Every claim about making Windows faster is a claim about a specific key, API or service. This table names it.
The unit of a row here is not a product. It is a claim–surface pair: the thing optimisers sell, joined to the operating-system surface it must actually be writing to if the claim is true at all. Once the surface is named, the claim becomes checkable, because Microsoft documents most of these surfaces and documents what Windows does with them when nothing is installed.
Sixty-eight rows. Each carries the primary source, the documented default, the release at which the answer changed, and one verdict from a fixed vocabulary of eight. Where we could not confirm a mechanism from a primary source the verdict is UNVERIFIED and the row says what we checked. That happens sixteen times, which is the honest number and not a failure of effort.
§1Eight questions to ask before you install anything that promises speed
This is the standing preamble to the table, and it is the part worth memorising. It is a buyer’s test, not a technical one, and it works without any knowledge of Windows internals.
- Does it name the surface? A product that says it “cleans your registry” and never names a key is not describing a mechanism. Every row in this table names one, and if we could not name one the row says so.
- Does it publish a capability boundary? A list of exactly which autostart surfaces, services and keys it reads and writes. Sysinternals Autoruns publishes its list as command-line switches. Almost nothing else in this category publishes anything. Ours is at §4.
- Does the operating system already do this, and since which version? Column 6 exists because for most of these the answer is yes, and the date is usually earlier than the product that is selling it. Receive Window Auto-Tuning landed in Windows Vista; a 2008 feature list still advertised setting the transmission unit cache size by hand.
- Is the number falsifiable with an in-box counter? If nothing in Performance Monitor, Resource Monitor or the event log can confirm or refute the figure on the box, the figure is marketing. Column 7 is blank on most rows precisely because most claims name no counter.
- Does the scan report a count, or does it report details? A number of “issues” with no per-item path is not a diagnosis. This is the distinction regulators actually punished — not the failure to deliver speed, but the fabricated diagnosis. The scan is the product, and a count with no per-item path is the one part of the product a buyer has no way to check.
- Does the free scan find problems before it has read anything? The Federal Trade Commission’s 2019 Office Depot and Support.com order describes a “PC Health Check” whose result was driven by four yes/no questions the user answered before the scan began. Ticking any one box produced a malware-found report.
- Can you undo it, item by item, six months later? Backup before the change, per-change restore, and an export you can read in a text editor. A single “restore all” button is not the same thing, and neither is a backup format only the vendor can open.
- Who is the vendor, and does the answer stay the same on every page? A consistent answer is the cheapest trust signal there is, and its absence is information. The worked example is this domain’s own history: Tenglnet gives a Jaipur street address in the 2008 capture, the same street relocated to Washington DC in 2012, and a Chinese ICP number on the Windows 8 pages. We report the inconsistency; we draw no conclusion about intent, and none should be read into it.
Two things this preamble deliberately does not say. It does not say that optimisers make no difference — some rows below are TRADE, meaning the mechanism is real and the cost is named. And it does not cite Microsoft’s retired support policy for registry cleaning utilities as proof that cleaners do not work. That document is a support-scope and liability disclaimer. It says Microsoft does not support these tools and is not responsible for damage they cause; it never says they fail to speed up a PC, and anyone citing it as if it did is overreading it. We say so even though the overreading would suit us.
§2How to read a row
Twelve columns, fixed. The table is set to the full 84-character measure rather than the 68-character prose measure, and it is still wider than a phone. We chose to keep all twelve columns in one table rather than split rows into blocks on narrow screens, because the value of the artifact is the comparison across columns — reading down DOCUMENTED DEFAULT is the fastest way to learn what Windows already does. On a narrow screen the page scrolls sideways. No cell is truncated, hidden or collapsed at any width.
| # | Column | What is in it |
|---|---|---|
| 1 | ID | Stable. Cited from articles, never reused, never renumbered. /mechanisms/#S-04 is a permanent deep link |
| 2 | THE CLAIM, AS SOLD | Twelve words or fewer, in the seller’s framing, not ours |
| 3 | SURFACE IT MUST TOUCH | The key, API, file, service or task. Full path, never truncated |
| 4 | DOCUMENTED BY | MS-DOC / MS-KB / SYSINTERNALS / THIRD-PARTY / UNDOCUMENTED, linked to the source |
| 5 | DOCUMENTED DEFAULT | What Windows does with nothing installed, and where that is written down |
| 6 | VERSION BOUNDARY | The release at which the answer changed |
| 7 | MEASURABLE EFFECT | The counter that would move, and by how much. Blank is the honest default and stays blank — it is blank on 60 of the 68 rows |
| 8 | VERDICT | One of eight codes, below |
| 9 | COST OF BEING WRONG | What breaks if you apply it anyway |
| 10 | SOURCES | Numbered, keyed to §5, every one with an access date |
| 11 | WINSET CLAIMED | Whether this domain’s own former product advertised it: 2008 / 2012 / WIN8 / —, each linked to the capture |
| 12 | LAST VERIFIED | ISO date, and the build the documentation applies to |
The verdict vocabulary is closed. There is no ninth code, and a row that does not fit one of these eight is a row we have not finished.
| Code | Rows | Means |
|---|---|---|
| NO-OP | 5 | The surface is ignored on any supported Windows. Writing it changes nothing |
| SUPERSEDED | 14 | It did something once; the OS now does it. Version boundary mandatory |
| TRADE | 13 | It works, and it costs something else. Both sides stated |
| HARMFUL | 5 | Net loss, with the mechanism of the loss named |
| DEPENDS | 13 | A real conditional. The condition is named, or the code may not be used |
| UNVERIFIED | 16 | We could not confirm the mechanism from a primary source. What we checked is listed, and the row is filed at /mechanisms/unverified/ |
| UNSAFE-CLAIM | 1 | A licensing or legal claim we will not test, endorse or explain operationally |
| HARDWARE | 1 | The bottleneck is physical and no setting fixes it |
UNVERIFIED and DEPENDS together are 29 of 68 rows — 43%. That is not a weakness of the table, it is the table. Uncertainty does not convert, which is exactly why affiliate content has no vocabulary for it, and why a page that ships it on day one looks different from everything else returned for these queries.
Two modifier flags appear as superscripts on a code. † the write touches licensing, telemetry or compliance rather than performance. ‡ the surface no longer exists, or is no longer honoured, in a currently supported build. Flagged rows are kept, never deleted, because a large share of the traffic to this domain arrives on links a decade old and those readers need the historical row more than anyone.
Clean up computer memory automatic timer by Windows Winset.Archived vendor help index, tlwinset.com/help.htm, capture 2012-08-24. Checked 2026-08-05 · Ledger row M-01
The three cards on this page are three of the thirty-three claim cards on this site, spread across thirteen pages. Thirty-two of them quote archived Tenglnet material and each carries its archive URL and its capture date; the thirty-third quotes a trade association about its own file format, with the address and the date we read it. Every quotation is capped at twenty-five words and the longest anywhere on the site currently runs to twenty-one. We do not republish the previous owner’s prose; we quote it as evidence of what was claimed, and the writing around it is ours.
§3The Mechanism Ledger
| ID | The claim, as sold | Surface it must touch | Documented by | Documented default | Version boundary | Measurable effect | Verdict | Cost of being wrong | Sources | Winset claimed | Last verified |
|---|---|---|---|---|---|---|---|---|---|---|---|
| M-01 | “Clean up computer memory on an automatic timer” | EmptyWorkingSet(hProcess) · SetProcessWorkingSetSize(hProcess, (SIZE_T)-1, (SIZE_T)-1) | MS-DOC | “Removes as many pages as possible from the working set of the specified process.” Nothing in Windows calls this on a schedule; the memory manager trims under memory pressure. Microsoft does not document where the removed pages go. | XP (API) · unchanged 25H2 | HARMFUL | A working set is by definition the pages of a process resident in physical memory. Every page removed must be faulted back in on next access. The timer guarantees this repeats. | [1][2][88] | 2012 | 2026-08-05 · 25H2 | |
| M-02 | “Clean memory when free memory is less than 30%” | GlobalMemoryStatusEx → MEMORYSTATUSEX.ullAvailPhys · Memory\Available MBytes | MS-DOC | “It is the sum of the size of the standby, free, and zero lists.” Pages holding cached file data on the standby list are already counted as available and are handed to any process that asks. | — | NO-OP | The trigger fires on a number that already counts the file cache as available, so the tool acts on a condition that is not a shortage, and discards cache to prove it. | [3][4][89][92] | WIN8 | 2026-08-05 · 25H2 | |
| M-03 | “Turn off memory compression to make Windows faster” | Disable-MMAgent -MemoryCompression · Enable-MMAgent -MemoryCompression | MS-DOC | Not stated. The cmdlet reference describes the switch as “uses memory compression” and gives no default and no behaviour. The feature shipped in Windows 10 RTM per a Microsoft video with the Windows kernel team. | Win10 RTM (1507) | UNVERIFIED | There is no documented default to restore to. Checked: Enable-MMAgent, Get-MMAgent, Memory Management Registry Keys, the Server cache and memory manager pages, RAMMap. | [5][7] | — | 2026-08-05 · 25H2 | |
| M-04 | “Combine identical memory pages to free RAM” | Enable-MMAgent -PageCombining | MS-DOC | “Page combining is disabled by default but can be enabled by using the Enable-MMAgent Windows PowerShell cmdlet. Page combining was added in Windows Server 2012.” The client default is not stated in any current Microsoft page. | Windows Server 2012 | DEPENDS | Condition, named by Microsoft: it helps on machines with many private, pageable pages of identical content, and “the downside of enabling page combining is increased CPU usage.” No CPU figure is published. | [5][6] | — | 2026-08-05 · 25H2 | |
| M-05 | “Set a fixed page file size for better performance” | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PagingFiles | MS-DOC | “By default, page files are system-managed… when the system commit charge is more than 90 percent of the system commit limit, the page file is increased.” Growth stops at three times physical memory or 4 GB, whichever is larger. | — | DEPENDS | Condition: the crash-dump setting. Automatic memory dump is enabled by default, and a fixed page file smaller than the dump requirement means the next bug check produces no dump and says nothing about it. | [8][9] | — | 2026-08-05 · 25H2 | |
| M-06 | “Wipe the page file at shutdown for a clean start” | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\ClearPageFileAtShutdown | MS-DOC | Disabled. “Client Computer Effective Default Settings: Disabled.” When enabled it also clears hiberfil.sys where hibernation is disabled on a portable device. | — | Shutdown duration. Microsoft: on a device with 2 GB of RAM and a 2-GB page file this “could increase the shutdown process by more than 30 minutes”, because the storage area is overwritten several times. | HARMFUL | The machine takes minutes to tens of minutes longer to shut down and restart, every time, and the mechanism is a multi-pass overwrite Microsoft documents on the same page. | [10] | — | 2026-08-05 · 25H2 |
| M-07 | “Keep the kernel in RAM to stop disk thrashing” | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\DisablePagingExecutive | MS-DOC | 0 — “Drivers and system code can be paged to disk as needed.” The Windows Performance Toolkit reference sets it only to enable x64 stackwalking on Vista and Windows 7, and states “Systems with Windows 8 and higher do not need this registry change.” | Win8 (no longer needed for tracing) | UNVERIFIED | The only Microsoft statement that it “improves performance on machines with a lot of memory” is on a Windows Server 2003 reference page. Checked: the WPT reference, Memory Management Registry Keys, the Server 2003 page. No current-build source. | [11][12] | — | 2026-08-05 · 25H2 | |
| M-08 | “One click empties the standby list and frees your RAM” | RAMMap → Empty → Empty Standby List / Empty Working Sets | UNDOCUMENTED | Not stated. The RAMMap page documents seven tabs, refresh and snapshot save/load, and defers terminology outward: “please see Windows Internals, 5th Edition.” The Empty menu is not described anywhere on it. | — | UNVERIFIED | The standby list is the file cache. Whatever is discarded is read from disk again on next use, and no Microsoft source states what the command does or what it costs. Checked: the RAMMap page, the Defrag Tools episode index, the Server cache troubleshooting guide. | [16] | — | 2026-08-05 · 25H2 | |
| M-09 | “Disable prefetching to stop background disk activity” | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters\EnablePrefetcher | MS-DOC | Not stated. The value table — 0 disabled, 1 application start, 2 boot, 3 both — exists only in archived Windows Embedded Standard 7 documentation, written for devices with a write filter where “Prefetch is unable to persist its data from startup to startup.” | — | UNVERIFIED | No Microsoft-documented default exists to restore. The widely repeated “default is 3” is unsourced. Checked: the Embedded pages for XP Embedded and Standard 7, Memory Management Registry Keys, the Win32 memory reference. | [17] | — | 2026-08-05 · 25H2 | |
| M-10 | “Free up memory instead of buying more RAM” | System commit charge against the system commit limit · Memory\Committed Bytes · Memory\Commit Limit | MS-DOC | The commit limit is physical memory plus the current page file size. “System-managed page files automatically grow… when the system commit charge reaches 90 percent of the system commit limit.” | — | HARDWARE | If committed bytes sit near the commit limit, the machine is short of memory, not short of housekeeping. No registry value changes how much physical memory is installed; the page file grows onto disk and the machine pages. | [8][9][3] | — | 2026-08-05 · 25H2 | |
| R-01 | “The registry becomes very large and slows the computer” | The registry hives themselves · HKLM\SYSTEM\CurrentControlSet\Control\RegistrySizeLimit | MS-DOC | “Windows Server 2003 with SP1, Windows Server 2003 and Windows XP: There are no explicit limits on the total amount of space that may be consumed by hives.” The global quota is documented only under a Windows 2000 heading. | XP / Server 2003 | SUPERSEDED | The premise of the sale is a Windows 9x and Windows 2000 premise. One caveat we will not suppress: KB 2567018 states the old limit is still honoured on Server 2003 through 2008 R2, and on XP through Windows 7, if an administrator sets the value to something other than 0. | [18][19][93] | WIN8 | 2026-08-05 · 25H2 | |
| R-02 | “Scan and clean up the Windows registry” | RegDeleteKeyEx / RegDeleteValue against HKCR and HKLM\SOFTWARE\Classes | UNDOCUMENTED | Windows does not remove unreferenced class registrations on a schedule and publishes no maintenance guidance that involves doing so. No Microsoft source connects deleting them to any change in a performance counter. | — | UNVERIFIED | Microsoft’s retired support policy says it does not support registry cleaners and is not responsible for issues they cause. That is a support-scope and liability position, not a performance finding, and the same article concedes a damaged registry can cause slowdowns. Checked: the archived policy, the current unwanted-software criteria, Registry Storage Space. | [20][21][88] | 2012 | 2026-08-05 · 25H2 | |
| R-03 | “Scan complete: 1,247 registry errors found” | None named. A count with no per-item path names no surface at all. | MS-DOC | Microsoft classifies as unwanted software anything that will “Display exaggerated claims about your device’s health” or “Make misleading or inaccurate claims about files, registry entries, or other items on your device.” | Criteria updated 2026-01-29 | UNVERIFIED | A claim that names no surface cannot be verified or refuted, which is the point of preamble question 1. What would close it is a per-item report with full key paths; that is also the difference regulators acted on. | [21] | — | 2026-08-05 · 25H2 | |
| R-04 | “Accelerate menu display speed” | HKCU\Control Panel\Desktop\MenuShowDelay | MS-DOC | REG_SZ, “Milliseconds in decimal”, default value 400. “Determines the interval from the time the cursor is pointed at a menu until the menu items are displayed.” Microsoft has published no modern restatement. | — (documented for Windows 2000) | Menu open delay in milliseconds. Documented default 400; the value moves perceived latency only and no throughput counter exists that it would change. | TRADE | At 0 there is no dwell time, so sub-menus open under the pointer as it passes over them and menu navigation becomes error-prone. The machine is not faster; the interface is. | [25][87] | 2008 | 2026-08-05 · 25H2 |
| R-05 | “Optimized CPU priority and delay time” | HKLM\SYSTEM\CurrentControlSet\Control\PriorityControl\Win32PrioritySeparation | MS-DOC | Default 0x2. A six-bit field, AABBCC: interval length, variable or fixed, and the foreground-to-background quantum ratio. The Programs radio button writes 100110b; Background services writes 011000b. | NT 4.0 (meaning changed) | DEPENDS | Condition: where the work is. Microsoft documents that the same default value 0x2 means shorter variable intervals favouring the foreground on client SKUs and longer fixed intervals with equal treatment on server. Neither setting creates processor time; it reallocates it. | [26][87] | 2008 | 2026-08-05 · 25H2 | |
| R-06 | “Our helper loads into every process that starts” | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs | MS-DOC | “Starting in Windows 8, the AppInit_DLLs infrastructure is disabled when secure boot is enabled.” And: “usage of AppInit_DLLs is not recommended.” | Win8 | SUPERSEDED‡ | On a machine with Secure Boot on, the value is not read and the product silently does nothing. Microsoft also states that even legitimate AppInit DLLs “can unintentionally cause system deadlocks and performance problems.” | [23] | — | 2026-08-05 · 25H2 | |
| R-07 | “Block a program from ever launching again” | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<exe>\Debugger | MS-DOC | Key absent. Microsoft documents the value as a way to “Specify a debugger to use when starting a program”: a REG_SZ holding the full path to a debugger, which Windows launches in place of the named executable. | — | TRADE | It works, and the cost is that the named process is now launched under whatever the value points at. Sysinternals Autoruns enumerates this surface under the name “image hijacks”, which is what it is when somebody else writes it. | [24][80] | — | 2026-08-05 · 25H2 | |
| R-08 | “Turn off last-access timestamps for a faster disk” | HKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate | MS-DOC | “In Windows 10 v1803 operating system and later… The NtfsDisableLastAccessUpdate value is now treated as a bitfield”, including 0x2, System managed. On servers, and on clients whose boot volume exceeds the policy threshold, updates are already disabled. | 1803 (bitfield) · 2004 (128 GB fallback retired) | SUPERSEDED | On most current machines Windows has already made this decision. Note that the fsutil reference is stale here and still documents only the old 1/0 form; the accurate source is the file-system protocol specification. | [27][28] | — | 2026-08-05 · 25H2 | |
| R-09 | “Automatically close applications that stop responding” | HKCU\Control Panel\Desktop\AutoEndTasks · WaitToKillAppTimeout · HungAppTimeout | MS-DOC | AutoEndTasks 0 — “Processes do not end automatically.” WaitToKillAppTimeout 20000 (20 seconds). HungAppTimeout 5000. All three REG_SZ under the same key, documented for Windows 2000 and Windows Server 2003. | — (documented for Windows 2000) | TRADE | Logoff and shutdown get shorter, and a process that has not finished writing is ended without the End Task dialog appearing. The saving is measured in seconds of shutdown; the cost is unsaved data, and both are documented on the same pages. | [29][30][31][87] | 2008 | 2026-08-05 · 25H2 | |
| R-10 | “User Account Control management” | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System → EnableLUA, ConsentPromptBehaviorAdmin, PromptOnSecureDesktop | MS-DOC | EnableLUA 1, ConsentPromptBehaviorAdmin 5 (prompt for consent for non-Windows binaries), PromptOnSecureDesktop 1, EnableVirtualization 1. Every UAC value and its default is tabulated on one current Microsoft page. | — | TRADE | It works, and the cost is not performance. Setting EnableLUA to 0 disables Admin Approval Mode “and all related UAC policy settings”, and Windows Security notifies the user that overall security is reduced. UAC has never been a speed feature. | [32][88] | 2012 | 2026-08-05 · 25H2 | |
| R-11 | “Set the desktop icon cache size” | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Max Cached Icons | UNDOCUMENTED | Not stated anywhere Microsoft publishes. There is no Microsoft reference page for this value, no documented default, and no documented data type. | — | UNVERIFIED | There is no Microsoft-stated default to restore, so the change cannot be cleanly undone. Checked: learn.microsoft.com and support.microsoft.com searches for the value name; every result was a user-authored Microsoft Q&A thread, which is not documentation. | [87] | 2008 | 2026-08-05 · 25H2 | |
| R-12 | “Use free Windows 7 for 360 days” | slmgr.vbs /rearm · HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\SkipRearm | MS-DOC | “The activation grace period is typically 30 days… in Windows 7 and Windows Vista, there is a limit to the number of times Windows can be rearmed. Typically, a system can be rearmed only 3 times.” KB 929828: “The Rearm process can be run a maximum of three times in a Windows image.” | Win8 (“the Windows licensing state can be reset repeatedly”) | UNSAFE-CLAIM† | We state the documented limit and stop there. The archived help page for this feature offers a checkbox for having used it more than three times, taking it to twelve. We do not describe, endorse or test any method of exceeding the documented limit, and no Microsoft source documents a 360-day figure. | [34][35][95] | WIN8 | 2026-08-05 · 25H2 | |
| S-01 | “Optimize Windows services to speed up your computer” | HKLM\SYSTEM\CurrentControlSet\Services\<name>\Start = 4 | MS-DOC | 0 Boot, 1 System, 2 Automatic, 3 Demand, 4 Disabled. “The service is disabled and will not be loaded.” Attempts to start it return ERROR_SERVICE_DISABLED. | — | DEPENDS | Condition: which service. Microsoft publishes per-service recommendations for Windows Server 2016 with Desktop Experience and for Windows IoT Enterprise fixed-function devices. It publishes none for general-purpose Windows client, and says “We don’t recommend applying policies that disable services that aren’t by default by Microsoft.” | [36][37][41][42][88] | 2012 | 2026-08-05 · 25H2 | |
| S-02 | “Click Recommend and we select the unnecessary services” | The vendor’s own recommendation list, which was never published | UNDOCUMENTED | Microsoft’s only published service-disabling guidance is scoped, in its own words, to “Windows Server 2016 with Desktop Experience, unless you’re using it as a desktop replacement for end-users”, and its own affirmative disable list runs to two services. | Server 2019 (guidance became the defaults) | UNVERIFIED | Nobody outside the vendor can know which services a hidden list contains, which is preamble question 2 failing in one word. Checked: the Server 2016 guidance, the IoT Enterprise services guidance, and searches for a Windows 10 or 11 client equivalent, which does not exist. | [41][42][91] | WIN8 | 2026-08-05 · 25H2 | |
| S-03 | “Delay startup services so the desktop appears sooner” | ChangeServiceConfig2 with SERVICE_CONFIG_DELAYED_AUTO_START_INFO · sc config <name> start=delayed-auto | MS-DOC | fDelayedAutostart FALSE. When set, “the ServiceMain thread for the service is started with THREAD_PRIORITY_LOWEST”, and is raised to normal only after the service reports SERVICE_RUNNING. | Vista / Server 2008 | TRADE | Logon feels faster and the service starts later at the lowest thread priority. Microsoft states the costs plainly: “There is no specific time guarantee as to when the service will be started”, and a delayed service cannot belong to a load-ordering group. | [38] | — | 2026-08-05 · 25H2 | |
| S-04 | “Stop services running when you do not need them” | SERVICE_TRIGGER via ChangeServiceConfig2 / SERVICE_CONFIG_TRIGGER_INFO · sc qtriggerinfo <name> | MS-DOC | “A service can register to be started or stopped when a trigger event occurs. This eliminates the need for services to start when the system starts… a service can start when it is needed.” | Win7 / Server 2008 R2 | SUPERSEDED | The operating system has shipped this since 2009, per service, with the trigger conditions inspectable from the command line. One documented limit worth knowing: “Trigger-start and trigger-stop requests are not guaranteed under low memory conditions.” | [39] | — | 2026-08-05 · 25H2 | |
| S-05 | “Group services into fewer processes to save memory” | svchost.exe process grouping · HKLM\SYSTEM\CurrentControlSet\Services\<name>\SvcHostSplitDisable | MS-DOC | “This change is automatic for systems with more than 3.5 GB of RAM running the Client Desktop SKU. On systems with 3.5 GB or less RAM, we’ll continue to group services into a shared SvcHost process.” | 1703 | DEPENDS | Condition: installed memory against the documented threshold, on Client Desktop SKUs only. Note that the widely cited value SvcHostSplitThresholdInKB with a default of 3670016 appears in no Microsoft source we could find; the value Microsoft does document is the per-service SvcHostSplitDisable. | [40] | — | 2026-08-05 · 25H2 | |
| S-06 | “Disable the search indexer to make the machine faster” | HKLM\SYSTEM\CurrentControlSet\Services\WSearch\Start | MS-KB | Automatic (Delayed Start) on Windows client; Manual on Windows IoT Enterprise; already Disabled on Windows Server 2016 with Desktop Experience. Microsoft documents the indexer as self-throttling: it stops when disk or CPU use is high and pauses on battery. | — | Items indexed. Microsoft: “fewer than 30,000 items” on a typical user’s computer; “If the Indexer indexes more than 400,000 items, you may begin to see performance issues”; hard limit about 1,000,000. | TRADE | Start menu and File Explorer stop returning content results, and Microsoft names this behaviour directly: “Some anti-virus programs and ‘Optimize your PC’ applications disable the Windows Search service. We recommend that you don’t run such applications if you want to use Search.” | [42][43] | — | 2026-08-05 · 25H2 |
| S-07 | “Disable SysMain, it is pointless on an SSD” | HKLM\SYSTEM\CurrentControlSet\Services\SysMain\Start | MS-DOC | Automatic on the client family, where Microsoft’s current guidance marks it “Don’t disable”. Since Windows 7: “Windows will disable Superfetch, ReadyBoost, as well as boot and application launch prefetching on SSDs with good random read, random write and flush performance.” | Vista (introduced) · Win7 (SSD auto-disable) | DEPENDS | Condition: the system disk, and Windows already decides it per drive by benchmarking random reads. Microsoft has never recommended that an administrator make this decision by hand, and its two published positions — the 2009 auto-disable and the current “Don’t disable” — have never been reconciled in writing. | [13][14][15][42] | — | 2026-08-05 · 25H2 | |
| S-08 | “Turn off Windows Update to stop background disk activity” | HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\Start | MS-DOC | Manual. “Disabling Windows Update service prevents Windows Update, its automatic updating feature, and programs aren’t able to use the Windows Update Agent (WUA) API.” | — | TRADE | Background disk and network activity stop, and so do security updates. The second cost is less obvious and is documented: any installer or management tool that calls the WUA API fails, which is a support call nobody connects back to this change. | [42] | — | 2026-08-05 · 25H2 | |
| S-09 | “Auto-set the transmission unit cache size” | HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TcpWindowSize | MS-DOC | “This registry setting is ignored by this version of Windows and is consuming a small amount of extra space in the registry.” The Next Generation TCP/IP stack derives the receive window continuously from the measured bandwidth-delay product per connection. | Vista | SUPERSEDED‡ | The value does nothing at all; the machine’s actual receive window is set by Receive Window Auto-Tuning. This is the cleanest case in the table: a 2008 product advertised tuning by hand a number that Windows had derived automatically since 2006. | [82][83][87] | 2008 | 2026-08-05 · 25H2 | |
| S-10 | “Turn off TCP auto-tuning to fix slow downloads” | netsh interface tcp set global autotuninglevel=<normal|restricted|highlyrestricted|experimental|disabled> | MS-DOC | “The default level is Normal.” Five levels, Normal 0x8 through Disabled. “Starting with Windows Server 2019, you can no longer use the registry to configure the TCP receive window size.” | Vista (auto-tuning) · Server 2019 (registry route removed) | DEPENDS | Condition, and it is narrow: an intermediate device that does not comply with RFC 1323 window scaling. Microsoft documents disabling auto-tuning as a workaround for exactly that case, in KB 947239, and for no other. Note the popular “Microsoft says never disable it” quotation is from a blog post that no longer resolves. | [81][97] | — | 2026-08-05 · 25H2 | |
| S-11 | “Auto-set maximum transmission unit and segment size” | netsh interface ipv4 set subinterface mtu= · HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnablePMTUDiscovery | MS-KB | The netsh MTU default is “the natural MTU of the link” and store=active is not persistent. EnablePMTUDiscovery default 1: “If you set this parameter to 0, an MTU of 576 bytes is used for all connections that are not to computers on the local subnet.” | — (parameter reference never republished past XP) | DEPENDS | Condition: a path that silently drops ICMP fragmentation-needed messages, which is the only situation where a hand-set MTU beats discovery. Set it wrong and every connection off the local subnet runs at 576 bytes, which is a documented, permanent slowdown. | [84][85][87] | 2008 | 2026-08-05 · 25H2 | |
| S-12 | “Reclaim the 20% of bandwidth Windows reserves” | Software\Policies\Microsoft\Windows\Psched\NonBestEffortLimit (“Limit reservable bandwidth”) | MS-DOC | “By default, the Packet Scheduler limits the system to 80 percent of the bandwidth of a connection.” The policy is a ceiling on what programs may reserve, not a standing deduction from the link. | — | UNVERIFIED | The figure on the live Microsoft page is 80, not 20, and it describes a different thing from the folklore. The sentence everyone quotes to debunk this — that all bandwidth is available unless a program requests priority — was in KB 316666, which now returns 404. No live Microsoft page addresses the claim. | [86] | — | 2026-08-05 · 25H2 | |
| B-01 | “Use all your CPU cores at boot” | BCD element numproc · bcdedit /set numproc · msconfig → Boot → Advanced options | MS-DOC | Unset. The element is documented as “numproc [integer] Uses only the specified number of processors”, inside a reference Microsoft introduces as “boot options… related to developing, testing, and debugging drivers.” | Vista / Server 2008 | NO-OP | The word is only. The element is a cap: setting it can reduce the processors the system uses and can never raise the number, so there is nothing to unlock. Microsoft documents the BCD element and not the msconfig checkbox, and we do not assert the unchecked state beyond that. | [44][45][90] | WIN8 | 2026-08-05 · 25H2 | |
| B-02 | “Optimize computer boot speed” | HKLM and HKCU \SOFTWARE\Microsoft\Windows\CurrentVersion\Run · the Startup folders · Task Manager → Startup | MS-DOC | Since Windows 8 the Startup tab computes an impact rating in-box, from the same three locations the archived vendor help page describes its own boot module editing. | Win8 | Startup impact, as Microsoft defines it: High is more than 1 second of CPU time or more than 3 MB of disk I/O at startup; Medium is 300–1000 ms CPU or 300 KB–3 MB disk I/O; Low is under 300 ms and under 300 KB. | SUPERSEDED | The feature the suites charged for shipped in the box, better instrumented, in 2012. The in-box list has one documented gap and it is the same gap the paid tools had: it covers Run, RunOnce and the Startup folders only, not scheduled tasks and not Group Policy. | [52][22][88] | 2012 | 2026-08-05 · 25H2 |
| B-03 | “Shut down and start up in seconds” | Fast Startup / hybrid shutdown · hiberfil.sys | MS-DOC | “Fast Startup is enabled by default in Windows.” At shutdown Windows closes all applications, logs off all user sessions, then “saves the kernel memory image (including the loaded kernel-mode drivers) in Hiberfil.sys”. | Win8 | SUPERSEDED | Two documented consequences readers should hold together: “The Fast Startup setting doesn’t apply to Restart”, so a restart is still a cold boot; and every boot-time figure published after 2012 measures a different operation from the ones published before it, which makes cross-era comparisons meaningless. | [46][47][88] | 2012 | 2026-08-05 · 25H2 | |
| B-04 | “Force a better system timer for a faster machine” | bcdedit /set useplatformclock · bcdedit /set disabledynamictick | MS-DOC | Both unset. Microsoft attaches the identical note to each: “This option should only be used for debugging.” useplatformclock “Forces the use of the platform clock as the system’s performance counter.” | — | UNVERIFIED | No Microsoft source supports a performance claim for either element, and the only characterisation given is debugging-only. Checked: the bcdedit /set reference, the BCD boot options reference, the bcdedit command-line options page. Reverting is documented: /deletevalue. | [44][45] | — | 2026-08-05 · 25H2 | |
| B-05 | “We measured your boot time and it is too slow” | Diagnostics-Performance operational log, event ID 100 → BootTime, MainPathBootTime, BootPostBootTime | UNDOCUMENTED | The Windows ADK defines the analogous assessment metrics — Main Path Boot Duration, Post On/Off Duration, Total Boot [Excluding BIOS] Duration — but it does not define the event-log field names, and no Microsoft page does. | Win8 / Win10 (assessment scope) | UNVERIFIED | A number quoted from a field nobody documents cannot be checked against anything. Checked: the ADK assessment page, the WPT on/off transition recording page, and the TechNet Wiki archive for event 100, which tabulates the event but defines no timing field. The only Microsoft text relating them is an archived forum post carrying an as-is disclaimer. | [48] | — | 2026-08-05 · 25H2 | |
| B-06 | “Defragment your boot files so Windows starts faster” | HKLM\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction\Enable · defrag /b | MS-DOC | “If the entry is set to Y, Windows automatically optimizes the file location for boot optimization. This optimization occurs automatically if the system is idle for 10 minutes.” The current defrag reference documents /b and a weekly maintenance task, and never mentions this key. | Server 2003 | SUPERSEDED‡ | Windows has done this on an idle timer since the Dfrg.msc era, so a product selling it was selling a scheduled task. The registry key is documented only for Windows Server 2003 and the page is archived; do not read it as current behaviour. | [49][50][88] | 2012 | 2026-08-05 · 25H2 | |
| B-07 | “Our driver reaches parts of Windows other tools cannot” | HKLM\SYSTEM\CurrentControlSet\Services\<driver>\Start = 0 or 1, loading a kernel-mode driver | MS-DOC | “Starting with Windows 10, version 1607, Windows will not load any new kernel-mode drivers which are not signed by the Dev Portal.” 64-bit Windows has enforced kernel-mode code signing since Windows Vista. | Vista x64 · 1607 with Secure Boot on | DEPENDS | Condition, and Microsoft states it exactly: cross-signed drivers still load if Secure Boot is off in the BIOS, if the machine was upgraded in place to 1607 from an earlier release, or if the signing certificate was issued before 2015-07-29. This is the change that quietly ended a whole product category, and it ended it conditionally. | [51] | — | 2026-08-05 · 25H2 | |
| B-08 | “Unlock more memory for your programs” | bcdedit /set increaseuserva · the /3GB switch in Boot.ini on Server 2003 and XP | MS-DOC | Unset: on 32-bit Windows the split is 2 GB user and 2 GB system. “On 64-bit editions of Windows, 32-bit applications marked with the IMAGE_FILE_LARGE_ADDRESS_AWARE flag have 4 GB of address space available” with no boot flag at all. | Server 2003 / XP (/3GB) · 64-bit Windows (unnecessary) | User-mode virtual address space on 32-bit Windows: from 2048 MB to a maximum of 3072 MB, and only for images linked large-address-aware. On 64-bit Windows the setting has nothing to give. | SUPERSEDED‡ | Microsoft names the cost on the same page: with the split moved, “the file cache, paged pool, and nonpaged pool are smaller, which can adversely affect applications with heavy networking or I/O.” On a 64-bit machine there is no upside to trade against that. | [53][44] | — | 2026-08-05 · 25H2 |
| D-01 | “Scan and clean up computer junk files” | cleanmgr /sageset:n and /sagerun:n · HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches | MS-DOC | Disk Cleanup ships in Windows, stores per-profile selections as StateFlagsNNNN under VolumeCaches, and is still recommended by Microsoft where Storage Sense is unavailable. Its own guidance on temporary files: “You can safely delete temporary files that haven’t been modified within the last week.” | 1903 (Storage Sense policies) | SUPERSEDED | The scriptable version of this has been in the box since Windows 2000 and is free. One correction we owe the record: Microsoft has not deprecated Disk Cleanup. It is on neither the deprecated-features nor the removed-features list, and the widely repeated 2018 deprecation is not on any Microsoft page we could load. | [54][55][88] | 2012 | 2026-08-05 · 25H2 | |
| D-02 | “Windows never cleans up after itself” | Storage Sense · ConfigStorageSenseGlobalCadence · ConfigStorageSenseRecycleBinCleanupThreshold · ConfigStorageSenseDownloadsCleanupThreshold | MS-DOC | “Storage Sense is automatically turned on when the machine runs into low disk space and is set to run whenever the machine runs into storage pressure.” Temporary-file cleanup defaults to on. | 1903 | Recycle Bin: files older than 30 days, by default. Downloads: 0, meaning never. Cloud content dehydration: 0, meaning never. | TRADE | It runs for free and it deliberately leaves alone the two folders most likely to be large. Microsoft states it: “items in your Downloads folder and OneDrive… will not be touched unless you set up Storage Sense to do so.” That is the gap a paid cleaner is actually filling, and you can close it in Settings. | [56] | — | 2026-08-05 · 25H2 |
| D-03 | “Your WinSxS folder is 12 GB and can be cleaned” | DISM /Online /Cleanup-Image /AnalyzeComponentStore and /StartComponentCleanup | MS-DOC | “Some tools, such as the File Explorer, determine the size of directories without taking into account that the contained files might be hard linked, which might lead you to think that the WinSxS folder takes up more disk space than it really does.” A scheduled task already runs the cleanup, waiting at least 30 days after an updated component is installed. | Win10 | AnalyzeComponentStore reports three separate numbers: Windows Explorer Reported Size, which “doesn’t factor in the use of hard links”; Actual Size, which does; and Shared with Windows, which “shouldn’t be considered part of the component store overhead”. | SUPERSEDED | Any figure produced by measuring the folder in Explorer is inflated by hard links, so the headline number in the sales pitch is an artefact of the measuring method. Running /ResetBase to squeeze more out of it means “All existing update packages can’t be uninstalled after this command is completed.” | [57][58][88] | 2012 | 2026-08-05 · 25H2 |
| D-04 | “Delete the Prefetch folder to free space and speed up Windows” | %SystemRoot%\Prefetch\*.pf · %SystemRoot%\Prefetch\Layout.ini | MS-DOC | “When an application is launched the prefetcher looks in the prefetch directory to determine whether a .pf file is present… If the .pf file exists, the kernel component of the prefetcher issues asynchronous IOs to prefetch metadata, data, and image pages described in the trace file.” Layout.ini is regenerated every 72 hours during idle. | — | HARMFUL | The mechanism of the loss is on the same page: a launch with no trace file gets no prefetch, so the next few launches of every deleted application are slower until the traces are rebuilt. No Microsoft guidance has ever recommended deleting this folder, and the space it occupies is small. | [59] | — | 2026-08-05 · 25H2 | |
| D-05 | “Defragment your SSD for peak performance” | defrag /o · Optimize-Volume · the weekly Optimize Drives maintenance task | MS-DOC | Windows already runs optimisation as a maintenance task, “typically… every week”. For SSDs it performs retrim, and traditional defragmentation “is done once per month… Changing the frequency of the scheduled task doesn’t affect the once per month cadence for the SSDs.” Optimize-Volume on a TRIM-capable SSD defaults to -Retrim alone. | — | SUPERSEDED | Running a manual traditional defragmentation on an SSD is documented to make the next scheduled run skip it. Microsoft’s own table says an SSD without TRIM support gets “No operation” — there is nothing for a third-party tool to add. | [50][60] | — | 2026-08-05 · 25H2 | |
| D-06 | “Immunize the disk partition against autorun viruses” | An undeletable autorun.inf directory at each volume root · HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun | MS-DOC | Microsoft documents two values that persistently disable AutoRun, NoDriveAutoRun and NoDriveTypeAutoRun, and warns: “Applications should not modify these values, as there is no way to reliably restore them to their original values.” The directory trick is not documented anywhere. | — | UNVERIFIED | Occupying the filename with a folder is a real technique with no Microsoft documentation, and the update usually cited as having ended the threat, KB 971029, now returns 404 at every support.microsoft.com URL we checked, in both its numeric and GUID forms. Checked: the AutoPlay registry page, both KB URLs, learn.microsoft.com searches. | [33][94] | WIN8 | 2026-08-05 · 25H2 | |
| D-07 | “Free gigabytes by turning off hibernation” | powercfg /hibernate off · /size · /type reduced · HKLM\SYSTEM\CurrentControlSet\Control\Power\HiberFileSizePercent | MS-DOC | “The default size cannot be smaller than 50” percent of total memory, and “a hiberfile that has a custom default size, or HiberFileSizePercent >= 40, is considered as a full hiberfile.” Microsoft does not publish a single default percentage; it states the file grows in direct proportion to installed RAM. | — | Microsoft’s own Windows 10 1607 measurements: /h off saves more than 825 MB on x86 with 2 GB of RAM and more than 1.5 GB on x64 with 4 GB. /h /type reduced saves more than 400 MB and more than 930 MB respectively. | TRADE | Hibernation goes, and so does Fast Startup, because hibernating the kernel session at shutdown is what writes that file. On a machine where Fast Startup was the thing making boots feel quick, this trades disk space for the boot time the same tool is selling. | [61][58] | — | 2026-08-05 · 25H2 |
| D-08 | “Clean system trace files” | %LOCALAPPDATA%\CrashDumps · HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps | MS-DOC | “This feature is not enabled by default.” When an administrator does enable it, DumpCount defaults to 10 and “when the maximum value is exceeded, the oldest dump file in the folder will be replaced with the new dump file.” | Vista SP1 / Server 2008 | NO-OP | Local user-mode crash dumps are off unless somebody turned them on, and when on the folder caps itself. A cleaner reporting recovered space here is reporting on a folder that was already self-limiting, or empty. | [62][88] | 2012 | 2026-08-05 · 25H2 | |
| D-09 | “Delete SoftwareDistribution to reclaim update space” | %SystemRoot%\SoftwareDistribution\Download · %SystemRoot%\SoftwareDistribution\DataStore | MS-DOC | Microsoft documents removing this folder only as a Windows Update repair step, behind an explicit caution that it “should only be performed at this point in the troubleshooting if you can’t resolve your Windows Update issues after following all steps”. Its manual procedure renames rather than deletes. | — | DEPENDS | Condition: whether Windows Update is actually broken. There is no documented size cap or purge schedule for this cache and no Microsoft statement that clearing it is safe routine maintenance, so a cleaner that empties it on a schedule is running a repair procedure on a machine that is not broken. | [63] | — | 2026-08-05 · 25H2 | |
| D-10 | “Windows is hiding gigabytes from you in reserved storage” | DISM /Online /Set-ReservedStorageState /State:Disabled · /Get-ReservedStorageState | MS-DOC | “Reserved storage increases the likelihood that Windows updates can be downloaded and installed without users having to free disk space.” It works out of the box on devices that connect directly to Windows Update, and not automatically under WSUS or Configuration Manager. | 1903 (feature) · 2004 (DISM commands) | UNVERIFIED | The size is the whole claim and Microsoft states no size anywhere we could load — not on the DISM page and not on the support page. What is documented cuts against the framing: “When your device is low on space, Windows will clear reserved storage so it can be used for other processes.” Checked: both pages and the Dism PowerShell module. | [64] | — | 2026-08-05 · 25H2 | |
| A-01 | “Manage every program that starts with Windows” | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run · HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | MS-DOC | “The Run key makes the program run every time the user logs on.” Two documented properties people get wrong: “the order in which those programs run is indeterminate”, and “the system may choose to delay the execution of programs in the Run key and in the Startup group.” | — | TRADE | Editing these two keys works and is the single most defensible intervention in the whole category. The cost is that they are two of at least sixteen documented autostart surfaces, so a manager that reads only these will report a machine as clean when it is not. | [22][80][87] | 2008 | 2026-08-05 · 25H2 | |
| A-02 | “Remove leftover one-time startup entries” | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce · HKCU\...\RunOnce | MS-DOC | “By default, the value of a RunOnce key is deleted before the command line is run.” A leading ! defers deletion until after the command runs; a leading * forces the entry to run in Safe Mode, where these keys are otherwise ignored. | — | NO-OP | The entry deletes itself before it executes, so on a healthy machine there is nothing left to clean. The exception is the one worth knowing: an entry prefixed with ! survives its own run, and that is the case a cleanup is actually for. | [22] | — | 2026-08-05 · 25H2 | |
| A-03 | “Clear out your startup folder” | %APPDATA%\Microsoft\Windows\Start Menu\Programs\StartUp · %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\StartUp | MS-DOC | FOLDERID_Startup is per-user; FOLDERID_CommonStartup is machine-wide. Microsoft documents both with their default paths and their legacy pre-Vista equivalents. | Vista (path form) | TRADE | Removing a shortcut works, is instantly reversible, and needs no tool. The cost is a category error people make constantly: these are two different folders, and clearing the per-user one leaves everything an installer put in the all-users one. | [65] | — | 2026-08-05 · 25H2 | |
| A-04 | “One list shows everything that runs at logon” | Task Scheduler triggers TASK_TRIGGER_BOOT (8) and TASK_TRIGGER_LOGON (9) · %SystemRoot%\System32\Tasks | MS-DOC | “Triggers the task when the computer boots” and “Triggers the task when a specific user logs on.” Task Manager’s Startup tab, which Microsoft documents, covers Run, RunOnce and the Startup folders and nothing else. | Vista / Server 2008 | DEPENDS | Condition: whether the list includes scheduled tasks. This is the surface most consumer startup managers miss, and it is where a modern updater or telemetry component usually lives, so the answer to “why is something still running?” is very often here. | [66][52][80] | — | 2026-08-05 · 25H2 | |
| A-05 | “Nothing on this machine is set to start automatically” | root\subscription → __EventFilter, CommandLineEventConsumer, __FilterToConsumerBinding | MS-DOC | “The CommandLineEventConsumer class starts an arbitrary process in the local system when an event is delivered to it”, and a permanent consumer “operates and receives events after it is created and even after a reboot of the operating system as long as WMI is running.” | Vista (runs as LocalSystem in session 0) | UNVERIFIED | A clean-bill-of-health sentence cannot be supported by a tool that does not enumerate this namespace, and we could not confirm from any published capability list that consumer optimisers do. Autoruns publishes its coverage as a switch, autorunsc -m, which is the comparison. | [67][80] | — | 2026-08-05 · 25H2 | |
| A-06 | “Speed up Explorer by removing shell extensions” | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved | MS-DOC | “The system stores entries representing approved user interface extensions on a system in the following registry key.” The list is only consulted when an administrator turns on EnforceShellExtensionSecurity. | — | DEPENDS | Condition: EnforceShellExtensionSecurity. With it off — which is the ordinary state — removing an entry from the Approved list changes nothing, because nothing is checking the list. A tool that reports the removal as a fix has reported a fix that did not happen. | [68] | — | 2026-08-05 · 25H2 | |
| A-07 | “Remove browser add-ons that are slowing you down” | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects | MS-DOC | “If this key exists and there are CLSIDs listed underneath it, then Internet Explorer uses that information to create an instance of each object.” Internet Explorer 11 ended support on 2022-06-15 and “has been permanently disabled on certain versions of Windows 10.” | 2022-06-15 | NO-OP‡ | The only program documented to read this key is retired and disabled, so entries under it are inert. We stop short of the obvious next sentence: we found no Microsoft statement that Microsoft Edge ignores this key, only that Internet Explorer is gone. | [69][70] | — | 2026-08-05 · 25H2 | |
| A-08 | “Our tool loads before anything else on the system” | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute | SYSINTERNALS | A MULTI_SZ “contains the names and arguments of programs that are executed by Session Manager”, typically holding Autocheck Autochk *. It runs between the loading of boot and system-start drivers and the enabling of paging, and Session Manager resolves the names against system32. | — | TRADE | Nothing loads earlier in user mode, and that is exactly the cost: a program here runs before paging is enabled, with no user-mode environment around it. Microsoft warns against removing the default value, and a machine that never runs autochk never checks its file system at boot. | [71][80] | — | 2026-08-05 · 25H2 | |
| A-09 | “Replace the Windows shell with a faster one” | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon → Shell, Userinit | MS-KB | Shell = explorer.exe and Userinit = C:\windows\system32\userinit.exe. “Winlogon service tries to load the Windows default shell (explorer.exe) and user shell (userinit.exe) from registry” at this path. | — | HARMFUL | The mechanism of the loss is that these two values are load-bearing for logon itself. If either does not resolve, Winlogon cannot start the shell and the user cannot log in — which is why the Microsoft page documenting the correct values is a logon-failure article rather than a customisation guide. | [72][80] | — | 2026-08-05 · 25H2 | |
| A-10 | “Preload system DLLs so programs launch faster” | HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs | MS-DOC | “If the DLL is on the list of known DLLs… then the system uses its copy of the known DLL.” Known DLLs is step 5 of the documented search order, ahead of the application folder and the system folder. Safe DLL search mode is on by default. | — | UNVERIFIED | What is documented is the list’s position in the loader’s search order, not a preload. We could not confirm from any primary source that adding an entry changes launch time, and adding one changes which copy of a DLL every process resolves to. Checked: the DLL search order page, both packaged and unpackaged orders, the Session Manager references. | [73][80] | — | 2026-08-05 · 25H2 | |
| A-11 | “Install our layer to optimise your network” | Winsock Layered Service Providers · the Winsock catalog | MS-DOC | “Layered Service Providers are deprecated. Starting with Windows 8 and Windows Server 2012, use Windows Filtering Platform.” Uncategorised providers “will not be loaded in services or system processes” including lsass, winlogon and many svchost processes. | Win8 | SUPERSEDED‡ | The platform replaced this with the Windows Filtering Platform more than a decade ago, and an uncategorised provider is already excluded from the processes that matter most. A broken chain here historically took the machine’s networking with it. | [74][80] | — | 2026-08-05 · 25H2 | |
| A-12 | “Repair your Windows logon and password security” | HKLM\SYSTEM\CurrentControlSet\Control\Lsa → Security Packages, Notification Packages | MS-DOC | A REG_MULTI_SZ list of DLL names without the extension. “Each time the system starts, the LSA loads the SSP/AP DLLs in this list.” Separately: “Windows doesn’t support removing, replacing, or wrapping inbox security packages… As of January 10, 2017, Windows prevents these actions.” | Win8.1 · 2017-01-10 | HARMFUL | The mechanism of the loss is that this list is loaded into the Local Security Authority at every boot. A DLL here that is missing, wrong or unloadable does not degrade logon, it prevents it, and the failure appears before there is a desktop to run a repair tool on. | [75][96][80] | — | 2026-08-05 · 25H2 | |
| A-13 | “Clean up printer drivers to fix a slow spooler” | HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\<name>\Driver | MS-KB | Each monitor is a subkey with a Driver value naming a user-mode DLL the spooler loads; the in-box example is Standard TCP/IP Port pointing at tcpmon.dll. Installing one requires SeLoadDriverPrivilege and the file must be in system32. | — | DEPENDS | Condition: whether the DLL a monitor names is still on disk. Microsoft’s documented failure here is a spooler crash caused by a leftover monitor entry, which means this is one of the few rows where a genuine leftover really does break something — and removing the wrong one breaks printing. | [76][80] | — | 2026-08-05 · 25H2 | |
| A-14 | “Remove desktop gadgets that slow your machine” | HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar\TurnOffSidebar | MS-DOC | Security Advisory 2719662, published 2012-07-10, shipped an automated solution that “disables Windows Sidebar and Gadgets on supported editions of Windows Vista and Windows 7”. Windows 8 went further: “we have chosen to remove Gadgets from the operating system entirely.” | Win8 | SUPERSEDED‡ | Microsoft disabled this in 2012 and removed it in Windows 8, so on any supported build there is nothing here to clean. The row is kept because the surface is still enumerated by Autoruns and still appears in tool feature lists. | [77][78][80] | — | 2026-08-05 · 25H2 | |
| A-15 | “Install our codec pack to speed up video playback” | HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 | MS-DOC | Documented only incidentally, inside an audio-compression API reference: “The lParam parameter is a registry value name in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32. The value identifies a DLL that implements an ACM codec.” | — | UNVERIFIED | No Microsoft page treats this key as a subject: there is no documented layout, no enumeration of the value-name prefixes, and no statement about when entries are loaded. Checked: the ACM API reference, the multimedia reference pages, learn.microsoft.com searches for the key path. | [79][80] | — | 2026-08-05 · 25H2 | |
| A-16 | “One list of everything that starts, with nothing hidden” | Sysinternals Autoruns · autorunsc -a * | SYSINTERNALS | Autoruns publishes its own coverage as command-line switches: b boot execute, d AppInit DLLs, e Explorer add-ons, g sidebar gadgets, h image hijacks, i IE add-ons, k known DLLs, l logon, m WMI, n Winsock providers, o codecs, p printer monitor DLLs, r LSA providers, s services and drivers, t scheduled tasks, w Winlogon. | — | TRADE | It is free, it is Microsoft’s, and it will show you dozens of entries you do not recognise and cannot safely remove — it names surfaces, it does not render verdicts. That is the trade, and publishing the boundary is the difference between this tool and everything else in this table. | [80] | — | 2026-08-05 · 25H2 |
§4What this Ledger covers, and what it does not
Declaring the boundary is the second question in the preamble, so it would be indefensible not to answer it here. Autoruns publishes its coverage as command-line switches; this is ours.
Covered. These surfaces are in scope, are documented above where a row exists, and will accumulate rows as articles are published:
HKLM and HKCU Run and RunOnce · the per-user and all-users Startup folders · services and their Start values · drivers · scheduled tasks · trigger-start registrations · WMI permanent event subscriptions · shell extensions · browser helper objects · AppInit_DLLs · image file execution options · BootExecute · Winlogon Shell and Userinit · KnownDLLs · Winsock protocol and network providers · LSA security packages · codecs registered under Drivers32 · printer monitor DLLs · sidebar gadgets · the Memory Management key · PrefetchParameters · TCP autotuning levels · the component store · page file settings · power schemes · the boot configuration store
Not covered, and this list is as binding as the first one:
- Anything that would require us to execute a binary we do not possess. We have not run Windows Winset, we do not hold a copy, we will not obtain one and we would not distribute it if we had it. Every statement in the table about what a product claimed is sourced to an archived page; every statement about what a surface does is sourced to documentation. There is no third category here and there never will be.
- Anything vendor-proprietary with no public documentation. If a tool writes to a key it invented, we have no way to describe what it does and we do not guess. This is why UNDOCUMENTED appears in column 4 rather than an adjective.
- Server SKUs. Several rows below cite Windows Server documentation because it is the only documentation that exists — Microsoft’s service-disabling guidance is scoped to Windows Server 2016 with Desktop Experience, and its page-combining defaults are stated for Server and not for client. Where that happens the row says so. We do not publish verdicts for server deployments.
- Hardware. Storage controllers, firmware, thermal throttling and drive health. One row is marked HARDWARE to make the category visible, and that is the extent of it.
- Third-party antivirus, VPN and browser internals. Adjacent, frequently the actual cause of a slow machine, and a different publication.
- Windows 10 and 11 feature-update regressions. Real, often correctly diagnosed by the people complaining, and not a documented surface. A regression is an event, not a mechanism, and it belongs in an article with a date on it.
when the computer be used for a period of time, the registry becomes very large, serious impact on computer speedArchived vendor help topic, tlwinset.com/wineb/wh16.htm, capture 2013-09-24. Checked 2026-08-05 · Ledger row R-01
The premise in that card is the reason the whole category exists, and Microsoft documents that it stopped being true a very long time ago. The registry size quota is a Windows 2000 concept; from Windows XP and Windows Server 2003 the documentation states there are no explicit limits on the space hives may consume. Row R-01 carries the detail, including the one place the old quota is still honoured if an administrator sets it deliberately.
§5Sources
Numbered, keyed from column 10. Primary sources preferred throughout: Microsoft documentation first, Microsoft KB and Sysinternals second, archived Microsoft material where nothing current exists, and archived vendor pages only for what a vendor claimed. Every one of these was fetched by us on 2026-08-05, which is the access date for all of them, and several are in the table specifically because the fetch failed or the page had been unpublished.
- EmptyWorkingSet function (psapi.h)
- SetProcessWorkingSetSize function (memoryapi.h)
- MEMORYSTATUSEX structure (sysinfoapi.h)
- Memory object performance counters, including Available Bytes (archived, Windows Server 2003)
- Enable-MMAgent (MMAgent module)
- Cache and memory manager improvements in Windows Server
- Memory compression in Windows 10 RTM, with the Windows kernel team
- How to determine the appropriate page file size for 64-bit versions of Windows
- Introduction to the page file
- Shutdown: Clear virtual memory pagefile
- DisablePagingExecutive (archived, Windows Server 2003)
- Kernel Trace Control API reference (Windows Performance Toolkit)
- ReadyBoost with an SD card or a flash drive
- Support and Q&A for solid-state drives (archived, Engineering Windows 7, 2009-05-05)
- Inside the Windows Vista Kernel, Part 2, Mark Russinovich
- RAMMap (Sysinternals)
- Disable Prefetch (archived, Windows Embedded Standard 7)
- Registry storage space
- Windows honors Registry Size Limit functionality if the key is set (KB 2567018)
- Microsoft support policy for the use of registry cleaning utilities (KB 2563254). Unpublished by Microsoft. Every live URL redirects to the generic Windows hub; this archived capture is the only readable form we found
- How Microsoft identifies malware and potentially unwanted applications
- Run and RunOnce registry keys
- AppInit DLLs and Secure Boot
- Debugging a service, which documents the Image File Execution Options Debugger value
- MenuShowDelay (archived, Windows 2000 Server registry reference)
- Win32PrioritySeparation (archived registry reference)
- [MS-FSA] Appendix A: Product Behavior — the only Microsoft source stating the 1803 last-access change
- fsutil behavior. Stale on last-access semantics; documents only the pre-1803 form
- AutoEndTasks (archived)
- WaitToKillAppTimeout (archived)
- HungAppTimeout (archived)
- User Account Control settings and configuration
- Enabling and disabling AutoRun
- SkipRearm (Windows unattend reference)
- Error when running sysprep /generalize (KB 929828), which states the three-rearm maximum
- CreateServiceW function
- The HKLM\SYSTEM\CurrentControlSet\Services registry tree
- SERVICE_DELAYED_AUTO_START_INFO structure
- Service trigger events
- Svchost.exe service refactoring
- Security guidelines for system services in Windows Server 2016. Server-scoped by its own statement
- Guidance on configuring system services (Windows IoT Enterprise, fixed-function devices)
- Windows Search performance issues (KB 4558579)
- BCDEdit /set
- BCD boot options reference
- Distinguishing fast startup from wake-from-hibernation
- Fast Startup causes system hibernation or shutdown to fail
- On/Off Transition Performance assessment (Windows ADK)
- Disk Defragmenter tools and settings (archived, Windows Server 2003)
- defrag
- Kernel-mode code signing policy (Windows Vista and later)
- Startup apps (Windows 8 developer cookbook), with the startup-impact thresholds
- 4-gigabyte tuning
- cleanmgr
- Automating the Disk Cleanup tool (KB 253597)
- Policy CSP — Storage, which carries the Storage Sense defaults
- Determine the actual size of the WinSxS folder
- Compact OS, single-instancing, and image optimization, which carries the hibernation and footprint measurements
- What is application launch prefetching? (archived Microsoft blog)
- Optimize-Volume, with the per-media-type defaults
- powercfg command-line options
- Collecting user-mode dumps
- Additional resources for Windows Update
- DISM storage reserve command-line options
- KNOWNFOLDERID, which gives both Startup folder paths
- TASK_TRIGGER_TYPE2 enumeration
- CommandLineEventConsumer class
- Only allow approved Shell extensions (archived)
- The basics of Browser Helper Objects (archived Microsoft blog)
- Internet Explorer and Microsoft Edge lifecycle FAQ
- Inside Native Applications, Mark Russinovich (Sysinternals)
- Cannot log on to Windows, which gives the Winlogon Shell and Userinit defaults. Carries Microsoft’s community-content disclaimer
- Dynamic-link library search order
- Categorizing Layered Service Providers and applications
- Registering SSP/AP DLLs
- Print spooler crashes (KB 947477), which gives the Print\Monitors key layout
- Microsoft Security Advisory 2719662, vulnerabilities in Gadgets
- Desktop gadgets removed (Windows 8 developer cookbook)
- acmDriverAdd function, the only Microsoft page naming Drivers32
- Autoruns for Windows (Sysinternals), with the autorunsc coverage switches
- Performance tuning network adapters, with the five auto-tuning levels and the default
- New networking features in Windows Server 2008 and Windows Vista (The Cable Guy, archived)
- SMB: No registry setting for tuning the TCP window size in TCP/IP should exist (archived)
- netsh interface ipv4 set subinterface (archived)
- TCP/IP and NBT configuration parameters (KB 314053). Scoped to Windows XP and never republished
- Policy CSP — ADMX_QoS, which states the 80 percent Packet Scheduler figure
- Archived Tenglnet product page, tlwinset.com/index.htm, capture 2008-10-24
- Archived Windows Winset capability index, tlwinset.com/help.htm, capture 2012-08-24
- Archived Windows8 Winset capability index, tlwinset.com/wineb/help.htm, capture 2013-09-22
- Archived help topic, boot speed, tlwinset.com/wineb/wh3.htm, capture 2013-09-24
- Archived help topic, services, tlwinset.com/wineb/wh5.htm, capture 2013-09-24
- Archived help topic, memory, tlwinset.com/wineb/wh6.htm, capture 2013-09-24
- Archived help topic, registry, tlwinset.com/wineb/wh16.htm, capture 2013-09-24
- Archived help topic, disk immunisation, tlwinset.com/wineb/wh19.htm, capture 2013-09-24
- Archived help topic, licensing, tlwinset.com/wineb/wh25.htm, capture 2013-09-24
- Restrictions around registering and installing a security package
- Receive Window Auto-Tuning for HTTP (KB 947239)
Four things this list records by their absence, each of which drove a verdict above. KB 2563254, the registry-cleaner support policy, is unpublished and readable only in an archive capture. KB 971029, the AutoRun restriction update, and KB 316666, the bandwidth-reservation explanation, both return 404 at every support.microsoft.com URL we checked, in numeric and GUID forms. And the Microsoft blog post everyone quotes for “never disable auto-tuning” now redirects to a landing page. A reference that cites sources it has not fetched cannot notice any of that, which is why every one above was fetched.
§6How a row changes, and where the old one goes
Every edit to a row is dated and kept at /mechanisms/changes/. Nothing here is silently revised: if a verdict moves, the old verdict stays on that page with the source that moved it. The log is live and empty at launch, which is the only honest state for a record that has recorded nothing yet.
The sixteen UNVERIFIED rows are restated as open questions at /mechanisms/unverified/, each with the single piece of evidence that would close it. If you hold one of those pieces the address is the contact form, corrections are published with the same prominence as the original claim, and whoever gets there first is credited in the body rather than in a footnote.
Once a row’s LAST VERIFIED date is more than a year old the row is drawn differently, so you can see at a glance which entries nobody has looked at lately and weigh them accordingly. That matters more here than it sounds: Microsoft unpublished its registry-cleaner support policy some time after December 2023, and a reference that cannot notice a source disappearing is not a reference.
You can use windows7 offers up 360 days free from this feature.Archived vendor help topic, tlwinset.com/wineb/wh25.htm, capture 2013-09-24. Checked 2026-08-05 · Ledger row R-12
Microsoft’s documented mechanism in that family is an activation grace period of typically thirty days plus a maximum of three rearms. The advertised figure is twelve times thirty. We state the documented limit as a fact, we state that the claim exceeds it, and we decline to describe any method of going further. Row R-12 is the only UNSAFE-CLAIM in the table.