Performance on Windows 10 or 11
With this tutorial your PC will gain performance in Windows 10 or 11
The arrival of Windows 11 on our computers has brought several interesting new features. Among them is the use of hardware virtualization in the most advanced CPUs to provide an additional layer of security, but its use involves a reduction in performance. With this tutorial You will be able to disable VBS and regain what you lost on your PC, especially on Windows 11.
One of Microsoft's obsessions with its new version of Windows has to do with the security y el objetivo de conseguir un entorno de computación confiable, lo cual es importante en entornos corporativos y empresariales donde se manejan una gran cantidad de datos sensibles y privados. En concreto recomiendan a los fabricantes y ensambladores de nuevos ordenadores que los vendan con el VBS activado por defecto, los cuales previenen que se pueda ejecutar código malicioso que falla las comprobaciones de integración del código por el hecho que se hacen pasar por applications y controladores confiables.
Any extra security is always good, the problem comes when that extra security becomes a loss of performance considerable on CPUs, especially if you're using a first-generation AMD Ryzen, the 1000 series, or an Intel Core 10 or older. If we have the case of using hardware relatively modern you can lose a 5% of performance, but as we go further back we can see performance cuts on a 28%.
Microsoft currently allows gaming PCs that ship with Windows 11 They are sold with VBS and HVCI disabled, but we may have purchased a pre-built computer not originally designed for gaming and have converted it for gaming or simply upgraded from Windows 10.
What are VBS and HVCI?
In its simplest definition, VBS uses the virtualization capabilities of hardware to create a region within memory that is completely isolated from the rest of the system. In other words, it makes use of the capabilities that allow us to run other operating systems through a hypervisor, but not to run an entire system, but to execute certain functions of a system. Windows 10 and later in that environment isolated.
One way to break security is through hardware drivers, because they are used to communicate programs with different devices. components Many of the computer's physical drivers have a level of privileges much higher than a normal program and a programmer with bad intentions can benefit from this and pass off malicious applications as drivers.
Con tal de ganar un nivel de security adicional se hace uso del Hypervisor-Enforced Code Integrity o HVCI que hace uso del Virtualization-based Security o VBS en Windows para comprobar si el código es malicioso o no. ¿Cómo? Pues de la misma manera que un artillero puede hacer explotar una bomba en un entorno controlado, aquí se hace lo mismo: se ejecuta el driver malicioso en un entorno separado que no puede afectar al resto del sistema. Otra de las funcionalidades es asignar el entorno de memory typical of the TPM module to store key credentials for the use of certain sensitive actions such as the user's personal and banking data.
Of course, this means having to run an additional environment that cuts processor resources que vamos a querer tener disponibles para nuestras aplicaciones. Veamos a continuación cómo desactivar esta función de Windows 11 y recuperar la potencia perdida.
How to know if VBS is enabled?
The first and most important thing is to know if the VBS is active in our installation of Windows 11 and here the answer is it depends on how we have performed the installation. If for example we have updated from a Windows 10 installation then the VBS will be inactive, but if you have done an installation from scratch or it is a new device it will always be active, so the first thing we will have to know is if this technology is active or not.
To do this you just have to follow the following steps:
- Escribe en el cuadro de búsqueda de la taskbar: información del sistema. La búsqueda del sistema debería encontrar un programa de nombre homónimo que tendrás que ejecutar.
- Sin seleccionar nada haz scroll hacia abajo hasta que veas la línea que pone security basada en virtualización, ahí podrás saber si el VBS está habilitado o no.
Una pista: el VBS requiere un módulo TPM 2.0 (software o hardware) para funcionar, por lo que si no tenéis uno entonces dicha característica no se podrá activar. Esto es también una buena way to check if your Windows PC 10 has a TPM module enabled and working.
How to disable Windows 11 VBS on your PC
Lo primero que tienes que tener en cuenta es que existen dos formas de desactivar, o mejor dicho, de inhabilitar el VBS en tu instalación de Windows 11, para ello sigue los siguientes pasos:
- In the Windows taskbar search, type: core isolation. This will take you to a specific page in the system configuration, which is the one you see below:
- Well, you just have to keep the "memory integrity" disabled to keep the VBS completely disabled, with this you will make your Intel or AMD CPU gain performance under Windows 11 in exchange for losing security. So we recommend it if you are going to do things like running a video game, rendering a scene with Blender or simply installing a program whose decompression requires a large amount of processing.
Using the command prompt
The other option is to use the command prompt, to do this follow the following steps:
- Escribe cmd en la búsqueda de la barra de tareas de Windows para que encuentre el símbolo del sistema, pero no lo ejecutes tal cual, sino que pulsa con el botón derecho sobre la búsqueda y selecciona ejecutar como administrador para poder ejecutarlo con todos los permisos, ya que nos serán necesarios.
- Then write the following: bcdedit /set hypervisorlaunchtype off
- With this, the VBS will be deactivated immediately, in any case, we do not need to tell you in this case as in the previous one that it is totally advisable to restart the computer for the changes to take effect in the system.
We hope that this tutorial We hope that you found it useful and that your CPU's lost performance returns to normal after disabling VBS, although if you work in an environment that requires data protection we do not recommend it. Putting your clients' data at risk has criminal consequences in several countries, so if you are a professional in certain sectors we recommend not performing this operation because of what could happen with malicious programs.
(Source: https:Hardzone