3) Windows OS & PC Security Issues Flashcards

1
Q

Windows Symptoms: Slow Performance

A

Task Manager > Check for high CPU usage
Windows Update (latest patches/drivers)
Check for available space & defrag
Laptop (Power saving mode?)

Run anti-virus/anti-malware (especially if unrecognized processes running)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Windows Symptoms: Limited Connectivity

A

Yellow triangle over network icon (or in network status)

Local:
Check physical connection, check WAP connection
Check IP configuration
Reboot

External:
Wireless router rebooted/turned off
Ping default gateway & external IP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Windows Symptoms: Failure to Boot

A

asdf

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Windows Symptoms: No OS Found

A

Check boot drives (remove any media)
Startup repair (can look at every step along boot process)
Modify Windows Boot Config Database (BCD)
Formerly boot.ini
Recovery Console: bootrec /rebuildbcd

Missing NTLDR (boot loader is missing)
Run startup repair or replace manually & reboot
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Windows Symptoms: App Crashes

A

Check event log

Check reliability monitor (history of app problems)
Checks for resolutions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Windows Symptoms: BSoD

A

Bad hardware, bad drivers, bad application
Newer BSoD may give some details

Use last known good config, system restore, rollback driver (also try safe mode)

Reseat/remove hardware
Run hardware diagnostics (by manufacturer)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Windows Symptoms: Black Screens

A

Driver corruption, OS system file corruption

Video Driver - Start in VGA mode - F8 for startup options
Or update driver in safe mode (known good source)

Run SFC (run from recovery console)

Repair/refresh or recover from backup

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Windows Symptoms: Printing Issues

A

Print or scan a test page (built into Windows)
Different from application printing

Use diagnostic tools
Web-based, vendor specific, generic

Clear the print queue or clear specific print job
Restart print spooler

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Windows Symptoms: Services fail to start

A
"One or more services failed to start"
Bad/incorrect driver, bad hardware
Try starting manually
Check account permissions
Confirm service dependencies
If Windows service, check system files
If application service, reinstall application

Open Windows Services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Windows Symptoms: Slow Bootup

A

Boot process hangs or takes longer than usual
No activity, no drive lights

Manage startup apps
Win10: Task Manager | Earlier: msconfig

Or disable everything, load them back one at a time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Windows Symptoms: Slow Profile Load

A

Roaming user profile
Desktop follows you to any computer

Network latency to domain controller
Slows login scripts, slow to apply policies

Client picks a remote domain controller instead of local

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Windows Solutions: Defragment HDD

A

Moves file fragments so they are contiguous
Sharing a common border (in order)
Improves read/write speeds

Cmd: defrag
May be in weekly schedule (task scheduler)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Windows Solutions: Reboot

A

Why it works:
Bug in router software (reset router)
App using too many resources (stops the app)

Memory leak slowly consumes available RAM
(Clears RAM & starts again)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Windows Solutions: Kill Tasks

A

Sometimes you can locate the problem process via task manager and kill it.

Source by resource (CPU/Memory/Network/Disk)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Windows Solutions: Restart Services

A

Services - apps running in background
Same types of problems as interactive apps

Task Manager/Services: Start/Stop/Restart/Pause/Resume

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Windows Solutions: Update Network Settings

A

One config mismatch can cause significant slowdowns
Speed/duplex settings need to match

Most auto negotiations work fine (until they don’t)
Certain configs may need manual speed/duplex settings

Driver may not show negotiated value

17
Q

Windows Solutions: Reimage/reload OS

A

Windows is huge/complex
Spend time finding the needle, or just build a new haystack

Many organizations have pre-built images
(May be best not to research issues)

Win 8/10 includes reset option
Settings > Update/Security > Recovery

18
Q

Windows Solutions: Roll Back Updates

A
Restore Points (rewind to previous config)
Restore point can be created automatically with application installations.
19
Q

Windows Solutions: Roll Back Devices/Drivers

A

Device drivers can break Windows

Device Manager > Roll Back Driver

20
Q

Windows Solutions: Apply Updates

A

Windows Update
Centralized OS & Driver Updates
Flexibility: Change active hours | Auto/Manual

Applications must be patched
Security issues don’t stop at the OS
Download from publisher

21
Q

Windows Solutions: Repair Application

A

Some applications have a repair option.

Or you can uninstall/reinstall

22
Q

Windows Solutions: Disable Startup Services/Apps

A

Trial & Error
Disable all, begin adding them back
Or disable one at a time
May take many restarts

23
Q

Windows Solutions: Safe Boot

A

Safe Mode - F8 on boot
Advanced Boot Options > Enable Safe Mode
Or interrupt boot process 3 times

If this doesn’t work, Windows is in Fast Startup
Fast Startup: Shutdown = Hibernate
Msconfig to turn off

Networking, Command Prompt, VGA Mode options

24
Q

Windows Solutions: Rebuild Windows Profiles

A

“User profile service failed the logon”
“User profile cannot be loaded”
“User documents may be missing”

Log in with admin rights
Rename existing user folder, backup user registry
HKLM\Software\Microsoft\WindowsNT\CurrentVersion\ProfileList > Right Click > Export
Delete registry entry (you have backup)
Restart

Login with the user account
Profile will be rebuilt
Will recreate \users\name folder

Login as admin, copy over files from old profile
Only move over documents, not all files (may be corrupted)

25
Q

Security Symptoms: Pop-ups

A

Update your browser, use the latest version
Check pop-up block feature or get extension
Scan for malware

26
Q

Security Symptoms: Browser Redirection

A

Browser directs you to the wrong page with a search feature or home page.
Malware is intercepting search queries/results

Use anti-virus/anti-malware
To completely remove, restore to known good backup

27
Q

Security Symptoms: Security Alerts

A

Security alerts may indicate bad certificate
Click on lock icon

Certificate may be expired or linked to wrong domain
Certificate may be invalid (authority not trusted)

28
Q

Security Symptoms: Slow Performance/Internet Connectivity Issues

A

Can be a sign of malware.
Malware may take you where it wants.
You can’t protect yourself if you can’t download.
May block OS update function.

Malware/virus scan

Use software from another resource, or restore from backup/image.

29
Q

Security Symptoms: PC/OS Lockup

A

Could be hardware problem, but also security issue.
Run hardware diagnostic.
Check logs when restarting.
Check Caps/Num Lock

May still be able to kill bad apps

30
Q

Security Symptoms: Application Crash

A
Application stops working, may be malware.
Check event log.
Check reliability monitor.
Reinstall/repair the application.
Virus/malware scan.
31
Q

Security Symptoms: Rogue Antivirus

A

A fake anti-virus/anti-malware software.
May be ransomware.
Can be very difficult to get rid of.

32
Q

Security Symptoms: Spam

A

Unsolicited emails
Advertisements
Phishing attacks
Spread viruses

Spam filters can be helpful.

33
Q

Security Symptoms: Renamed System Files/Disappearing Files

A

Also a sign of malware.
Scan for viruses/malware.

May need to restore to backup.

34
Q

Security Symptoms: File Permission Changes/Access Denied

A

Malware may change file permissions, causing “access denied” errors when trying to access certain files or applications.

35
Q

Security Symptoms: Hijacked Email

A

Infected computers can become email spammers.
May receive odd replies/emails from users.
Bounce messages from unknown emails.

Scan for malware.

36
Q

Security Symptoms: System/App Log Errors

A

Many errors go undetected, so check logs.
Filter & research

Find security issues:
Improper logins
Unexpected app use
Failed login attempts