With the recent news that Dell installed a root certificate with a publicly accessible private key on their notebooks, I'm wondering how I can protect myself against this kind of incompetence. Of course I can't fully protect myself against actually malicious attacks by the vendor if I execute their binaries, but I would like to be notified if any program installs a root certificate that compromises my security.
Doing a clean Windows installation is something I do anyway, but as far as I know this wouldn't help in this case as the certificate was added by Dell software. And I probably need to install at least some Dell software for the drivers. I'd also like to prevent certificates from other sources to be installed without my knowledge.
Is there an easy way to verify if any root certificates are installed that aren't the default ones that come with Windows?