Working Set tlwinset.com

How Windows actually works — the registry, prefetch, services, the memory manager — explained from documentation, so you can judge a speed-up claim yourself. We have not run the software we write about, and we say which parts we could not verify.

Subject  What each “make Windows faster” claim must be writing to, if it is true Covers  Memory manager · registry · services · boot · disk · autostart surfaces We ran it  No. We hold no copy and distribute none. Sourcing  Microsoft documentation, Microsoft KB, Sysinternals · archived vendor pages for claims only Ledger rows  68 · M-01 … A-16 Open questions  16  →  /mechanisms/unverified/ Published  2026-08-05   Last verified  2026-08-05 · documentation current for Windows 11 25H2

Every claim about making Windows faster is a claim about a specific key, API or service. This table names it.

The unit of a row here is not a product. It is a claim–surface pair: the thing optimisers sell, joined to the operating-system surface it must actually be writing to if the claim is true at all. Once the surface is named, the claim becomes checkable, because Microsoft documents most of these surfaces and documents what Windows does with them when nothing is installed.

Sixty-eight rows. Each carries the primary source, the documented default, the release at which the answer changed, and one verdict from a fixed vocabulary of eight. Where we could not confirm a mechanism from a primary source the verdict is UNVERIFIED and the row says what we checked. That happens sixteen times, which is the honest number and not a failure of effort.


§1Eight questions to ask before you install anything that promises speed

This is the standing preamble to the table, and it is the part worth memorising. It is a buyer’s test, not a technical one, and it works without any knowledge of Windows internals.

  1. Does it name the surface? A product that says it “cleans your registry” and never names a key is not describing a mechanism. Every row in this table names one, and if we could not name one the row says so.
  2. Does it publish a capability boundary? A list of exactly which autostart surfaces, services and keys it reads and writes. Sysinternals Autoruns publishes its list as command-line switches. Almost nothing else in this category publishes anything. Ours is at §4.
  3. Does the operating system already do this, and since which version? Column 6 exists because for most of these the answer is yes, and the date is usually earlier than the product that is selling it. Receive Window Auto-Tuning landed in Windows Vista; a 2008 feature list still advertised setting the transmission unit cache size by hand.
  4. Is the number falsifiable with an in-box counter? If nothing in Performance Monitor, Resource Monitor or the event log can confirm or refute the figure on the box, the figure is marketing. Column 7 is blank on most rows precisely because most claims name no counter.
  5. Does the scan report a count, or does it report details? A number of “issues” with no per-item path is not a diagnosis. This is the distinction regulators actually punished — not the failure to deliver speed, but the fabricated diagnosis. The scan is the product, and a count with no per-item path is the one part of the product a buyer has no way to check.
  6. Does the free scan find problems before it has read anything? The Federal Trade Commission’s 2019 Office Depot and Support.com order describes a “PC Health Check” whose result was driven by four yes/no questions the user answered before the scan began. Ticking any one box produced a malware-found report.
  7. Can you undo it, item by item, six months later? Backup before the change, per-change restore, and an export you can read in a text editor. A single “restore all” button is not the same thing, and neither is a backup format only the vendor can open.
  8. Who is the vendor, and does the answer stay the same on every page? A consistent answer is the cheapest trust signal there is, and its absence is information. The worked example is this domain’s own history: Tenglnet gives a Jaipur street address in the 2008 capture, the same street relocated to Washington DC in 2012, and a Chinese ICP number on the Windows 8 pages. We report the inconsistency; we draw no conclusion about intent, and none should be read into it.

Two things this preamble deliberately does not say. It does not say that optimisers make no difference — some rows below are TRADE, meaning the mechanism is real and the cost is named. And it does not cite Microsoft’s retired support policy for registry cleaning utilities as proof that cleaners do not work. That document is a support-scope and liability disclaimer. It says Microsoft does not support these tools and is not responsible for damage they cause; it never says they fail to speed up a PC, and anyone citing it as if it did is overreading it. We say so even though the overreading would suit us.


§2How to read a row

Twelve columns, fixed. The table is set to the full 84-character measure rather than the 68-character prose measure, and it is still wider than a phone. We chose to keep all twelve columns in one table rather than split rows into blocks on narrow screens, because the value of the artifact is the comparison across columns — reading down DOCUMENTED DEFAULT is the fastest way to learn what Windows already does. On a narrow screen the page scrolls sideways. No cell is truncated, hidden or collapsed at any width.

#ColumnWhat is in it
1IDStable. Cited from articles, never reused, never renumbered. /mechanisms/#S-04 is a permanent deep link
2THE CLAIM, AS SOLDTwelve words or fewer, in the seller’s framing, not ours
3SURFACE IT MUST TOUCHThe key, API, file, service or task. Full path, never truncated
4DOCUMENTED BYMS-DOC / MS-KB / SYSINTERNALS / THIRD-PARTY / UNDOCUMENTED, linked to the source
5DOCUMENTED DEFAULTWhat Windows does with nothing installed, and where that is written down
6VERSION BOUNDARYThe release at which the answer changed
7MEASURABLE EFFECTThe counter that would move, and by how much. Blank is the honest default and stays blank — it is blank on 60 of the 68 rows
8VERDICTOne of eight codes, below
9COST OF BEING WRONGWhat breaks if you apply it anyway
10SOURCESNumbered, keyed to §5, every one with an access date
11WINSET CLAIMEDWhether this domain’s own former product advertised it: 2008 / 2012 / WIN8 / , each linked to the capture
12LAST VERIFIEDISO date, and the build the documentation applies to

The verdict vocabulary is closed. There is no ninth code, and a row that does not fit one of these eight is a row we have not finished.

CodeRowsMeans
NO-OP5The surface is ignored on any supported Windows. Writing it changes nothing
SUPERSEDED14It did something once; the OS now does it. Version boundary mandatory
TRADE13It works, and it costs something else. Both sides stated
HARMFUL5Net loss, with the mechanism of the loss named
DEPENDS13A real conditional. The condition is named, or the code may not be used
UNVERIFIED16We could not confirm the mechanism from a primary source. What we checked is listed, and the row is filed at /mechanisms/unverified/
UNSAFE-CLAIM1A licensing or legal claim we will not test, endorse or explain operationally
HARDWARE1The bottleneck is physical and no setting fixes it

UNVERIFIED and DEPENDS together are 29 of 68 rows — 43%. That is not a weakness of the table, it is the table. Uncertainty does not convert, which is exactly why affiliate content has no vocabulary for it, and why a page that ships it on day one looks different from everything else returned for these queries.

Two modifier flags appear as superscripts on a code. the write touches licensing, telemetry or compliance rather than performance. the surface no longer exists, or is no longer honoured, in a currently supported build. Flagged rows are kept, never deleted, because a large share of the traffic to this domain arrives on links a decade old and those readers need the historical row more than anyone.

Claim Clean up computer memory automatic timer by Windows Winset. Archived vendor help index, tlwinset.com/help.htm, capture 2012-08-24. Checked 2026-08-05 · Ledger row M-01

The three cards on this page are three of the thirty-three claim cards on this site, spread across thirteen pages. Thirty-two of them quote archived Tenglnet material and each carries its archive URL and its capture date; the thirty-third quotes a trade association about its own file format, with the address and the date we read it. Every quotation is capped at twenty-five words and the longest anywhere on the site currently runs to twenty-one. We do not republish the previous owner’s prose; we quote it as evidence of what was claimed, and the writing around it is ours.

§3The Mechanism Ledger

ID The claim, as sold Surface it must touch Documented by Documented default Version boundary Measurable effect Verdict Cost of being wrong Sources Winset claimed Last verified
M-01 “Clean up computer memory on an automatic timer” EmptyWorkingSet(hProcess) · SetProcessWorkingSetSize(hProcess, (SIZE_T)-1, (SIZE_T)-1) MS-DOC “Removes as many pages as possible from the working set of the specified process.” Nothing in Windows calls this on a schedule; the memory manager trims under memory pressure. Microsoft does not document where the removed pages go. XP (API) · unchanged 25H2 HARMFUL A working set is by definition the pages of a process resident in physical memory. Every page removed must be faulted back in on next access. The timer guarantees this repeats. [1][2][88] 2012 2026-08-05 · 25H2
M-02 “Clean memory when free memory is less than 30%” GlobalMemoryStatusEx → MEMORYSTATUSEX.ullAvailPhys · Memory\Available MBytes MS-DOC “It is the sum of the size of the standby, free, and zero lists.” Pages holding cached file data on the standby list are already counted as available and are handed to any process that asks. NO-OP The trigger fires on a number that already counts the file cache as available, so the tool acts on a condition that is not a shortage, and discards cache to prove it. [3][4][89][92] WIN8 2026-08-05 · 25H2
M-03 “Turn off memory compression to make Windows faster” Disable-MMAgent -MemoryCompression · Enable-MMAgent -MemoryCompression MS-DOC Not stated. The cmdlet reference describes the switch as “uses memory compression” and gives no default and no behaviour. The feature shipped in Windows 10 RTM per a Microsoft video with the Windows kernel team. Win10 RTM (1507) UNVERIFIED There is no documented default to restore to. Checked: Enable-MMAgent, Get-MMAgent, Memory Management Registry Keys, the Server cache and memory manager pages, RAMMap. [5][7] 2026-08-05 · 25H2
M-04 “Combine identical memory pages to free RAM” Enable-MMAgent -PageCombining MS-DOC “Page combining is disabled by default but can be enabled by using the Enable-MMAgent Windows PowerShell cmdlet. Page combining was added in Windows Server 2012.” The client default is not stated in any current Microsoft page. Windows Server 2012 DEPENDS Condition, named by Microsoft: it helps on machines with many private, pageable pages of identical content, and “the downside of enabling page combining is increased CPU usage.” No CPU figure is published. [5][6] 2026-08-05 · 25H2
M-05 “Set a fixed page file size for better performance” HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PagingFiles MS-DOC “By default, page files are system-managed… when the system commit charge is more than 90 percent of the system commit limit, the page file is increased.” Growth stops at three times physical memory or 4 GB, whichever is larger. DEPENDS Condition: the crash-dump setting. Automatic memory dump is enabled by default, and a fixed page file smaller than the dump requirement means the next bug check produces no dump and says nothing about it. [8][9] 2026-08-05 · 25H2
M-06 “Wipe the page file at shutdown for a clean start” HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\ClearPageFileAtShutdown MS-DOC Disabled. “Client Computer Effective Default Settings: Disabled.” When enabled it also clears hiberfil.sys where hibernation is disabled on a portable device. Shutdown duration. Microsoft: on a device with 2 GB of RAM and a 2-GB page file this “could increase the shutdown process by more than 30 minutes”, because the storage area is overwritten several times. HARMFUL The machine takes minutes to tens of minutes longer to shut down and restart, every time, and the mechanism is a multi-pass overwrite Microsoft documents on the same page. [10] 2026-08-05 · 25H2
M-07 “Keep the kernel in RAM to stop disk thrashing” HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\DisablePagingExecutive MS-DOC 0 — “Drivers and system code can be paged to disk as needed.” The Windows Performance Toolkit reference sets it only to enable x64 stackwalking on Vista and Windows 7, and states “Systems with Windows 8 and higher do not need this registry change.” Win8 (no longer needed for tracing) UNVERIFIED The only Microsoft statement that it “improves performance on machines with a lot of memory” is on a Windows Server 2003 reference page. Checked: the WPT reference, Memory Management Registry Keys, the Server 2003 page. No current-build source. [11][12] 2026-08-05 · 25H2
M-08 “One click empties the standby list and frees your RAM” RAMMap → Empty → Empty Standby List / Empty Working Sets UNDOCUMENTED Not stated. The RAMMap page documents seven tabs, refresh and snapshot save/load, and defers terminology outward: “please see Windows Internals, 5th Edition.” The Empty menu is not described anywhere on it. UNVERIFIED The standby list is the file cache. Whatever is discarded is read from disk again on next use, and no Microsoft source states what the command does or what it costs. Checked: the RAMMap page, the Defrag Tools episode index, the Server cache troubleshooting guide. [16] 2026-08-05 · 25H2
M-09 “Disable prefetching to stop background disk activity” HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters\EnablePrefetcher MS-DOC Not stated. The value table — 0 disabled, 1 application start, 2 boot, 3 both — exists only in archived Windows Embedded Standard 7 documentation, written for devices with a write filter where “Prefetch is unable to persist its data from startup to startup.” UNVERIFIED No Microsoft-documented default exists to restore. The widely repeated “default is 3” is unsourced. Checked: the Embedded pages for XP Embedded and Standard 7, Memory Management Registry Keys, the Win32 memory reference. [17] 2026-08-05 · 25H2
M-10 “Free up memory instead of buying more RAM” System commit charge against the system commit limit · Memory\Committed Bytes · Memory\Commit Limit MS-DOC The commit limit is physical memory plus the current page file size. “System-managed page files automatically grow… when the system commit charge reaches 90 percent of the system commit limit.” HARDWARE If committed bytes sit near the commit limit, the machine is short of memory, not short of housekeeping. No registry value changes how much physical memory is installed; the page file grows onto disk and the machine pages. [8][9][3] 2026-08-05 · 25H2
R-01 “The registry becomes very large and slows the computer” The registry hives themselves · HKLM\SYSTEM\CurrentControlSet\Control\RegistrySizeLimit MS-DOC “Windows Server 2003 with SP1, Windows Server 2003 and Windows XP: There are no explicit limits on the total amount of space that may be consumed by hives.” The global quota is documented only under a Windows 2000 heading. XP / Server 2003 SUPERSEDED The premise of the sale is a Windows 9x and Windows 2000 premise. One caveat we will not suppress: KB 2567018 states the old limit is still honoured on Server 2003 through 2008 R2, and on XP through Windows 7, if an administrator sets the value to something other than 0. [18][19][93] WIN8 2026-08-05 · 25H2
R-02 “Scan and clean up the Windows registry” RegDeleteKeyEx / RegDeleteValue against HKCR and HKLM\SOFTWARE\Classes UNDOCUMENTED Windows does not remove unreferenced class registrations on a schedule and publishes no maintenance guidance that involves doing so. No Microsoft source connects deleting them to any change in a performance counter. UNVERIFIED Microsoft’s retired support policy says it does not support registry cleaners and is not responsible for issues they cause. That is a support-scope and liability position, not a performance finding, and the same article concedes a damaged registry can cause slowdowns. Checked: the archived policy, the current unwanted-software criteria, Registry Storage Space. [20][21][88] 2012 2026-08-05 · 25H2
R-03 “Scan complete: 1,247 registry errors found” None named. A count with no per-item path names no surface at all. MS-DOC Microsoft classifies as unwanted software anything that will “Display exaggerated claims about your device’s health” or “Make misleading or inaccurate claims about files, registry entries, or other items on your device.” Criteria updated 2026-01-29 UNVERIFIED A claim that names no surface cannot be verified or refuted, which is the point of preamble question 1. What would close it is a per-item report with full key paths; that is also the difference regulators acted on. [21] 2026-08-05 · 25H2
R-04 “Accelerate menu display speed” HKCU\Control Panel\Desktop\MenuShowDelay MS-DOC REG_SZ, “Milliseconds in decimal”, default value 400. “Determines the interval from the time the cursor is pointed at a menu until the menu items are displayed.” Microsoft has published no modern restatement. — (documented for Windows 2000) Menu open delay in milliseconds. Documented default 400; the value moves perceived latency only and no throughput counter exists that it would change. TRADE At 0 there is no dwell time, so sub-menus open under the pointer as it passes over them and menu navigation becomes error-prone. The machine is not faster; the interface is. [25][87] 2008 2026-08-05 · 25H2
R-05 “Optimized CPU priority and delay time” HKLM\SYSTEM\CurrentControlSet\Control\PriorityControl\Win32PrioritySeparation MS-DOC Default 0x2. A six-bit field, AABBCC: interval length, variable or fixed, and the foreground-to-background quantum ratio. The Programs radio button writes 100110b; Background services writes 011000b. NT 4.0 (meaning changed) DEPENDS Condition: where the work is. Microsoft documents that the same default value 0x2 means shorter variable intervals favouring the foreground on client SKUs and longer fixed intervals with equal treatment on server. Neither setting creates processor time; it reallocates it. [26][87] 2008 2026-08-05 · 25H2
R-06 “Our helper loads into every process that starts” HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs MS-DOC “Starting in Windows 8, the AppInit_DLLs infrastructure is disabled when secure boot is enabled.” And: “usage of AppInit_DLLs is not recommended.” Win8 SUPERSEDED On a machine with Secure Boot on, the value is not read and the product silently does nothing. Microsoft also states that even legitimate AppInit DLLs “can unintentionally cause system deadlocks and performance problems.” [23] 2026-08-05 · 25H2
R-07 “Block a program from ever launching again” HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<exe>\Debugger MS-DOC Key absent. Microsoft documents the value as a way to “Specify a debugger to use when starting a program”: a REG_SZ holding the full path to a debugger, which Windows launches in place of the named executable. TRADE It works, and the cost is that the named process is now launched under whatever the value points at. Sysinternals Autoruns enumerates this surface under the name “image hijacks”, which is what it is when somebody else writes it. [24][80] 2026-08-05 · 25H2
R-08 “Turn off last-access timestamps for a faster disk” HKLM\SYSTEM\CurrentControlSet\Control\FileSystem\NtfsDisableLastAccessUpdate MS-DOC “In Windows 10 v1803 operating system and later… The NtfsDisableLastAccessUpdate value is now treated as a bitfield”, including 0x2, System managed. On servers, and on clients whose boot volume exceeds the policy threshold, updates are already disabled. 1803 (bitfield) · 2004 (128 GB fallback retired) SUPERSEDED On most current machines Windows has already made this decision. Note that the fsutil reference is stale here and still documents only the old 1/0 form; the accurate source is the file-system protocol specification. [27][28] 2026-08-05 · 25H2
R-09 “Automatically close applications that stop responding” HKCU\Control Panel\Desktop\AutoEndTasks · WaitToKillAppTimeout · HungAppTimeout MS-DOC AutoEndTasks 0 — “Processes do not end automatically.” WaitToKillAppTimeout 20000 (20 seconds). HungAppTimeout 5000. All three REG_SZ under the same key, documented for Windows 2000 and Windows Server 2003. — (documented for Windows 2000) TRADE Logoff and shutdown get shorter, and a process that has not finished writing is ended without the End Task dialog appearing. The saving is measured in seconds of shutdown; the cost is unsaved data, and both are documented on the same pages. [29][30][31][87] 2008 2026-08-05 · 25H2
R-10 “User Account Control management” HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System → EnableLUA, ConsentPromptBehaviorAdmin, PromptOnSecureDesktop MS-DOC EnableLUA 1, ConsentPromptBehaviorAdmin 5 (prompt for consent for non-Windows binaries), PromptOnSecureDesktop 1, EnableVirtualization 1. Every UAC value and its default is tabulated on one current Microsoft page. TRADE It works, and the cost is not performance. Setting EnableLUA to 0 disables Admin Approval Mode “and all related UAC policy settings”, and Windows Security notifies the user that overall security is reduced. UAC has never been a speed feature. [32][88] 2012 2026-08-05 · 25H2
R-11 “Set the desktop icon cache size” HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Max Cached Icons UNDOCUMENTED Not stated anywhere Microsoft publishes. There is no Microsoft reference page for this value, no documented default, and no documented data type. UNVERIFIED There is no Microsoft-stated default to restore, so the change cannot be cleanly undone. Checked: learn.microsoft.com and support.microsoft.com searches for the value name; every result was a user-authored Microsoft Q&A thread, which is not documentation. [87] 2008 2026-08-05 · 25H2
R-12 “Use free Windows 7 for 360 days” slmgr.vbs /rearm · HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\SkipRearm MS-DOC “The activation grace period is typically 30 days… in Windows 7 and Windows Vista, there is a limit to the number of times Windows can be rearmed. Typically, a system can be rearmed only 3 times.” KB 929828: “The Rearm process can be run a maximum of three times in a Windows image.” Win8 (“the Windows licensing state can be reset repeatedly”) UNSAFE-CLAIM We state the documented limit and stop there. The archived help page for this feature offers a checkbox for having used it more than three times, taking it to twelve. We do not describe, endorse or test any method of exceeding the documented limit, and no Microsoft source documents a 360-day figure. [34][35][95] WIN8 2026-08-05 · 25H2
S-01 “Optimize Windows services to speed up your computer” HKLM\SYSTEM\CurrentControlSet\Services\<name>\Start = 4 MS-DOC 0 Boot, 1 System, 2 Automatic, 3 Demand, 4 Disabled. “The service is disabled and will not be loaded.” Attempts to start it return ERROR_SERVICE_DISABLED. DEPENDS Condition: which service. Microsoft publishes per-service recommendations for Windows Server 2016 with Desktop Experience and for Windows IoT Enterprise fixed-function devices. It publishes none for general-purpose Windows client, and says “We don’t recommend applying policies that disable services that aren’t by default by Microsoft.” [36][37][41][42][88] 2012 2026-08-05 · 25H2
S-02 “Click Recommend and we select the unnecessary services” The vendor’s own recommendation list, which was never published UNDOCUMENTED Microsoft’s only published service-disabling guidance is scoped, in its own words, to “Windows Server 2016 with Desktop Experience, unless you’re using it as a desktop replacement for end-users”, and its own affirmative disable list runs to two services. Server 2019 (guidance became the defaults) UNVERIFIED Nobody outside the vendor can know which services a hidden list contains, which is preamble question 2 failing in one word. Checked: the Server 2016 guidance, the IoT Enterprise services guidance, and searches for a Windows 10 or 11 client equivalent, which does not exist. [41][42][91] WIN8 2026-08-05 · 25H2
S-03 “Delay startup services so the desktop appears sooner” ChangeServiceConfig2 with SERVICE_CONFIG_DELAYED_AUTO_START_INFO · sc config <name> start=delayed-auto MS-DOC fDelayedAutostart FALSE. When set, “the ServiceMain thread for the service is started with THREAD_PRIORITY_LOWEST”, and is raised to normal only after the service reports SERVICE_RUNNING. Vista / Server 2008 TRADE Logon feels faster and the service starts later at the lowest thread priority. Microsoft states the costs plainly: “There is no specific time guarantee as to when the service will be started”, and a delayed service cannot belong to a load-ordering group. [38] 2026-08-05 · 25H2
S-04 “Stop services running when you do not need them” SERVICE_TRIGGER via ChangeServiceConfig2 / SERVICE_CONFIG_TRIGGER_INFO · sc qtriggerinfo <name> MS-DOC “A service can register to be started or stopped when a trigger event occurs. This eliminates the need for services to start when the system starts… a service can start when it is needed.” Win7 / Server 2008 R2 SUPERSEDED The operating system has shipped this since 2009, per service, with the trigger conditions inspectable from the command line. One documented limit worth knowing: “Trigger-start and trigger-stop requests are not guaranteed under low memory conditions.” [39] 2026-08-05 · 25H2
S-05 “Group services into fewer processes to save memory” svchost.exe process grouping · HKLM\SYSTEM\CurrentControlSet\Services\<name>\SvcHostSplitDisable MS-DOC “This change is automatic for systems with more than 3.5 GB of RAM running the Client Desktop SKU. On systems with 3.5 GB or less RAM, we’ll continue to group services into a shared SvcHost process.” 1703 DEPENDS Condition: installed memory against the documented threshold, on Client Desktop SKUs only. Note that the widely cited value SvcHostSplitThresholdInKB with a default of 3670016 appears in no Microsoft source we could find; the value Microsoft does document is the per-service SvcHostSplitDisable. [40] 2026-08-05 · 25H2
S-06 “Disable the search indexer to make the machine faster” HKLM\SYSTEM\CurrentControlSet\Services\WSearch\Start MS-KB Automatic (Delayed Start) on Windows client; Manual on Windows IoT Enterprise; already Disabled on Windows Server 2016 with Desktop Experience. Microsoft documents the indexer as self-throttling: it stops when disk or CPU use is high and pauses on battery. Items indexed. Microsoft: “fewer than 30,000 items” on a typical user’s computer; “If the Indexer indexes more than 400,000 items, you may begin to see performance issues”; hard limit about 1,000,000. TRADE Start menu and File Explorer stop returning content results, and Microsoft names this behaviour directly: “Some anti-virus programs and ‘Optimize your PC’ applications disable the Windows Search service. We recommend that you don’t run such applications if you want to use Search.” [42][43] 2026-08-05 · 25H2
S-07 “Disable SysMain, it is pointless on an SSD” HKLM\SYSTEM\CurrentControlSet\Services\SysMain\Start MS-DOC Automatic on the client family, where Microsoft’s current guidance marks it “Don’t disable”. Since Windows 7: “Windows will disable Superfetch, ReadyBoost, as well as boot and application launch prefetching on SSDs with good random read, random write and flush performance.” Vista (introduced) · Win7 (SSD auto-disable) DEPENDS Condition: the system disk, and Windows already decides it per drive by benchmarking random reads. Microsoft has never recommended that an administrator make this decision by hand, and its two published positions — the 2009 auto-disable and the current “Don’t disable” — have never been reconciled in writing. [13][14][15][42] 2026-08-05 · 25H2
S-08 “Turn off Windows Update to stop background disk activity” HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\Start MS-DOC Manual. “Disabling Windows Update service prevents Windows Update, its automatic updating feature, and programs aren’t able to use the Windows Update Agent (WUA) API.” TRADE Background disk and network activity stop, and so do security updates. The second cost is less obvious and is documented: any installer or management tool that calls the WUA API fails, which is a support call nobody connects back to this change. [42] 2026-08-05 · 25H2
S-09 “Auto-set the transmission unit cache size” HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\TcpWindowSize MS-DOC “This registry setting is ignored by this version of Windows and is consuming a small amount of extra space in the registry.” The Next Generation TCP/IP stack derives the receive window continuously from the measured bandwidth-delay product per connection. Vista SUPERSEDED The value does nothing at all; the machine’s actual receive window is set by Receive Window Auto-Tuning. This is the cleanest case in the table: a 2008 product advertised tuning by hand a number that Windows had derived automatically since 2006. [82][83][87] 2008 2026-08-05 · 25H2
S-10 “Turn off TCP auto-tuning to fix slow downloads” netsh interface tcp set global autotuninglevel=<normal|restricted|highlyrestricted|experimental|disabled> MS-DOC “The default level is Normal.” Five levels, Normal 0x8 through Disabled. “Starting with Windows Server 2019, you can no longer use the registry to configure the TCP receive window size.” Vista (auto-tuning) · Server 2019 (registry route removed) DEPENDS Condition, and it is narrow: an intermediate device that does not comply with RFC 1323 window scaling. Microsoft documents disabling auto-tuning as a workaround for exactly that case, in KB 947239, and for no other. Note the popular “Microsoft says never disable it” quotation is from a blog post that no longer resolves. [81][97] 2026-08-05 · 25H2
S-11 “Auto-set maximum transmission unit and segment size” netsh interface ipv4 set subinterface mtu= · HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnablePMTUDiscovery MS-KB The netsh MTU default is “the natural MTU of the link” and store=active is not persistent. EnablePMTUDiscovery default 1: “If you set this parameter to 0, an MTU of 576 bytes is used for all connections that are not to computers on the local subnet.” — (parameter reference never republished past XP) DEPENDS Condition: a path that silently drops ICMP fragmentation-needed messages, which is the only situation where a hand-set MTU beats discovery. Set it wrong and every connection off the local subnet runs at 576 bytes, which is a documented, permanent slowdown. [84][85][87] 2008 2026-08-05 · 25H2
S-12 “Reclaim the 20% of bandwidth Windows reserves” Software\Policies\Microsoft\Windows\Psched\NonBestEffortLimit (“Limit reservable bandwidth”) MS-DOC “By default, the Packet Scheduler limits the system to 80 percent of the bandwidth of a connection.” The policy is a ceiling on what programs may reserve, not a standing deduction from the link. UNVERIFIED The figure on the live Microsoft page is 80, not 20, and it describes a different thing from the folklore. The sentence everyone quotes to debunk this — that all bandwidth is available unless a program requests priority — was in KB 316666, which now returns 404. No live Microsoft page addresses the claim. [86] 2026-08-05 · 25H2
B-01 “Use all your CPU cores at boot” BCD element numproc · bcdedit /set numproc · msconfig → Boot → Advanced options MS-DOC Unset. The element is documented as “numproc [integer] Uses only the specified number of processors”, inside a reference Microsoft introduces as “boot options… related to developing, testing, and debugging drivers.” Vista / Server 2008 NO-OP The word is only. The element is a cap: setting it can reduce the processors the system uses and can never raise the number, so there is nothing to unlock. Microsoft documents the BCD element and not the msconfig checkbox, and we do not assert the unchecked state beyond that. [44][45][90] WIN8 2026-08-05 · 25H2
B-02 “Optimize computer boot speed” HKLM and HKCU \SOFTWARE\Microsoft\Windows\CurrentVersion\Run · the Startup folders · Task Manager → Startup MS-DOC Since Windows 8 the Startup tab computes an impact rating in-box, from the same three locations the archived vendor help page describes its own boot module editing. Win8 Startup impact, as Microsoft defines it: High is more than 1 second of CPU time or more than 3 MB of disk I/O at startup; Medium is 300–1000 ms CPU or 300 KB–3 MB disk I/O; Low is under 300 ms and under 300 KB. SUPERSEDED The feature the suites charged for shipped in the box, better instrumented, in 2012. The in-box list has one documented gap and it is the same gap the paid tools had: it covers Run, RunOnce and the Startup folders only, not scheduled tasks and not Group Policy. [52][22][88] 2012 2026-08-05 · 25H2
B-03 “Shut down and start up in seconds” Fast Startup / hybrid shutdown · hiberfil.sys MS-DOC “Fast Startup is enabled by default in Windows.” At shutdown Windows closes all applications, logs off all user sessions, then “saves the kernel memory image (including the loaded kernel-mode drivers) in Hiberfil.sys”. Win8 SUPERSEDED Two documented consequences readers should hold together: “The Fast Startup setting doesn’t apply to Restart”, so a restart is still a cold boot; and every boot-time figure published after 2012 measures a different operation from the ones published before it, which makes cross-era comparisons meaningless. [46][47][88] 2012 2026-08-05 · 25H2
B-04 “Force a better system timer for a faster machine” bcdedit /set useplatformclock · bcdedit /set disabledynamictick MS-DOC Both unset. Microsoft attaches the identical note to each: “This option should only be used for debugging.” useplatformclock “Forces the use of the platform clock as the system’s performance counter.” UNVERIFIED No Microsoft source supports a performance claim for either element, and the only characterisation given is debugging-only. Checked: the bcdedit /set reference, the BCD boot options reference, the bcdedit command-line options page. Reverting is documented: /deletevalue. [44][45] 2026-08-05 · 25H2
B-05 “We measured your boot time and it is too slow” Diagnostics-Performance operational log, event ID 100 → BootTime, MainPathBootTime, BootPostBootTime UNDOCUMENTED The Windows ADK defines the analogous assessment metrics — Main Path Boot Duration, Post On/Off Duration, Total Boot [Excluding BIOS] Duration — but it does not define the event-log field names, and no Microsoft page does. Win8 / Win10 (assessment scope) UNVERIFIED A number quoted from a field nobody documents cannot be checked against anything. Checked: the ADK assessment page, the WPT on/off transition recording page, and the TechNet Wiki archive for event 100, which tabulates the event but defines no timing field. The only Microsoft text relating them is an archived forum post carrying an as-is disclaimer. [48] 2026-08-05 · 25H2
B-06 “Defragment your boot files so Windows starts faster” HKLM\SOFTWARE\Microsoft\Dfrg\BootOptimizeFunction\Enable · defrag /b MS-DOC “If the entry is set to Y, Windows automatically optimizes the file location for boot optimization. This optimization occurs automatically if the system is idle for 10 minutes.” The current defrag reference documents /b and a weekly maintenance task, and never mentions this key. Server 2003 SUPERSEDED Windows has done this on an idle timer since the Dfrg.msc era, so a product selling it was selling a scheduled task. The registry key is documented only for Windows Server 2003 and the page is archived; do not read it as current behaviour. [49][50][88] 2012 2026-08-05 · 25H2
B-07 “Our driver reaches parts of Windows other tools cannot” HKLM\SYSTEM\CurrentControlSet\Services\<driver>\Start = 0 or 1, loading a kernel-mode driver MS-DOC “Starting with Windows 10, version 1607, Windows will not load any new kernel-mode drivers which are not signed by the Dev Portal.” 64-bit Windows has enforced kernel-mode code signing since Windows Vista. Vista x64 · 1607 with Secure Boot on DEPENDS Condition, and Microsoft states it exactly: cross-signed drivers still load if Secure Boot is off in the BIOS, if the machine was upgraded in place to 1607 from an earlier release, or if the signing certificate was issued before 2015-07-29. This is the change that quietly ended a whole product category, and it ended it conditionally. [51] 2026-08-05 · 25H2
B-08 “Unlock more memory for your programs” bcdedit /set increaseuserva · the /3GB switch in Boot.ini on Server 2003 and XP MS-DOC Unset: on 32-bit Windows the split is 2 GB user and 2 GB system. “On 64-bit editions of Windows, 32-bit applications marked with the IMAGE_FILE_LARGE_ADDRESS_AWARE flag have 4 GB of address space available” with no boot flag at all. Server 2003 / XP (/3GB) · 64-bit Windows (unnecessary) User-mode virtual address space on 32-bit Windows: from 2048 MB to a maximum of 3072 MB, and only for images linked large-address-aware. On 64-bit Windows the setting has nothing to give. SUPERSEDED Microsoft names the cost on the same page: with the split moved, “the file cache, paged pool, and nonpaged pool are smaller, which can adversely affect applications with heavy networking or I/O.” On a 64-bit machine there is no upside to trade against that. [53][44] 2026-08-05 · 25H2
D-01 “Scan and clean up computer junk files” cleanmgr /sageset:n and /sagerun:n · HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\VolumeCaches MS-DOC Disk Cleanup ships in Windows, stores per-profile selections as StateFlagsNNNN under VolumeCaches, and is still recommended by Microsoft where Storage Sense is unavailable. Its own guidance on temporary files: “You can safely delete temporary files that haven’t been modified within the last week.” 1903 (Storage Sense policies) SUPERSEDED The scriptable version of this has been in the box since Windows 2000 and is free. One correction we owe the record: Microsoft has not deprecated Disk Cleanup. It is on neither the deprecated-features nor the removed-features list, and the widely repeated 2018 deprecation is not on any Microsoft page we could load. [54][55][88] 2012 2026-08-05 · 25H2
D-02 “Windows never cleans up after itself” Storage Sense · ConfigStorageSenseGlobalCadence · ConfigStorageSenseRecycleBinCleanupThreshold · ConfigStorageSenseDownloadsCleanupThreshold MS-DOC “Storage Sense is automatically turned on when the machine runs into low disk space and is set to run whenever the machine runs into storage pressure.” Temporary-file cleanup defaults to on. 1903 Recycle Bin: files older than 30 days, by default. Downloads: 0, meaning never. Cloud content dehydration: 0, meaning never. TRADE It runs for free and it deliberately leaves alone the two folders most likely to be large. Microsoft states it: “items in your Downloads folder and OneDrive… will not be touched unless you set up Storage Sense to do so.” That is the gap a paid cleaner is actually filling, and you can close it in Settings. [56] 2026-08-05 · 25H2
D-03 “Your WinSxS folder is 12 GB and can be cleaned” DISM /Online /Cleanup-Image /AnalyzeComponentStore and /StartComponentCleanup MS-DOC “Some tools, such as the File Explorer, determine the size of directories without taking into account that the contained files might be hard linked, which might lead you to think that the WinSxS folder takes up more disk space than it really does.” A scheduled task already runs the cleanup, waiting at least 30 days after an updated component is installed. Win10 AnalyzeComponentStore reports three separate numbers: Windows Explorer Reported Size, which “doesn’t factor in the use of hard links”; Actual Size, which does; and Shared with Windows, which “shouldn’t be considered part of the component store overhead”. SUPERSEDED Any figure produced by measuring the folder in Explorer is inflated by hard links, so the headline number in the sales pitch is an artefact of the measuring method. Running /ResetBase to squeeze more out of it means “All existing update packages can’t be uninstalled after this command is completed.” [57][58][88] 2012 2026-08-05 · 25H2
D-04 “Delete the Prefetch folder to free space and speed up Windows” %SystemRoot%\Prefetch\*.pf · %SystemRoot%\Prefetch\Layout.ini MS-DOC “When an application is launched the prefetcher looks in the prefetch directory to determine whether a .pf file is present… If the .pf file exists, the kernel component of the prefetcher issues asynchronous IOs to prefetch metadata, data, and image pages described in the trace file.” Layout.ini is regenerated every 72 hours during idle. HARMFUL The mechanism of the loss is on the same page: a launch with no trace file gets no prefetch, so the next few launches of every deleted application are slower until the traces are rebuilt. No Microsoft guidance has ever recommended deleting this folder, and the space it occupies is small. [59] 2026-08-05 · 25H2
D-05 “Defragment your SSD for peak performance” defrag /o · Optimize-Volume · the weekly Optimize Drives maintenance task MS-DOC Windows already runs optimisation as a maintenance task, “typically… every week”. For SSDs it performs retrim, and traditional defragmentation “is done once per month… Changing the frequency of the scheduled task doesn’t affect the once per month cadence for the SSDs.” Optimize-Volume on a TRIM-capable SSD defaults to -Retrim alone. SUPERSEDED Running a manual traditional defragmentation on an SSD is documented to make the next scheduled run skip it. Microsoft’s own table says an SSD without TRIM support gets “No operation” — there is nothing for a third-party tool to add. [50][60] 2026-08-05 · 25H2
D-06 “Immunize the disk partition against autorun viruses” An undeletable autorun.inf directory at each volume root · HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoDriveTypeAutoRun MS-DOC Microsoft documents two values that persistently disable AutoRun, NoDriveAutoRun and NoDriveTypeAutoRun, and warns: “Applications should not modify these values, as there is no way to reliably restore them to their original values.” The directory trick is not documented anywhere. UNVERIFIED Occupying the filename with a folder is a real technique with no Microsoft documentation, and the update usually cited as having ended the threat, KB 971029, now returns 404 at every support.microsoft.com URL we checked, in both its numeric and GUID forms. Checked: the AutoPlay registry page, both KB URLs, learn.microsoft.com searches. [33][94] WIN8 2026-08-05 · 25H2
D-07 “Free gigabytes by turning off hibernation” powercfg /hibernate off · /size · /type reduced · HKLM\SYSTEM\CurrentControlSet\Control\Power\HiberFileSizePercent MS-DOC “The default size cannot be smaller than 50” percent of total memory, and “a hiberfile that has a custom default size, or HiberFileSizePercent >= 40, is considered as a full hiberfile.” Microsoft does not publish a single default percentage; it states the file grows in direct proportion to installed RAM. Microsoft’s own Windows 10 1607 measurements: /h off saves more than 825 MB on x86 with 2 GB of RAM and more than 1.5 GB on x64 with 4 GB. /h /type reduced saves more than 400 MB and more than 930 MB respectively. TRADE Hibernation goes, and so does Fast Startup, because hibernating the kernel session at shutdown is what writes that file. On a machine where Fast Startup was the thing making boots feel quick, this trades disk space for the boot time the same tool is selling. [61][58] 2026-08-05 · 25H2
D-08 “Clean system trace files” %LOCALAPPDATA%\CrashDumps · HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\LocalDumps MS-DOC “This feature is not enabled by default.” When an administrator does enable it, DumpCount defaults to 10 and “when the maximum value is exceeded, the oldest dump file in the folder will be replaced with the new dump file.” Vista SP1 / Server 2008 NO-OP Local user-mode crash dumps are off unless somebody turned them on, and when on the folder caps itself. A cleaner reporting recovered space here is reporting on a folder that was already self-limiting, or empty. [62][88] 2012 2026-08-05 · 25H2
D-09 “Delete SoftwareDistribution to reclaim update space” %SystemRoot%\SoftwareDistribution\Download · %SystemRoot%\SoftwareDistribution\DataStore MS-DOC Microsoft documents removing this folder only as a Windows Update repair step, behind an explicit caution that it “should only be performed at this point in the troubleshooting if you can’t resolve your Windows Update issues after following all steps”. Its manual procedure renames rather than deletes. DEPENDS Condition: whether Windows Update is actually broken. There is no documented size cap or purge schedule for this cache and no Microsoft statement that clearing it is safe routine maintenance, so a cleaner that empties it on a schedule is running a repair procedure on a machine that is not broken. [63] 2026-08-05 · 25H2
D-10 “Windows is hiding gigabytes from you in reserved storage” DISM /Online /Set-ReservedStorageState /State:Disabled · /Get-ReservedStorageState MS-DOC “Reserved storage increases the likelihood that Windows updates can be downloaded and installed without users having to free disk space.” It works out of the box on devices that connect directly to Windows Update, and not automatically under WSUS or Configuration Manager. 1903 (feature) · 2004 (DISM commands) UNVERIFIED The size is the whole claim and Microsoft states no size anywhere we could load — not on the DISM page and not on the support page. What is documented cuts against the framing: “When your device is low on space, Windows will clear reserved storage so it can be used for other processes.” Checked: both pages and the Dism PowerShell module. [64] 2026-08-05 · 25H2
A-01 “Manage every program that starts with Windows” HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run · HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run MS-DOC “The Run key makes the program run every time the user logs on.” Two documented properties people get wrong: “the order in which those programs run is indeterminate”, and “the system may choose to delay the execution of programs in the Run key and in the Startup group.” TRADE Editing these two keys works and is the single most defensible intervention in the whole category. The cost is that they are two of at least sixteen documented autostart surfaces, so a manager that reads only these will report a machine as clean when it is not. [22][80][87] 2008 2026-08-05 · 25H2
A-02 “Remove leftover one-time startup entries” HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce · HKCU\...\RunOnce MS-DOC “By default, the value of a RunOnce key is deleted before the command line is run.” A leading ! defers deletion until after the command runs; a leading * forces the entry to run in Safe Mode, where these keys are otherwise ignored. NO-OP The entry deletes itself before it executes, so on a healthy machine there is nothing left to clean. The exception is the one worth knowing: an entry prefixed with ! survives its own run, and that is the case a cleanup is actually for. [22] 2026-08-05 · 25H2
A-03 “Clear out your startup folder” %APPDATA%\Microsoft\Windows\Start Menu\Programs\StartUp · %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\StartUp MS-DOC FOLDERID_Startup is per-user; FOLDERID_CommonStartup is machine-wide. Microsoft documents both with their default paths and their legacy pre-Vista equivalents. Vista (path form) TRADE Removing a shortcut works, is instantly reversible, and needs no tool. The cost is a category error people make constantly: these are two different folders, and clearing the per-user one leaves everything an installer put in the all-users one. [65] 2026-08-05 · 25H2
A-04 “One list shows everything that runs at logon” Task Scheduler triggers TASK_TRIGGER_BOOT (8) and TASK_TRIGGER_LOGON (9) · %SystemRoot%\System32\Tasks MS-DOC “Triggers the task when the computer boots” and “Triggers the task when a specific user logs on.” Task Manager’s Startup tab, which Microsoft documents, covers Run, RunOnce and the Startup folders and nothing else. Vista / Server 2008 DEPENDS Condition: whether the list includes scheduled tasks. This is the surface most consumer startup managers miss, and it is where a modern updater or telemetry component usually lives, so the answer to “why is something still running?” is very often here. [66][52][80] 2026-08-05 · 25H2
A-05 “Nothing on this machine is set to start automatically” root\subscription → __EventFilter, CommandLineEventConsumer, __FilterToConsumerBinding MS-DOC “The CommandLineEventConsumer class starts an arbitrary process in the local system when an event is delivered to it”, and a permanent consumer “operates and receives events after it is created and even after a reboot of the operating system as long as WMI is running.” Vista (runs as LocalSystem in session 0) UNVERIFIED A clean-bill-of-health sentence cannot be supported by a tool that does not enumerate this namespace, and we could not confirm from any published capability list that consumer optimisers do. Autoruns publishes its coverage as a switch, autorunsc -m, which is the comparison. [67][80] 2026-08-05 · 25H2
A-06 “Speed up Explorer by removing shell extensions” HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved MS-DOC “The system stores entries representing approved user interface extensions on a system in the following registry key.” The list is only consulted when an administrator turns on EnforceShellExtensionSecurity. DEPENDS Condition: EnforceShellExtensionSecurity. With it off — which is the ordinary state — removing an entry from the Approved list changes nothing, because nothing is checking the list. A tool that reports the removal as a fix has reported a fix that did not happen. [68] 2026-08-05 · 25H2
A-07 “Remove browser add-ons that are slowing you down” HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects MS-DOC “If this key exists and there are CLSIDs listed underneath it, then Internet Explorer uses that information to create an instance of each object.” Internet Explorer 11 ended support on 2022-06-15 and “has been permanently disabled on certain versions of Windows 10.” 2022-06-15 NO-OP The only program documented to read this key is retired and disabled, so entries under it are inert. We stop short of the obvious next sentence: we found no Microsoft statement that Microsoft Edge ignores this key, only that Internet Explorer is gone. [69][70] 2026-08-05 · 25H2
A-08 “Our tool loads before anything else on the system” HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\BootExecute SYSINTERNALS A MULTI_SZ “contains the names and arguments of programs that are executed by Session Manager”, typically holding Autocheck Autochk *. It runs between the loading of boot and system-start drivers and the enabling of paging, and Session Manager resolves the names against system32. TRADE Nothing loads earlier in user mode, and that is exactly the cost: a program here runs before paging is enabled, with no user-mode environment around it. Microsoft warns against removing the default value, and a machine that never runs autochk never checks its file system at boot. [71][80] 2026-08-05 · 25H2
A-09 “Replace the Windows shell with a faster one” HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon → Shell, Userinit MS-KB Shell = explorer.exe and Userinit = C:\windows\system32\userinit.exe. “Winlogon service tries to load the Windows default shell (explorer.exe) and user shell (userinit.exe) from registry” at this path. HARMFUL The mechanism of the loss is that these two values are load-bearing for logon itself. If either does not resolve, Winlogon cannot start the shell and the user cannot log in — which is why the Microsoft page documenting the correct values is a logon-failure article rather than a customisation guide. [72][80] 2026-08-05 · 25H2
A-10 “Preload system DLLs so programs launch faster” HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\KnownDLLs MS-DOC “If the DLL is on the list of known DLLs… then the system uses its copy of the known DLL.” Known DLLs is step 5 of the documented search order, ahead of the application folder and the system folder. Safe DLL search mode is on by default. UNVERIFIED What is documented is the list’s position in the loader’s search order, not a preload. We could not confirm from any primary source that adding an entry changes launch time, and adding one changes which copy of a DLL every process resolves to. Checked: the DLL search order page, both packaged and unpackaged orders, the Session Manager references. [73][80] 2026-08-05 · 25H2
A-11 “Install our layer to optimise your network” Winsock Layered Service Providers · the Winsock catalog MS-DOC “Layered Service Providers are deprecated. Starting with Windows 8 and Windows Server 2012, use Windows Filtering Platform.” Uncategorised providers “will not be loaded in services or system processes” including lsass, winlogon and many svchost processes. Win8 SUPERSEDED The platform replaced this with the Windows Filtering Platform more than a decade ago, and an uncategorised provider is already excluded from the processes that matter most. A broken chain here historically took the machine’s networking with it. [74][80] 2026-08-05 · 25H2
A-12 “Repair your Windows logon and password security” HKLM\SYSTEM\CurrentControlSet\Control\Lsa → Security Packages, Notification Packages MS-DOC A REG_MULTI_SZ list of DLL names without the extension. “Each time the system starts, the LSA loads the SSP/AP DLLs in this list.” Separately: “Windows doesn’t support removing, replacing, or wrapping inbox security packages… As of January 10, 2017, Windows prevents these actions.” Win8.1 · 2017-01-10 HARMFUL The mechanism of the loss is that this list is loaded into the Local Security Authority at every boot. A DLL here that is missing, wrong or unloadable does not degrade logon, it prevents it, and the failure appears before there is a desktop to run a repair tool on. [75][96][80] 2026-08-05 · 25H2
A-13 “Clean up printer drivers to fix a slow spooler” HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\<name>\Driver MS-KB Each monitor is a subkey with a Driver value naming a user-mode DLL the spooler loads; the in-box example is Standard TCP/IP Port pointing at tcpmon.dll. Installing one requires SeLoadDriverPrivilege and the file must be in system32. DEPENDS Condition: whether the DLL a monitor names is still on disk. Microsoft’s documented failure here is a spooler crash caused by a leftover monitor entry, which means this is one of the few rows where a genuine leftover really does break something — and removing the wrong one breaks printing. [76][80] 2026-08-05 · 25H2
A-14 “Remove desktop gadgets that slow your machine” HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Windows\Sidebar\TurnOffSidebar MS-DOC Security Advisory 2719662, published 2012-07-10, shipped an automated solution that “disables Windows Sidebar and Gadgets on supported editions of Windows Vista and Windows 7”. Windows 8 went further: “we have chosen to remove Gadgets from the operating system entirely.” Win8 SUPERSEDED Microsoft disabled this in 2012 and removed it in Windows 8, so on any supported build there is nothing here to clean. The row is kept because the surface is still enumerated by Autoruns and still appears in tool feature lists. [77][78][80] 2026-08-05 · 25H2
A-15 “Install our codec pack to speed up video playback” HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 MS-DOC Documented only incidentally, inside an audio-compression API reference: “The lParam parameter is a registry value name in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32. The value identifies a DLL that implements an ACM codec.” UNVERIFIED No Microsoft page treats this key as a subject: there is no documented layout, no enumeration of the value-name prefixes, and no statement about when entries are loaded. Checked: the ACM API reference, the multimedia reference pages, learn.microsoft.com searches for the key path. [79][80] 2026-08-05 · 25H2
A-16 “One list of everything that starts, with nothing hidden” Sysinternals Autoruns · autorunsc -a * SYSINTERNALS Autoruns publishes its own coverage as command-line switches: b boot execute, d AppInit DLLs, e Explorer add-ons, g sidebar gadgets, h image hijacks, i IE add-ons, k known DLLs, l logon, m WMI, n Winsock providers, o codecs, p printer monitor DLLs, r LSA providers, s services and drivers, t scheduled tasks, w Winlogon. TRADE It is free, it is Microsoft’s, and it will show you dozens of entries you do not recognise and cannot safely remove — it names surfaces, it does not render verdicts. That is the trade, and publishing the boundary is the difference between this tool and everything else in this table. [80] 2026-08-05 · 25H2

§4What this Ledger covers, and what it does not

Declaring the boundary is the second question in the preamble, so it would be indefensible not to answer it here. Autoruns publishes its coverage as command-line switches; this is ours.

Covered. These surfaces are in scope, are documented above where a row exists, and will accumulate rows as articles are published:

HKLM and HKCU Run and RunOnce · the per-user and all-users Startup folders · services and their Start values · drivers · scheduled tasks · trigger-start registrations · WMI permanent event subscriptions · shell extensions · browser helper objects · AppInit_DLLs · image file execution options · BootExecute · Winlogon Shell and Userinit · KnownDLLs · Winsock protocol and network providers · LSA security packages · codecs registered under Drivers32 · printer monitor DLLs · sidebar gadgets · the Memory Management key · PrefetchParameters · TCP autotuning levels · the component store · page file settings · power schemes · the boot configuration store

Not covered, and this list is as binding as the first one:

Claim when the computer be used for a period of time, the registry becomes very large, serious impact on computer speed Archived vendor help topic, tlwinset.com/wineb/wh16.htm, capture 2013-09-24. Checked 2026-08-05 · Ledger row R-01

The premise in that card is the reason the whole category exists, and Microsoft documents that it stopped being true a very long time ago. The registry size quota is a Windows 2000 concept; from Windows XP and Windows Server 2003 the documentation states there are no explicit limits on the space hives may consume. Row R-01 carries the detail, including the one place the old quota is still honoured if an administrator sets it deliberately.


§5Sources

Numbered, keyed from column 10. Primary sources preferred throughout: Microsoft documentation first, Microsoft KB and Sysinternals second, archived Microsoft material where nothing current exists, and archived vendor pages only for what a vendor claimed. Every one of these was fetched by us on 2026-08-05, which is the access date for all of them, and several are in the table specifically because the fetch failed or the page had been unpublished.

  1. EmptyWorkingSet function (psapi.h)
  2. SetProcessWorkingSetSize function (memoryapi.h)
  3. MEMORYSTATUSEX structure (sysinfoapi.h)
  4. Memory object performance counters, including Available Bytes (archived, Windows Server 2003)
  5. Enable-MMAgent (MMAgent module)
  6. Cache and memory manager improvements in Windows Server
  7. Memory compression in Windows 10 RTM, with the Windows kernel team
  8. How to determine the appropriate page file size for 64-bit versions of Windows
  9. Introduction to the page file
  10. Shutdown: Clear virtual memory pagefile
  11. DisablePagingExecutive (archived, Windows Server 2003)
  12. Kernel Trace Control API reference (Windows Performance Toolkit)
  13. ReadyBoost with an SD card or a flash drive
  14. Support and Q&A for solid-state drives (archived, Engineering Windows 7, 2009-05-05)
  15. Inside the Windows Vista Kernel, Part 2, Mark Russinovich
  16. RAMMap (Sysinternals)
  17. Disable Prefetch (archived, Windows Embedded Standard 7)
  18. Registry storage space
  19. Windows honors Registry Size Limit functionality if the key is set (KB 2567018)
  20. Microsoft support policy for the use of registry cleaning utilities (KB 2563254). Unpublished by Microsoft. Every live URL redirects to the generic Windows hub; this archived capture is the only readable form we found
  21. How Microsoft identifies malware and potentially unwanted applications
  22. Run and RunOnce registry keys
  23. AppInit DLLs and Secure Boot
  24. Debugging a service, which documents the Image File Execution Options Debugger value
  25. MenuShowDelay (archived, Windows 2000 Server registry reference)
  26. Win32PrioritySeparation (archived registry reference)
  27. [MS-FSA] Appendix A: Product Behavior — the only Microsoft source stating the 1803 last-access change
  28. fsutil behavior. Stale on last-access semantics; documents only the pre-1803 form
  29. AutoEndTasks (archived)
  30. WaitToKillAppTimeout (archived)
  31. HungAppTimeout (archived)
  32. User Account Control settings and configuration
  33. Enabling and disabling AutoRun
  34. SkipRearm (Windows unattend reference)
  35. Error when running sysprep /generalize (KB 929828), which states the three-rearm maximum
  36. CreateServiceW function
  37. The HKLM\SYSTEM\CurrentControlSet\Services registry tree
  38. SERVICE_DELAYED_AUTO_START_INFO structure
  39. Service trigger events
  40. Svchost.exe service refactoring
  41. Security guidelines for system services in Windows Server 2016. Server-scoped by its own statement
  42. Guidance on configuring system services (Windows IoT Enterprise, fixed-function devices)
  43. Windows Search performance issues (KB 4558579)
  44. BCDEdit /set
  45. BCD boot options reference
  46. Distinguishing fast startup from wake-from-hibernation
  47. Fast Startup causes system hibernation or shutdown to fail
  48. On/Off Transition Performance assessment (Windows ADK)
  49. Disk Defragmenter tools and settings (archived, Windows Server 2003)
  50. defrag
  51. Kernel-mode code signing policy (Windows Vista and later)
  52. Startup apps (Windows 8 developer cookbook), with the startup-impact thresholds
  53. 4-gigabyte tuning
  54. cleanmgr
  55. Automating the Disk Cleanup tool (KB 253597)
  56. Policy CSP — Storage, which carries the Storage Sense defaults
  57. Determine the actual size of the WinSxS folder
  58. Compact OS, single-instancing, and image optimization, which carries the hibernation and footprint measurements
  59. What is application launch prefetching? (archived Microsoft blog)
  60. Optimize-Volume, with the per-media-type defaults
  61. powercfg command-line options
  62. Collecting user-mode dumps
  63. Additional resources for Windows Update
  64. DISM storage reserve command-line options
  65. KNOWNFOLDERID, which gives both Startup folder paths
  66. TASK_TRIGGER_TYPE2 enumeration
  67. CommandLineEventConsumer class
  68. Only allow approved Shell extensions (archived)
  69. The basics of Browser Helper Objects (archived Microsoft blog)
  70. Internet Explorer and Microsoft Edge lifecycle FAQ
  71. Inside Native Applications, Mark Russinovich (Sysinternals)
  72. Cannot log on to Windows, which gives the Winlogon Shell and Userinit defaults. Carries Microsoft’s community-content disclaimer
  73. Dynamic-link library search order
  74. Categorizing Layered Service Providers and applications
  75. Registering SSP/AP DLLs
  76. Print spooler crashes (KB 947477), which gives the Print\Monitors key layout
  77. Microsoft Security Advisory 2719662, vulnerabilities in Gadgets
  78. Desktop gadgets removed (Windows 8 developer cookbook)
  79. acmDriverAdd function, the only Microsoft page naming Drivers32
  80. Autoruns for Windows (Sysinternals), with the autorunsc coverage switches
  81. Performance tuning network adapters, with the five auto-tuning levels and the default
  82. New networking features in Windows Server 2008 and Windows Vista (The Cable Guy, archived)
  83. SMB: No registry setting for tuning the TCP window size in TCP/IP should exist (archived)
  84. netsh interface ipv4 set subinterface (archived)
  85. TCP/IP and NBT configuration parameters (KB 314053). Scoped to Windows XP and never republished
  86. Policy CSP — ADMX_QoS, which states the 80 percent Packet Scheduler figure
  87. Archived Tenglnet product page, tlwinset.com/index.htm, capture 2008-10-24
  88. Archived Windows Winset capability index, tlwinset.com/help.htm, capture 2012-08-24
  89. Archived Windows8 Winset capability index, tlwinset.com/wineb/help.htm, capture 2013-09-22
  90. Archived help topic, boot speed, tlwinset.com/wineb/wh3.htm, capture 2013-09-24
  91. Archived help topic, services, tlwinset.com/wineb/wh5.htm, capture 2013-09-24
  92. Archived help topic, memory, tlwinset.com/wineb/wh6.htm, capture 2013-09-24
  93. Archived help topic, registry, tlwinset.com/wineb/wh16.htm, capture 2013-09-24
  94. Archived help topic, disk immunisation, tlwinset.com/wineb/wh19.htm, capture 2013-09-24
  95. Archived help topic, licensing, tlwinset.com/wineb/wh25.htm, capture 2013-09-24
  96. Restrictions around registering and installing a security package
  97. Receive Window Auto-Tuning for HTTP (KB 947239)

Four things this list records by their absence, each of which drove a verdict above. KB 2563254, the registry-cleaner support policy, is unpublished and readable only in an archive capture. KB 971029, the AutoRun restriction update, and KB 316666, the bandwidth-reservation explanation, both return 404 at every support.microsoft.com URL we checked, in numeric and GUID forms. And the Microsoft blog post everyone quotes for “never disable auto-tuning” now redirects to a landing page. A reference that cites sources it has not fetched cannot notice any of that, which is why every one above was fetched.


§6How a row changes, and where the old one goes

Every edit to a row is dated and kept at /mechanisms/changes/. Nothing here is silently revised: if a verdict moves, the old verdict stays on that page with the source that moved it. The log is live and empty at launch, which is the only honest state for a record that has recorded nothing yet.

The sixteen UNVERIFIED rows are restated as open questions at /mechanisms/unverified/, each with the single piece of evidence that would close it. If you hold one of those pieces the address is the contact form, corrections are published with the same prominence as the original claim, and whoever gets there first is credited in the body rather than in a footnote.

Once a row’s LAST VERIFIED date is more than a year old the row is drawn differently, so you can see at a glance which entries nobody has looked at lately and weigh them accordingly. That matters more here than it sounds: Microsoft unpublished its registry-cleaner support policy some time after December 2023, and a reference that cannot notice a source disappearing is not a reference.

Claim You can use windows7 offers up 360 days free from this feature. Archived vendor help topic, tlwinset.com/wineb/wh25.htm, capture 2013-09-24. Checked 2026-08-05 · Ledger row R-12

Microsoft’s documented mechanism in that family is an activation grace period of typically thirty days plus a maximum of three rearms. The advertised figure is twelve times thirty. We state the documented limit as a fact, we state that the claim exceeds it, and we decline to describe any method of going further. Row R-12 is the only UNSAFE-CLAIM in the table.