Investigate Startup Processes
pdf
keyboard_arrow_up
School
Amarillo College *
*We aren’t endorsed by this school
Course
ITSC 2335-
Subject
Information Systems
Date
Dec 6, 2023
Type
Pages
3
Uploaded by HighnessReindeer4532
Investigate Startup Processes
OBJECTIVES
The goal of this lab is to identify malicious software running on your computer by examining all running
processes. After completing this lab, you will be able to:
•
Identify all processes running on your computer at startup
•
Use the Internet to determine the function of each process
MATERIALS REQUIRED
This lab requires the following:
•
Windows 10 operating system
•
An account with administrator privileges
•
Internet access
LAB PREPARATION
Before the lab begins, the instructor or lab assistant needs to do the following:
•
Verify Windows starts with no errors
•
Verify each student has access to a user account with administrator privileges
•
Verify Internet access is available
ACTIVITY BACKGROUND
As more add-ons, utilities, and applications are installed on a system over time, they can cause Windows
to slow down and give errors. When a program automatically launches at startup, it takes up valuable
computer resources behind the scenes and can cause startup errors. In this lab, you learn to investigate
all the startup processes on your computer and to identify those you should remove.
Follow these steps to investigate the startup processes on your computer:
1. Restart your computer and log on as an administrator.
2. Use Task Manager to display all the running processes on your machine. Use the Details tab in Task
Manager. Be sure to show processes for all users.
3. How many processes are running? Note that many processes are listed twice, but you should count
each process only once. To help you identify processes listed more than once, click the Name column in
to sort the processes by process name. Figure 1 shows the running processes for one system, but yours
will be different. Write down or create screen shots that show these processes, so you can compare
them to the Safe Mode processes later in the lab (Step #5).
71
Figure 1 The Name and Image path name columns on the Details tab can help you identify a process and how it is loaded.
4. Now reboot the computer in Safe Mode and use Task Manager to list the running processes for all
users again. How many processes are running now? (Remember: Count each process only once.)
22
5. Which processes didn’t load when the system was running in Safe Mode?
(Compare to the list created
in step #3).
Apps that were not critical did not run.
6. Research each process identified in Step 5 on the web and write a one-sentence explanation of each
process on a separate piece of paper.
•
Did you find any malicious processes running? If so, list them:
No
•
Did you find any programs that should be uninstalled from the system? If so, list them:
None
•
Suppose one of the processes running on your computer is named whAgent.exe. What program
is associated with this process?
WebHancer
•
How could you use the System Configuration utility to temporarily disable a process?
By
enabling or disabling a process.
•
List the steps you could take to remove this program from your computer:
Control
Panel>Programs>Uninstall a Program, then right click program and choose uninstall.
7. To improve the computer’s performance, use the System Configuration utility to temporarily disable
any program that you decide is not necessary. Which program, if any, did you disable?
None
8. If the system works fine with the program disabled, go ahead and uninstall the program. Which
program, if any, did you uninstall?
None
REVIEW QUESTIONS
1. Why is it a good idea to temporarily disable a program before removing it altogether?
To clear program from the cache and prevent program from running in background.
2. Why might anti-malware software not detect malicious software?
Malicious software does not contain a signature database.
3. Why would you expect fewer processes to be running in Safe Mode?
Safe Mode should only run critical processes.
4. Why is disabling the Lsass.exe process not a good idea?
Prevents other services from starting correctly through security accounts manager.
5. What key do you press during startup to launch Safe Mode?
F4
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
- Access to all documents
- Unlimited textbook solutions
- 24/7 expert homework help