Solved

Is there a way to determine if a system runs faster after malware removal?

Posted on 2013-06-12
6
433 Views
Last Modified: 2013-11-22
I am frequently called on, mostly by friends and family, to help cleanup computers that have malware on them. I have been googling, but not able to find any sort of program that can help me verify the difference in system performance before and after a computer has been cleaned.
I am not looking for the standard benchmark test, that puts stress on the components, but rather something that simply shows a score of how fast the system runs. Obviously this would have to be a lightweight application to be able to run on a potentially highly infected machine before cleanup.

Any ideas?

Thanks,
0
Comment
Question by:dwils15
6 Comments
 
LVL 24

Expert Comment

by:aadih
ID: 39241398
I don't believe such a program exists. Sorry.
0
 
LVL 14

Assisted Solution

by:Rob Miners
Rob Miners earned 175 total points
ID: 39242880
If you are supporting Vista, Windows 7 or Windows 8.

Viruses, spyware and other malware can slow your boot to a crawl ...

You could create a batch file containing this one liner to determine if the startup process gets faster. It will collect data from 20 startups and keep overwriting the output each time it is run, adding the newest boot time to the first entry.

wevtutil qe Microsoft-Windows-Diagnostics-Performance/Operational /rd:true /f:text /c:20 /q:"*[System[(EventID = 100)]]" /e:Events > "%userprofile%\Desktop"\AVerageBootDuration.txt

note: you will need elevated privelages to run these batch files.

eXtra reading

Performance Testing Guide for Windows

http://msdn.microsoft.com/en-us/windows/hardware/gg463399.aspx
0
 
LVL 30

Assisted Solution

by:Sudeep Sharma
Sudeep Sharma earned 175 total points
ID: 39244400
You would already have these events available on Windows 7 and 8.

Try checking them first before following above steps.

Open event  viewer, go to Microsoft -> Windows -> Diagnostics-Performance and check that you should have Boot Performance Monitoring (Event ID 100)  and Shutdown Performance Monitoring (Event ID 200).

Sudeep
0
Revamp Your Training Process

Drastically shorten your training time with WalkMe's advanced online training solution that Guides your trainees to action.

 
LVL 1

Accepted Solution

by:
dwils15 earned 0 total points
ID: 39319278
0
 
LVL 1

Author Closing Comment

by:dwils15
ID: 39329137
I selected my own solution because it is closest to what I am looking for.
0
 
LVL 14

Expert Comment

by:Rob Miners
ID: 39329214
Cool and thanks for the links :)
0

Featured Post

PeopleSoft Has Never Been Easier

PeopleSoft Adoption Made Smooth & Simple!

On-The-Job Training Is made Intuitive & Easy With WalkMe's On-Screen Guidance Tool.  Claim Your Free WalkMe Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When you try to extract and to view the contents of a Microsoft Update Standalone Package (MSU) for Windows Vista, you cannot extract the files from the MSU. Here we are going to explain how to extract those hotfix details without using any third pa…
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question