With this tutorial your PC will gain performance in Windows 10 or 11

Performance on Windows 10 or 11

Performance on Windows 10 or 11

With this tutorial your PC will gain performance in Windows 10 or 11

The arrival of Windows 11 on our computers has brought several interesting news. Among them is the use of hardware virtualization in the most advanced CPUs to provide an additional layer of security, but its use means a cut in performance. With this tutorial you will be able to deactivate VBS and gain what you lost on your PC, especially in Windows 11.

One of Microsoft's obsessions with its new version of Windows has to do with security and the goal of achieving a reliable computing environment, which is important in corporate and business environments where a large amount of sensitive and private data is handled. Specifically, they recommend that manufacturers and assemblers of new computers sell them with VBS activated by default, which prevents malicious code from being executed that fails code integration checks due to the fact that they impersonate reliable applications and drivers. .

Home Performance Windows 11

Any extra security is always good, the problem comes when that extra security becomes a considerable loss of performance in the CPUs, especially if you use a first generation AMD Ryzen, the 1000 series, or an Intel Core 10 or earlier. If we have the case of using relatively modern hardware you can lose a 5% of performance, but as we go further into the past we can see performance cuts in a 28%.

Microsoft currently allows gaming PCs that ship with Windows 11 to be sold with VBS and HVCI disabled, but we may have bought a pre-built PC not originally designed for gaming and converted it for gaming or simply upgraded from Windows 10.

What are VBS and HVCI?

VBS Architecture Windows 10

In its simplest definition, VBS uses hardware virtualization capabilities to create a region within memory that is completely isolated from the rest of the system. In other words, it makes use of the capabilities that allow us to run other operating systems through a hypervisor, but not to run an entire system, but to run certain functions of Windows 10 and later in said isolated environment.

One way to break security is through hardware drivers, because they are used to communicate programs with the different physical components of the computer, many of them have a level of privileges much higher than a normal program and a programmer with bad intentions can take advantage of this and pass off malicious applications as drivers.

Windows VBS Diagram 2

In order to gain an additional level of security, Hypervisor-Enforced Code Integrity or HVCI is used, which makes use of Virtualization-based Security or VBS in Windows to check if the code is malicious or not. How? Well, in the same way that a gunner can explode a bomb in a controlled environment, the same thing is done here: the malicious driver is executed in a separate environment that cannot affect the rest of the system. Another feature is to assign the TPM module's own memory environment to store the key credentials for the use of certain sensitive actions such as the user's personal and banking data.

Of course, this means having to run an additional environment that cuts processor resources that we will want to have available for our applications. Let's see below how to deactivate this function of Windows 11 and recover the lost power.

How to know if VBS is enabled?

Administrator System Symbol

The first and most important thing is to know if VBS is active in our Windows 11 installation and here the answer is that it depends on how we have carried out the installation. If for example we have updated from a Windows 10 installation then the VBS will be inactive, but if you have done an installation from scratch or it is a new device it will always be active, so the first thing we will have to know is if this technology is active or no.

To do this you just have to follow the following steps:

  1. Type in the search box on the taskbar: system information. System search should find a eponymously named program that you'll need to run.
  2. Without selecting anything, scroll down until you see the line that says virtualization-based security, there you can see if VBS is enabled or not.

Hint: VBS requires a TPM 2.0 module (software or hardware) to work, so if you don't have one then the feature won't work. This is also a good way to check if your Windows 10 PC has a TPM module enabled and working.

How to disable Windows 11 VBS on your PC

core insulation

The first thing you have to keep in mind is that there are two ways to deactivate, or rather, to disable VBS in your Windows 11 installation, to do so, follow these steps:

  1. In Windows taskbar search type: kernel isolation. This will find you a specific page of the system configuration that is the one you see below:
  2. Well, you just have to keep the "memory integrity" disabled to keep the VBS completely disabled, with this you will make your Intel or AMD CPU gain performance under Windows 11 in exchange for losing security. So we recommend it if you are going to do things like run a video game, render a scene with Blender, or simply install a program whose decompression requires a lot of processing.

Using the command prompt

Command Prompt Administrator 1

The other option is to use the command prompt, to do this follow these steps:

  1. Type cmd in the search on the Windows taskbar so that it finds the command prompt, but do not run it as is, instead right click on the search and select run as administrator to be able to run it with all permissions, because we will need them.
  2. Then write the following: bcdedit /set hypervisorlaunchtype off
  3. With this, the VBS will be deactivated immediately, in any case we do not need to tell you both in this case and in the previous one that it is totally recommended to restart the computer so that the changes take effect in the system.

We hope that this tutorial has been useful to you and that the lost performance of your CPU returns to the same after disabling VBS, although if you work in an environment that requires data protection, we do not recommend it. Endangering the data of your clients has criminal consequences in several countries, so if you are professionals in certain sectors, we recommend that you do not carry out this operation because of what could happen with malicious programs.

(Source: https:hard zone

5 1 vote
Article Rating
Suscribir
Notificar de
guest

0 comments
Comentarios en línea
Ver todos los comentarios