilege SeTakeOwnershipPrivilege - -$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::TakeOwnership) -$regACL = $regKey.GetAccessControl() -$regACL.SetOwner($adminGroup) -$regKey.SetAccessControl($regACL) -$regKey.Close() -Write-Host "Owner changed to Administrators." -$regKey = [Microsoft.Win32.Registry]::LocalMachine.OpenSubKey("zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks",[Microsoft.Win32.RegistryKeyPermissionCheck]::ReadWriteSubTree,[System.Security.AccessControl.RegistryRights]::ChangePermissions) -$regACL = $regKey.GetAccessControl() -$regRule = New-Object System.Security.AccessControl.RegistryAccessRule ($adminGroup,"FullControl","ContainerInherit","None","Allow") -$regACL.SetAccessRule($regRule) -$regKey.SetAccessControl($regACL) -Write-Host "Permissions modified for Administrators group." -Write-Host "Registry key permissions successfully updated." -$regKey.Close() - -Write-Host 'Deleting Application Compatibility Appraiser' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0600DD45-FAF2-4131-A006-0B17509B9F78}" /f | Out-Null -Write-Host 'Deleting Customer Experience Improvement Program' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4738DE7A-BCC1-4E2D-B1B0-CADB044BFA81}" /f | Out-Null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FAC31FA-4A85-4E64-BFD5-2154FF4594B3}" /f | Out-Null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC931F16-B50A-472E-B061-B6F79A71EF59}" /f | Out-Null -Write-Host 'Deleting Program Data Updater' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0671EB05-7D95-4153-A32B-1426B9FE61DB}" /f | Out-Null -Write-Host 'Deleting autochk proxy' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{87BF85F4-2CE1-4160-96EA-52F554AA28A2}" /f | Out-Null -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8A9C643C-3D74-4099-B6BD-9C6D170898B1}" /f | Out-Null -Write-Host 'Deleting QueueReporting' -reg delete "HKEY_LOCAL_MACHINE\zSOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3176A65-4E44-4ED3-AA73-3283660ACB9C}" /f | Out-Null -Write-Host "Tweaking complete!" +# Application Compatibility Appraiser +Remove-Item -Path "$tasksPath\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser" -Force -ErrorAction SilentlyContinue + +# Customer Experience Improvement Program (removes the entire folder and all tasks within it) +Remove-Item -Path "$tasksPath\Microsoft\Windows\Customer Experience Improvement Program" -Recurse -Force -ErrorAction SilentlyContinue + +# Program Data Updater +Remove-Item -Path "$tasksPath\Microsoft\Windows\Application Experience\ProgramDataUpdater" -Force -ErrorAction SilentlyContinue + +# Chkdsk Proxy +Remove-Item -Path "$tasksPath\Microsoft\Windows\Chkdsk\Proxy" -Force -ErrorAction SilentlyContinue + +# Windows Error Reporting (QueueReporting) +Remove-Item -Path "$tasksPath\Microsoft\Windows\Windows Error Reporting\QueueReporting" -Force -ErrorAction SilentlyContinue + +Write-Host "Task files have been deleted." Write-Host "Unmounting Registry..." -$regKey.Close() reg unload HKLM\zCOMPONENTS | Out-Null -reg unload HKLM\zDRIVERS | Out-Null reg unload HKLM\zDEFAULT | Out-Null reg unload HKLM\zNTUSER | Out-Null -reg unload HKLM\zSCHEMA | Out-Null -reg unload HKLM\zSOFTWARE +reg unload HKLM\zSOFTWARE | Out-Null reg unload HKLM\zSYSTEM | Out-Null Write-Host "Cleaning up image..." Repair-WindowsImage -Path $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase @@ -388,8 +274,7 @@ Write-Host ' ' Write-Host "Unmounting image..." Dismount-WindowsImage -Path $ScratchDisk\scratchdir -Save Write-Host "Exporting image..." -# Compressiontype Recovery is not supported with PShell https://learn.microsoft.com/en-us/powershell/module/dism/export-windowsimage?view=windowsserver2022-ps#-compressiontype -Export-WindowsImage -SourceImagePath $ScratchDisk\tiny11\sources\install.wim -SourceIndex $index -DestinationImagePath $ScratchDisk\tiny11\sources\install2.wim -CompressionType Fast +Dism.exe /Export-Image /SourceImageFile:"$ScratchDisk\tiny11\sources\install.wim" /SourceIndex:$index /DestinationImageFile:"$ScratchDisk\tiny11\sources\install2.wim" /Compress:recovery Remove-Item -Path "$ScratchDisk\tiny11\sources\install.wim" -Force | Out-Null Rename-Item -Path "$ScratchDisk\tiny11\sources\install2.wim" -NewName "install.wim" | Out-Null Write-Host "Windows image completed. Continuing with boot.wim." @@ -420,14 +305,10 @@ Write-Host "Bypassing system requirements(on the setup image):" & 'reg' 'add' 'HKLM\zSYSTEM\Setup\MoSetup' '/v' 'AllowUpgradesWithUnsupportedTPMOrCPU' '/t' 'REG_DWORD' '/d' '1' '/f' | Out-Null Write-Host "Tweaking complete!" Write-Host "Unmounting Registry..." -$regKey.Close() reg unload HKLM\zCOMPONENTS | Out-Null -reg unload HKLM\zDRIVERS | Out-Null reg unload HKLM\zDEFAULT | Out-Null reg unload HKLM\zNTUSER | Out-Null -reg unload HKLM\zSCHEMA | Out-Null -$regKey.Close() -reg unload HKLM\zSOFTWARE +reg unload HKLM\zSOFTWARE | Out-Null reg unload HKLM\zSYSTEM | Out-Null Write-Host "Unmounting image..." Dismount-WindowsImage -Path $ScratchDisk\scratchdir -Save From 977c06ae1887e6f515278b4135ba99a8b4368c1a Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Sat, 6 Sep 2025 00:26:15 +0300 Subject: [PATCH 58/63] Update README.md new desc --- README.md | 147 +++++++++++++++++++++++++++++++++++------------------- 1 file changed, 96 insertions(+), 51 deletions(-) diff --git a/README.md b/README.md index f39750bc..a90d2712 100644 --- a/README.md +++ b/README.md @@ -1,91 +1,136 @@ # tiny11builder - -Scripts to build a trimmed-down Windows 11 image - now in **PowerShell**! +Scripts to build a trimmed-down Windows 11 image - now in PowerShell!
Tiny11 builder, now completely overhauled.
+ +Latest Update (September 6, 2025) +It's been a while, but a new update is here! + +Added removal for Copilot and the new Outlook for Windows client. + +Switched to a more efficient compression method (/Compress:recovery), resulting in significantly smaller ISO files! + +Included new tweaks to proactively block the reinstallation of certain unwanted apps. + After more than a year (for which I am so sorry) of no updates, tiny11 builder is now a much more complete and flexible solution - one script fits all. Also, it is a steppingstone for an even more fleshed-out solution.
You can now use it on ANY Windows 11 release (not just a specific build), as well as ANY language or architecture. This is made possible thanks to the much-improved scripting capabilities of PowerShell, compared to the older Batch release.
-Since it is written in PowerShell, you need to set the execution policy to `Unrestricted`, so that you could run the script. -If you haven't done this before, make sure to run `Set-ExecutionPolicy unrestricted` as administrator in PowerShell before running the script, otherwise it would just crash. - +Since it is written in PowerShell, you need to set the execution policy to Unrestricted, so that you could run the script. +If you haven't done this before, make sure to run Set-ExecutionPolicy unrestricted as administrator in PowerShell before running the script, otherwise it would just crash. This is a script created to automate the build of a streamlined Windows 11 image, similar to tiny11. -My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The only executable included is **oscdimg.exe**, which is provided in the Windows ADK and it is used to create bootable ISO images. -Also included is an unattended answer file, which is used to bypass the Microsoft Account on OOBE and to deploy the image with the `/compact` flag. -It's open-source, **so feel free to add or remove anything you want!** Feedback is also much appreciated. +My main goal is to use only Microsoft utilities like DISM, and no utilities from external sources. The script has also been updated to use DISM's recovery compression, resulting in a much smaller final ISO size. The only other executable included is oscdimg.exe, which is provided in the Windows ADK and it is used to create bootable ISO images. +Also included is an unattended answer file, which is used to bypass the Microsoft Account on OOBE and to deploy the image with the /compact flag. +It's open-source, so feel free to add or remove anything you want! Feedback is also much appreciated. -Also, for the very first time, **introducing tiny11 core builder**! A more powerful script, designed for a quick and dirty development testbed. Just the bare minimun, none of the fluff. +Also, for the very first time, introducing tiny11 core builder! A more powerful script, designed for a quick and dirty development testbed. Just the bare minimum, none of the fluff. This script generates a significantly reduced Windows 11 image. However, it's not suitable for regular use due to its lack of serviceability - you can't add languages, updates, or features post-creation. tiny11 Core is not a full Windows 11 substitute but a rapid testing or development tool, potentially useful for VM environments. Instructions: +Download Windows 11 from the Microsoft website (https://www.microsoft.com/software-download/windows11) + +Mount the downloaded ISO image using Windows Explorer. + +Run the script and follow the on-screen prompts (selecting the drive letter and image SKU). -1. Download Windows 11 from the Microsoft website () -2. Mount the downloaded ISO image using Windows Explorer. -3. Select the drive letter where the image is mounted (only the letter, no colon (:)) -4. Select the SKU that you want the image to be based. -5. Sit back and relax :) -6. When the image is completed, you will see it in the folder where the script was extracted, with the name tiny11.iso +Sit back and relax :) + +When the image is completed, you will see it in the folder where the script was extracted, with the name tiny11.iso What is removed: +Clipchamp + +News + +Weather + +Xbox (although Xbox Identity provider is still here, so it should be possible to be reinstalled with no issues) + +GetHelp + +GetStarted + +Office Hub + +Solitaire + +PeopleApp + +PowerAutomate + +ToDo + +Alarms + +Mail and Calendar -- Clipchamp -- News -- Weather -- Xbox (although Xbox Identity provider is still here, so it should be possible to be reinstalled with no issues) -- GetHelp -- GetStarted -- Office Hub -- Solitaire -- PeopleApp -- PowerAutomate -- ToDo -- Alarms -- Mail and Calendar -- Feedback Hub -- Maps -- Sound Recorder -- Your Phone -- Media Player -- QuickAssist -- Internet Explorer -- Tablet PC Math -- Edge -- OneDrive +Feedback Hub + +Maps + +Sound Recorder + +Your Phone + +Media Player + +QuickAssist + +Internet Explorer + +Tablet PC Math + +Edge + +OneDrive + +Copilot + +Outlook for Windows (new) For tiny11 core: -- all of the above + -- Windows Component Store (WinSxS) -- Windows Defender (only disabled, can be enabled back if needed) -- Windows Update (Windows Update wouldn't work anyway without WinSxS, so enabling it would only put the system in a state where it would try to update but fail spectacularily) -- WinRE +all of the above + + +Windows Component Store (WinSxS) + +Windows Defender (only disabled, can be enabled back if needed) + +Windows Update (Windows Update wouldn't work anyway without WinSxS, so enabling it would only put the system in a state where it would try to update but fail spectacularly) + +WinRE +
-Keep in mind that **you cannot add back features in tiny11 core**! +Keep in mind that you cannot add back features in tiny11 core!

You will be asked during image creation if you want to enable .net 3.5 support!
+ Known issues: +Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: winget install edge. -1. Although Edge is removed, there are some remnants in the Settings. But the app in itself is deleted. You can install any browser using WinGet (after you update the app using Microsoft Store). If you want Edge, Copilot and Web Search back, simply install Edge using Winget: `winget install edge`.
Note: You might have to update Winget before being able to install any apps, using Microsoft Store.

-2. Outlook and Dev Home might reappear after some time. +2. Outlook and Dev Home might reappear after some time. This is an ongoing battle, though the latest script update tries to prevent this more aggressively.

3. If you are using this script on arm64, you might see a glimpse of an error while running the script. This is caused by the fact that the arm64 image doesn't have OneDriveSetup.exe included in the System32 folder. Features to be implemented: -- ~~disabling telemetry~~ (Implemented in the 04-29-24 release!) -- more ad suppression -- improved language and arch detection -- more flexibility in what to keep and what to delete -- maybe a GUI??? +~~disabling telemetry~~ (Implemented in the 04-29-24 release!) + +~~more ad suppression~~ (Partially implemented in the 09-06-25 release!) + +improved language and arch detection + +more flexibility in what to keep and what to delete + +maybe a GUI??? And that's pretty much it for now! Thanks for trying it and let me know how you like it! From e5752915f6f3a333134a7fdca4a0deea80fe1d8a Mon Sep 17 00:00:00 2001 From: Old Character <167513064+Miiraak@users.noreply.github.com> Date: Sun, 7 Sep 2025 00:00:24 +0200 Subject: [PATCH 59/63] Update log path and name ## Purpose : - Fix #17 - Fix #18 > This will avoid collision and let user retrive easely the log file. ## Details : - Using subexpression `$(get-date -f yyyyMMdd_HHmms)` inside the log file name. - Changing path of the log to `$PSScriptRoot` . (so iso, log, script will be at the same place.) --- tiny11maker.ps1 | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index caf897c4..fdc7c955 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -19,12 +19,12 @@ .\tiny11maker.ps1 -SCRATCH D -ISO E .\tiny11maker.ps1 - *If you put only the value in parameters the first one must be the iso mounted. The second is the scratch drive. - prefer the use of "-ISO" as you can put in the order you want. + *If you ordinal parameters the first one must be the mounted iso. The second is the scratch drive. + prefer the use of full named parameter (eg: "-ISO") as you can put in the order you want. .NOTES Auteur: ntdevlabs - Date: 05-06-24 + Date: 06-09-25 #> #---------[ Parameters ]---------# @@ -101,7 +101,7 @@ if (-not (Test-Path -Path "$PSScriptRoot/autounattend.xml")) { } # Start the transcript and prepare the window -Start-Transcript -Path "$ScratchDisk\tiny11.log" +Start-Transcript -Path "$PSScriptRoot\tiny11_$(get-date -f yyyyMMdd_HHmms).log" $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host @@ -539,3 +539,4 @@ Stop-Transcript exit + From a3bb93e0d9e988aca5440e3812dca87c67caea2f Mon Sep 17 00:00:00 2001 From: Old Character <167513064+Miiraak@users.noreply.github.com> Date: Sun, 7 Sep 2025 00:29:42 +0200 Subject: [PATCH 60/63] Remove duplicated reg. keys ## Purpose : - Fix #19 ## Details : - Removing duplicate of the value `OemPreInstalledAppsEnabled`. - Removing duplicate of the value `PreInstalledAppsEnabled`. - Removing duplicate of the value `SilentInstalledAppsEnabled`. - Removing duplicate of the value `SubscribedContentEnabled`. - Removing duplicate of the value `ContentDeliveryAllowed`. --- tiny11maker.ps1 | 12 ++---------- 1 file changed, 2 insertions(+), 10 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index fdc7c955..af7e5dda 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -24,7 +24,7 @@ .NOTES Auteur: ntdevlabs - Date: 06-09-25 + Date: 09-07-25 #> #---------[ Parameters ]---------# @@ -105,7 +105,7 @@ Start-Transcript -Path "$PSScriptRoot\tiny11_$(get-date -f yyyyMMdd_HHmms).log" $Host.UI.RawUI.WindowTitle = "Tiny11 image creator" Clear-Host -Write-Output "Welcome to the tiny11 image creator! Release: 09-04-25" +Write-Output "Welcome to the tiny11 image creator! Release: 09-07-25" $hostArchitecture = $Env:PROCESSOR_ARCHITECTURE New-Item -ItemType Directory -Force -Path "$ScratchDisk\tiny11\sources" | Out-Null @@ -302,13 +302,8 @@ Set-RegistryValue 'HKLM\zNTUSER\SOFTWARE\Microsoft\Windows\CurrentVersion\Conten Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\CloudContent' 'DisableWindowsConsumerFeatures' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'ContentDeliveryAllowed' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\PolicyManager\current\device\Start' 'ConfigureStartPins' 'REG_SZ' '{"pinnedList": [{}]}' -Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'ContentDeliveryAllowed' 'REG_DWORD' '0' -Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'ContentDeliveryAllowed' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'FeatureManagementEnabled' 'REG_DWORD' '0' -Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'OemPreInstalledAppsEnabled' 'REG_DWORD' '0' -Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'PreInstalledAppsEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'PreInstalledAppsEverEnabled' 'REG_DWORD' '0' -Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SilentInstalledAppsEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SoftLandingEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContentEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-310093Enabled' 'REG_DWORD' '0' @@ -317,7 +312,6 @@ Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\Conten Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-338393Enabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-353694Enabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContent-353696Enabled' 'REG_DWORD' '0' -Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SubscribedContentEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Windows\CurrentVersion\ContentDeliveryManager' 'SystemPaneSuggestionsEnabled' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\PushToInstall' 'DisablePushToInstall' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\MRT' 'DontOfferThroughWUAU' 'REG_DWORD' '1' @@ -538,5 +532,3 @@ if (Test-Path -Path "$PSScriptRoot\autounattend.xml") { Stop-Transcript exit - - From 4a24bff48b7b7e0c7453aec25e7c7bda4923a680 Mon Sep 17 00:00:00 2001 From: Old Character <167513064+Miiraak@users.noreply.github.com> Date: Sun, 7 Sep 2025 00:35:07 +0200 Subject: [PATCH 61/63] Correction typo in comment and output ## Purpose : - Fix #20 ## Details : - Change `or` by `of` in line 349 and 350 --- tiny11maker.ps1 | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index af7e5dda..3d8b9f77 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -346,8 +346,8 @@ Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\InputPersonalization\TrainedD Set-RegistryValue 'HKLM\zNTUSER\Software\Microsoft\Personalization\Settings' 'AcceptedPrivacyPolicy' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zSOFTWARE\Policies\Microsoft\Windows\DataCollection' 'AllowTelemetry' 'REG_DWORD' '0' Set-RegistryValue 'HKLM\zSYSTEM\ControlSet001\Services\dmwappushservice' 'Start' 'REG_DWORD' '4' -## Prevents installation or DevHome and Outlook -Write-Output "Prevents installation or DevHome and Outlook:" +## Prevents installation of DevHome and Outlook +Write-Output "Prevents installation of DevHome and Outlook:" Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler_Oobe\OutlookUpdate' 'workCompleted' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\OutlookUpdate' 'workCompleted' 'REG_DWORD' '1' Set-RegistryValue 'HKLM\zSOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Orchestrator\UScheduler\DevHomeUpdate' 'workCompleted' 'REG_DWORD' '1' @@ -532,3 +532,4 @@ if (Test-Path -Path "$PSScriptRoot\autounattend.xml") { Stop-Transcript exit + From b8cd6e90034dc61532e89b45753903e2c500697b Mon Sep 17 00:00:00 2001 From: NTDEV <38796849+ntdevlabs@users.noreply.github.com> Date: Thu, 11 Sep 2025 01:45:57 +0300 Subject: [PATCH 62/63] Update README.md --- README.md | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/README.md b/README.md index 552bb070..72ed8787 100644 --- a/README.md +++ b/README.md @@ -113,4 +113,10 @@ You will be asked during image creation if you want to enable .net 3.5 support! - maybe a GUI??? And that's pretty much it for now! +## ❤️ Support the Project + +If this project has helped you, please consider showing your support! A small donation helps me dedicate more time to projects like this. +Thank you! + +**[Patreon](http://patreon.com/ntdev) | [PayPal](http://paypal.me/ntdev2) | [Ko-fi](http://ko-fi.com/ntdev)** Thanks for trying it and let me know how you like it! From af06d5ab5748183127a4d778be79dbfb322975c8 Mon Sep 17 00:00:00 2001 From: FrysCrypto <119890880+FrysCrypto@users.noreply.github.com> Date: Fri, 12 Sep 2025 01:46:20 -0500 Subject: [PATCH 63/63] Update tiny11maker.ps1 -StartComponentCleanup switch no longer supported in most recent powershell versions --- tiny11maker.ps1 | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tiny11maker.ps1 b/tiny11maker.ps1 index 3d8b9f77..c24757f2 100644 --- a/tiny11maker.ps1 +++ b/tiny11maker.ps1 @@ -387,7 +387,7 @@ reg unload HKLM\zNTUSER | Out-Null reg unload HKLM\zSOFTWARE | Out-Null reg unload HKLM\zSYSTEM | Out-Null Write-Output "Cleaning up image..." -Repair-WindowsImage -Path $ScratchDisk\scratchdir -StartComponentCleanup -ResetBase +dism.exe /Image:$ScratchDisk\scratchdir /Cleanup-Image /StartComponentCleanup /ResetBase Write-Output "Cleanup complete." Write-Output ' ' Write-Output "Unmounting image..."