The human race just turned the wheel over for another year and with it came a new decade. The author is aware that some people say the decade starts in 2021, but the author does not mean to debate that here. Considering the last decade, many things changed: we saw the rise of new attack methods, increasingly complicated attacks, and even the simplifying of some complex attacks into “Malware as a Service”.Continue reading…
A while back a user reached out to me describing a problem of slow access to an external, bus-powered hard drive they had purchased only half a year ago. They said it was a USB 3.0 hard drive and they had also made sure to plug the drive into a USB 3.0 compatible port on their recently purchased laptop. The user also mentioned that the anti-virus solution they were using had unusually long scan times, sometimes running for over 10 hours.
They also described an issue of not being able to properly eject this same external hard drive after using it at the end of the day, but that was a separate issue that will also be covered.
After gaining remote access to this system, so I could see what they were seeing, I checked the configuration of the laptop. They were right, the laptop was powerful with a nice quad-core Intel process, 8 GB of RAM, and a SSD hard drive. But, all of this had little to do with why this external hard drive enclosure, which was a spinning disk, was performing poorly. I loaded the contents of the drive in Windows File Explorer and found multiple folders at the root of the drive. The user began navigating into the the folders and subfolders to find some files they were having issues working with. We navigated down five and six levels deep, and at each level I saw many other folders within each directory. I thought I had spotted the first issue, an index that was far too large to be accessed quickly.
Navigating back out to the root of the external drive, I checked the properties of the folder in which we had just explored and found that while it was not large in size, it had tens of thousands of files and folders within the folder. We checked a few more folders together at the root of the drive and they were the same way, tens of thousands of files and folders within each one. I explained that the drive was formatted as NTFS and that this type of file system kept a Master File Table which was basically an index of every folder and file on the disk. As this Master File Table became larger and larger as times went on, it can also became fragmented. This fragmentation could drastically slowdown the load times of folders and files within folders, because the actuator that controlled the read/write heads would have to constantly bounce around the disk to enumerate the files and folders with all their attributes within a specified directory.
We set about resolving this issue by lowering the overall number of files and folders on the disk. We used an application called 7-Zip to compress one of the folders at the root of the external drive and then deleted the original folder from the drive. This lowered the number of entires in the Master File Table, increasing performance almost immediately. Since the user had mentioned that they were seeing incredibly long scan times with their anti-virus solution, I also recommended we password protect the zipped files, which would keep their anti-virus solution from being able to scan the contents of the file.
Over the course of a few days the user managed to compress and password protect many unused folders at the root of the external drive. They reported back much faster performance of the external drive and the anti-virus scans were no longer taking unacceptable periods of time to complete.
Bonus: Cannot Safely Eject External Drive
We had one last issue to tackle. The user was still having an issue ejecting the disk safely after each use. We plugged in the external drive and were immediately able to safely eject the external drive. We systematically opened files on the external drive with each application they used to perform their work, saved the file, and then tried to eject the drive. Everything went smoothly until the user opened an AutoCAD application file, saved the file, and exited the program. The drive would no longer safely eject. We closed a “helper” program for AutoCAD we found in Task Manager and the drive safely ejected. I showed the user this workaround method and also mentioned that a reboot would allow them to safely eject the drive, too.
This fall, just a few short months from the time of this writing, Microsoft will be releasing a minor update to follow the most recent Windows 10 Creators Update from earlier this year. It will include some new features, including a few that revolve around their built-in Windows Defender suite. With these changes to Windows Defender, Microsoft hopes to make their latest operating system more resistant to ransomware attacks which have become prolific over the last several years.
One of the features coming with the update is called Controlled Folder Access. Microsoft touts the feature as a direct response to ransomware. It will work via a whitelist approach, with Windows Defender only granting certain applications the privilege to access the data of a protected user account; otherwise, the application is not allowed to read, write, or modify any data a user might own such as documents, pictures, or videos.
The default folder list includes Documents, Pictures, Movies, and Desktop and are hard-coded into the feature with no option for removal, but additional folders can be added manually through the Windows Defender Security Center. There will also be an option to add custom software to the whitelist, but Microsoft states that most software should already be pre-whitelisted. If an application is not whitelisted and attempts to alter data within a protected folder it will be automatically blacklisted and the user will be notified. Although this feature has many benefits, Microsoft will have the feature disabled by default. It can also be enabled in the Windows Defender Security Center under Virus & threat protection settings, as seen below.
Other features coming with the Fall Creators Update include a Cloud Clipboard which will allow copy and pasting between multiple Windows 10 devices; a Timeline feature, which will be similar to the app switcher found on many mobile phone operating systems; Pick Up Where You Left Off, which will be an application synchronization service that developers can use much like the Cloud Clipboard; and OneDrive Files On-Demand, which will allow access to files, even if they are only stored in the cloud and not locally.
Windows 10 is also getting a design language refresh. Microsoft is moving away from the Metro UI to offer a more consistent, depth-enabled interface with lighting and motion effects. It is being likened to Google’s own Material Design. Overall, a welcome change, but one that may be more resource demanding.
Will you be upgrading? What feature do you look forward to most? Leave a comment below!
Microsoft recently released their next major evolutionary update to Windows 10 called Creators Update. It boasts a lot of new features and innovations. New additions in the update include Paint 3D, Remix 3D, and greater support for augmented reality with Windows Mixed Reality. Some new features include better Cortana integration with more apps, the ability to easily broadcast games live with Microsoft’s Beam service, and blue light reduction (like Night Shift in iOS). Edge even got a feature update with tab grouping.
There is also a larger feature that has gamers excited called Game Mode. There has been some early testing done and it was found that enabling this mode with slower, cheaper processors did see a performance increase while gaming.
As far as new security features, Microsoft is investing heavily in Windows Defender. They have given Windows Defender its own home with a new applet called Windows Defender Security Center. It gives much more information and allows for overall easier management of security features. Windows Defender Security Center includes other security measures for management, such as Windows Firewall and browser security settings. Additionally, Windows Hello now allows for proximity auto-locking when paired with a bluetooth device. Microsoft also added a privacy dashboard which will allow one to manage activity data across multiple services and more simply change privacy settings.
All of these features and updates are exciting for anyone interested in technology. But, before one dives straight into the update, even if offered automatically, there are some things one might consider doing first. Below is an outlined process by which one might go about performing the Windows 10 Creators Update.
1. Preflight Check
There are certain things that should be completed as a precaution before performing this upgrade to Windows 10 Creators Update. First thing, always make a backup. Disk2vhd is exceptionally good for this and is available for free from Microsoft, included as part of the Sysinternals Suite. Disk2vhd could not be more simple to use. Once you download, unzip the file, and run it, follow these directions:
- Be sure to check the Use Vhdx and Use Volume Shadow Copy options.
- Choose a path where to save the image file and give it a name.
- The author strongly recommends a USB 3.0 external drive with adequate capacity on which to store the image, when considering a path.
- Check the box of the appropriate volumes which should be included, excluding any external volumes.
- Click the Create button.
Depending on how much data is on the volume(s) selected and the transfer speed of the drive used, the time required to complete the backup can range from 30 minutes to several hours. Browse into the image once it is created to make sure it is not corrupt and your files will be accessible, in case the update procedure fails. This can be done by right-clicking the drive and selecting Mount, then opening Disk Management and right-clicking the mounted Disk and selecting Online. When done, in Disk Management right-click the mounted Disk and select Unmount. An additional prompt will appear, just click OK.
Just for safe measure, be sure to unplug the external hard drive after safely ejecting it.
2. Start the Update
If the Creators Update does not appear automatically, it can be started by browsing to the following Microsoft Creators Update page and clicking the Update now button.
This will download a small utility which starts the update. Launching the utility brings up the Windows 10 Update Assistant. Click the Update now button. This will perform a check to see if your system passes the requirements for the update. The utility will then begin downloading and installing the update automatically. Depending on the speed of your connection to the remote server (the Internet), this download can take several minutes to several hours. Feel free to work in the meantime and minimize the window.
Once the update process is completed, the Windows 10 Update Assistant will prompt for a restart of the computer. It also kicks off a 30 minute countdown timer, so be sure to be close at hand when this part of the upgrade process approaches. An unexpected, automated reboot could cause loss of data.
3. The Update Process
Below is a video of the update process. There are several reboots and it took almost an hour to complete on a 2014 iMac with an Intel Core i5 processor and 1 TB spinning disk drive.
4. Post Update
After the update is finished, you will be guided through some of the new settings, displayed below.
5. It is Complete
After everything is complete, if there are no issues, you will be presented with the following screen.
I immediately noticed that the iMac on which this upgrade was performed seemed to run much quicker than it previously had. It is hard to tell if this is due to the optimization of Windows 10 in this update or because the update was like refreshing the system. Applications seem to launch faster and boots seem quicker, as well.
What results have you noticed after the update?
Post a comment below with anything you experienced or what you think about the Creators Update.