2 recipe stable W7 system files (1)

  
a using file signatures to verify that the system files are modified

in Windows7 operating system, all system files (including Microsoft approved driver file) will With Microsoft's signature. The signature information includes information such as the system file name, storage path, file creation date, and version number. If the system administrator deploys the Windows 7 system, collect relevant information. Then, when the operating system is unstable, the system administrator suspects that the system file is damaged, you can compare the signature of the system file with the original signature, and you can determine whether the system file is not known by the administrator. Was changed. Therefore, relevant measures can be taken to repair the system files to restore the stability of the operating system.

Microsoft operating system, now do not need to collect this information manually. A graphical file signing tool is provided in the system to help system administrators do the job. In command line mode, entering the sigverif command will sign the dialog.

This file signature tool is a graphical management tool based on Microsoft's operating system provides. When an application or hardware component is installed, if the system administrator suspects that the original, protected, digitally signed system file or startup program has been illegally modified or replaced, then the tool can be used to check for The existence of this situation. Although this tool already exists in previous versions of the operating system, it has been ignored by everyone. This tool has been improved a lot in Windows 7, especially in terms of performance. After the author's test, in the Windows 7 operating system, this tool runs several times faster than the previous version of the operating system. In addition, this tool has also been improved in functionality. For example, in the previous operating system, only the system files were detected, and the drivers were not detected. For now, this tool will detect both system files and driver files to ensure that all files have Microsoft digital signatures. When the tool detects a file version that is not signed or inaccurate, it will inform the administrator of the relevant information file name, modification time, version number, and so on. This information is also kept in the system-related logs for subsequent queries by the system administrator. But after I use

I think there is an inconvenient place, just can not write these information directly into a text file or copy directly. If the tool now has a problem with a file, such as tcpip.sys this file has a problem. Now system administrators may need to find out the specific purpose of this file on the Internet, and whether anyone has encountered this problem before. But what makes me discouraged is that I can't directly copy the file name. Now when I want to ask others about the purpose of this file, I have to manually input it, not by copying and pasting. The author suggests that Microsoft's design experts can be more humane in this regard. Finally, you can export this information directly to a text file in this window or you can copy and paste directly. Instead of opening a log file to do these behaviors.

Also note that this tool does not repair itself dedicated to the file in question. So running this tool does not require administrator privileges. In other words, ordinary users can also run this program to check if the system files have been maliciously changed.


Copyright © Windows knowledge All Rights Reserved