********************** Windows PowerShell transcript start Start time: 20210202010555 Username: DESKTOP-APRLQ65\Administrator RunAs User: DESKTOP-APRLQ65\Administrator Configuration Name: Machine: DESKTOP-APRLQ65 (Microsoft Windows NT 10.0.19042.0) Host Application: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process ID: 2824 PSVersion: 5.1.19041.546 PSEdition: Desktop PSCompatibleVersions: 1.0, 2.0, 3.0, 4.0, 5.0, 5.1.19041.546 BuildVersion: 10.0.19041.546 CLRVersion: 4.0.30319.42000 WSManStackVersion: 3.0 PSRemotingProtocolVersion: 2.3 SerializationVersion: 1.1.0.1 ********************** Transcript started, output file is WindowsDCtranscript.txt ******Decrapifying Windows 10...****** Removing app package: 1527c705-839a-4832-9118-54d4Bd6a0c89 Removing app package: c5e2524a-ea46-4f67-841f-6a9465d9d515 Removing app package: E2A4F912-2574-4A75-9BB0-0D023378592B Removing app package: F46D4000-FD22-4DB4-AC8E-4E1DDDE828FE Removing app package: Microsoft.CredDialogHost Removing app package: Microsoft.Win32WebViewHost Removing app package: Microsoft.Windows.CallingShellApp Removing app package: Microsoft.Windows.NarratorQuickStart Removing app package: Microsoft.Windows.PeopleExperienceHost Removing app package: Microsoft.Windows.PinningConfirmationDialog Removing app package: Microsoft.Windows.Search Removing app package: Microsoft.XboxGameCallableUI Removing app package: MicrosoftWindows.Client.CBS Removing app package: MicrosoftWindows.UndockedDevKit Removing app package: NcsiUwpApp Removing app package: Windows.CBSPreview Removing app package: Windows.PrintDialog Removing app package: Microsoft.549981C3F5F10 Removing app package: Microsoft.BingWeather Removing app package: Microsoft.GetHelp Removing app package: Microsoft.Microsoft3DViewer Removing app package: Microsoft.MicrosoftOfficeHub Removing app package: Microsoft.MicrosoftSolitaireCollection Removing app package: Microsoft.MicrosoftStickyNotes Removing app package: Microsoft.MixedReality.Portal Removing app package: Microsoft.MSPaint Removing app package: Microsoft.Office.OneNote Removing app package: Microsoft.People Removing app package: Microsoft.ScreenSketch Removing app package: Microsoft.SkypeApp Removing app package: Microsoft.VP9VideoExtensions Removing app package: Microsoft.Wallet Removing app package: Microsoft.WebMediaExtensions Removing app package: Microsoft.WebpImageExtension Removing app package: Microsoft.Windows.Photos Removing app package: Microsoft.WindowsAlarms Removing app package: Microsoft.WindowsCamera Removing app package: microsoft.windowscommunicationsapps Removing app package: Microsoft.WindowsFeedbackHub Removing app package: Microsoft.WindowsMaps Removing app package: Microsoft.WindowsSoundRecorder Removing app package: Microsoft.Xbox.TCUI Removing app package: Microsoft.XboxApp Removing app package: Microsoft.XboxGameOverlay Removing app package: Microsoft.XboxGamingOverlay Removing app package: Microsoft.XboxIdentityProvider Removing app package: Microsoft.XboxSpeechToTextOverlay Removing app package: Microsoft.YourPhone Removing app package: Microsoft.ZuneMusic Removing app package: Microsoft.ZuneVideo Removing provisioned app Microsoft.549981C3F5F10 Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.BingWeather Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.GetHelp Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.Microsoft3DViewer Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.MicrosoftOfficeHub Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.MicrosoftSolitaireCollection Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.MicrosoftStickyNotes Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.MixedReality.Portal Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.MSPaint Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.Office.OneNote Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.People Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.ScreenSketch Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.SkypeApp Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.VP9VideoExtensions Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.Wallet Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.WebMediaExtensions Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.WebpImageExtension Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.Windows.Photos Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.WindowsAlarms Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.WindowsCamera Path : Online : True RestartNeeded : False Removing provisioned app microsoft.windowscommunicationsapps Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.WindowsFeedbackHub Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.WindowsMaps Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.WindowsSoundRecorder Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.Xbox.TCUI Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.XboxApp Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.XboxGameOverlay Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.XboxGamingOverlay Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.XboxIdentityProvider Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.XboxSpeechToTextOverlay Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.YourPhone Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.ZuneMusic Path : Online : True RestartNeeded : False Removing provisioned app Microsoft.ZuneVideo Path : Online : True RestartNeeded : False ***Disabling some unecessary scheduled tasks...*** Actions : {MSFT_TaskExecAction} Author : $(@%SystemRoot%\system32\invagent.dll,-701) Date : Description : $(@%SystemRoot%\system32\invagent.dll,-702) Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS) Settings : MSFT_TaskSettings3 Source : $(@%SystemRoot%\system32\invagent.dll,-701) State : Disabled TaskName : ProgramDataUpdater TaskPath : \Microsoft\Windows\Application Experience\ Triggers : URI : \Microsoft\Windows\Application Experience\ProgramDataUpdater Version : 1.0 PSComputerName : Actions : {MSFT_TaskExecAction} Author : Microsoft Corporation Date : Description : If the user has consented to participate in the Windows Customer Experience Improvement Program, this job collects and sends usage data to Microsoft. Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU) Settings : MSFT_TaskSettings3 Source : Windows Customer Experience Improvement Program State : Disabled TaskName : Consolidator TaskPath : \Microsoft\Windows\Customer Experience Improvement Program\ Triggers : {MSFT_TaskTimeTrigger} URI : \Microsoft\Windows\Customer Experience Improvement Program\Consolidator Version : 1.0 PSComputerName : Actions : {MSFT_TaskExecAction} Author : $(@%SystemRoot%\system32\compattelrunner.exe,-501) Date : Description : $(@%SystemRoot%\system32\compattelrunner.exe,-503) Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS) Settings : MSFT_TaskSettings3 Source : $(@%SystemRoot%\system32\compattelrunner.exe,-501) State : Disabled TaskName : Microsoft Compatibility Appraiser TaskPath : \Microsoft\Windows\Application Experience\ Triggers : {MSFT_TaskTimeTrigger, MSFT_TaskTrigger, MSFT_TaskTrigger} URI : \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser Version : 1.0 PSComputerName : Actions : {MSFT_TaskComHandlerAction} Author : Microsoft Corporation Date : Description : The USB CEIP (Customer Experience Improvement Program) task collects Universal Serial Bus related statistics and information about your machine and sends it to the Windows Device Connectivity engineering group at Microsoft. The information received is used to help improve the reliability, stability, and overall functionality of USB in Windows. If the user has not consented to participate in Windows CEIP, this task does not do anything. Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:(A;OICI;FA;;;BA)(A;OICI;FA;;;SY)(A;OICI;GRGX;;;AU)(A;OICI;SD;;;S-1-5-87-1060603329-121822201-345 2730971-4292368946-61207722)(A;;FRFX;;;LS) Settings : MSFT_TaskSettings3 Source : Microsoft Corporation State : Disabled TaskName : UsbCeip TaskPath : \Microsoft\Windows\Customer Experience Improvement Program\ Triggers : URI : \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip Version : 1.0 PSComputerName : Actions : {MSFT_TaskExecAction} Author : Microsoft Corporation Date : Description : The Windows Disk Diagnostic reports general disk and system information to Microsoft for users participating in the Customer Experience Program. Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:(A;;GA;;;BA)(A;;GA;;;SY)(A;;FRFX;;;LS) Settings : MSFT_TaskSettings3 Source : Microsoft Corporation State : Disabled TaskName : Microsoft-Windows-DiskDiagnosticDataCollector TaskPath : \Microsoft\Windows\DiskDiagnostic\ Triggers : URI : \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector Version : 1.0 PSComputerName : Actions : {MSFT_TaskExecAction} Author : Microsoft Date : Description : Network information collector Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : Settings : MSFT_TaskSettings3 Source : Microsoft Windows Network Trace State : Disabled TaskName : GatherNetworkInfo TaskPath : \Microsoft\Windows\NetTrace\ Triggers : URI : \Microsoft\Windows\NetTrace\GatherNetworkInfo Version : PSComputerName : Actions : {MSFT_TaskExecAction} Author : Microsoft Corporation Date : Description : Windows Error Reporting task to process queued reports. Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:(A;;FA;;;BA)(A;;FA;;;SY)(A;;FRFX;;;WD) Settings : MSFT_TaskSettings3 Source : Microsoft Windows Error Reporting State : Disabled TaskName : QueueReporting TaskPath : \Microsoft\Windows\Windows Error Reporting\ Triggers : {MSFT_TaskBootTrigger, MSFT_TaskTrigger, MSFT_TaskTrigger, MSFT_TaskTrigger...} URI : \Microsoft\Windows\Windows Error Reporting\QueueReporting Version : 1.5 PSComputerName : Actions : {MSFT_TaskExecAction} Author : Microsoft Windows Feedback Date : Description : Update SIUF strings Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : Settings : MSFT_TaskSettings3 Source : System Initiated User Feedback State : Disabled TaskName : DmClientOnScenarioDownload TaskPath : \Microsoft\Windows\Feedback\Siuf\ Triggers : {MSFT_TaskTrigger} URI : \Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload Version : PSComputerName : Actions : {MSFT_TaskExecAction} Author : Microsoft Date : Description : XblGameSave Standby Task Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : Settings : MSFT_TaskSettings3 Source : State : Disabled TaskName : XblGameSaveTask TaskPath : \Microsoft\XblGameSave\ Triggers : {MSFT_TaskIdleTrigger} URI : \Microsoft\XblGameSave\XblGameSaveTask Version : PSComputerName : Actions : {MSFT_TaskComHandlerAction} Author : Microsoft Corporation Date : Description : Task periodically logging feature usage reports Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFX;;;AU) Settings : MSFT_TaskSettings3 Source : Microsoft Corporation State : Disabled TaskName : UsageDataReporting TaskPath : \Microsoft\Windows\Flighting\FeatureConfig\ Triggers : URI : \Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting Version : PSComputerName : Actions : {MSFT_TaskComHandlerAction} Author : Microsoft Corporation Date : 2014-11-05T00:00:00 Description : This task shows various Map related toasts Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : D:(A;;0x111FFFFF;;;SY)(A;;0x111FFFFF;;;BA)(A;;0x111FFFFF;;;S-1-5-80-3028837079-3186095147-95510720 0-3701964851-1150726376)(A;;FRFX;;;AU) Settings : MSFT_TaskSettings3 Source : State : Disabled TaskName : MapsToastTask TaskPath : \Microsoft\Windows\Maps\ Triggers : URI : \Microsoft\Windows\Maps\MapsToastTask Version : PSComputerName : Actions : {MSFT_TaskExecAction} Author : Microsoft Windows Feedback Date : Description : Update SIUF strings Documentation : Principal : MSFT_TaskPrincipal2 SecurityDescriptor : Settings : MSFT_TaskSettings3 Source : System Initiated User Feedback State : Disabled TaskName : DmClient TaskPath : \Microsoft\Windows\Feedback\Siuf\ Triggers : URI : \Microsoft\Windows\Feedback\Siuf\DmClient Version : PSComputerName : Disable-scheduledtask : Access is denied. At D:\decrap_2004.ps1:165 char:171 + ... blGameSaveTask" -erroraction silentlycontinue | Disable-scheduledtask + ~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : PermissionDenied: (PS_ScheduledTask:Root/Microsoft/...S_ScheduledTask) [Disable-ScheduledTask], CimException + FullyQualifiedErrorId : HRESULT 0x80070005,Disable-ScheduledTask Disable-scheduledtask : Access is denied. At D:\decrap_2004.ps1:165 char:171 + ... blGameSaveTask" -erroraction silentlycontinue | Disable-scheduledtask + ~~~~~~~~~~~~~~~~~~~~~ + CategoryInfo : PermissionDenied: (PS_ScheduledTask:Root/Microsoft/...S_ScheduledTask) [Disable-Schedule dTask], CimException + FullyQualifiedErrorId : HRESULT 0x80070005,Disable-ScheduledTask ***Stopping and disabling some services...*** ***Applying registry items to HKCU...*** The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. ***Applying registry items to default NTUSER.DAT...*** The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. ***Applying registry items to HKLM...*** The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. ERROR: Invalid key name. Type "REG DELETE /?" for usage. ERROR: Invalid key name. Type "REG DELETE /?" for usage. ERROR: Invalid key name. Type "REG DELETE /?" for usage. ERROR: Invalid key name. Type "REG DELETE /?" for usage. ERROR: Invalid key name. Type "REG DELETE /?" for usage. ERROR: Invalid key name. Type "REG DELETE /?" for usage. ERROR: Invalid key name. Type "REG DELETE /?" for usage. ERROR: Invalid key name. Type "REG DELETE /?" for usage. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. The operation completed successfully. ***Registry set current user and default user, and policies set for local machine!*** ***Setting clean start menu for new profiles...*** *******Decrapification complete.******* *******Remember to set your execution policy back! Set-Executionpolicy restricted is the Windows 10 default.******* *******Reboot your computer now!******* ********************** Windows PowerShell transcript end End time: 20210202010859 **********************