Unit OS12: Scripting 12.3. Lab Manual. 2 Copyright Notice © 2000-2005 David A. Solomon and Mark Russinovich These materials are part of the Windows Operating.

Slides:



Advertisements
Similar presentations
Installing Citrix Receiver
Advertisements

XP Tutorial 4 New Perspectives on Microsoft Windows XP 1 Microsoft Windows XP Personalizing Your Windows Environment Tutorial 4.
© Neeraj Suri EU-NSF ICT March 2006 Budapesti Műszaki és Gazdaságtudományi Egyetem Méréstechnika és Információs Rendszerek Tanszék Zoltán Micskei
Configuration Files CGS2564. DOS Config.sys Device drivers Memory configuration Autoexec.bat Run programs, DOS commands, etc. Environment settings File.
© Neeraj Suri EU-NSF ICT March 2006 Budapesti Műszaki és Gazdaságtudományi Egyetem Méréstechnika és Információs Rendszerek Tanszék Zoltán Micskei
The Windows Registry Adapted from
Chapter 3: Configuring the Windows Vista Environment.
Microsoft Windows Vista Chapter 6 Customizing Your Computer Using the Control Panel.
WINDOWS XP BACKNEXTEND 1-1 LINKS TO OBJECTIVES Starting Windows Using the Taskbar, opening & switching programs Using the Taskbar, opening & switching.
MZ790 Print Driver and RINC Software Install and Setup These instructions are to assist you in installation and setup of the MZ790 Print Driver and RINC.
Ch 9 Managing Active Directory User Accounts. Objectives Create Organizational Unit Creating User Accounts in Active Directory Disabling, Enabling, and.
Operating System & Application Files BACS 371 Computer Forensics.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Copyright 2007, EMC Paradigm Publishing Inc. WINDOWS XP BACKNEXTEND 1-1 LINKS TO OBJECTIVES Starting Windows Using the Taskbar, opening & switching programs.
OS and Application Files BACS 371 Computer Forensics.
Guide to MCSE , Enhanced 1 Activity 10-1: Restarting Windows Server 2003 Objective: to restart Windows Server 2003 Start  Shut Down  Restart Configure.
Budapesti Műszaki és Gazdaságtudományi Egyetem Méréstechnika és Információs Rendszerek Tanszék Scheduling in Windows Zoltan Micskei
© 2008 The McGraw-Hill Companies, Inc. All rights reserved. M I C R O S O F T ® Preparing for Electronic Distribution Lesson 14.
Windows Operating System Internals - by David A. Solomon and Mark E. Russinovich with Andreas Polze Unit OS4: Scheduling and Dispatch 4.6. Demos.
Beams Division Local Administrators Meeting 9/17/02 Brian Drendel.
Ch 11. Services A service is a specialized program that performs a function to support other programs Many services operate at a very low level – Interacting.
7.3. Windows Security Descriptors
1/28/2010 Network Plus Windows Networking Network Identification Identifies name and type of network. Installed adapters –Performed during Windows installation.
Windows Operating System Internals - by David A. Solomon and Mark E. Russinovich with Andreas Polze Unit OS3: Concurrency 3.5. Lab Slides & Lab Manual.
COMPREHENSIVE Windows Tutorial 5 Protecting Your Computer.
Introduction to Windows7
Computing Fundamentals Module Lesson 3 — Changing Settings and Customizing the Desktop Computer Literacy BASICS.
© Paradigm Publishing Inc. MICROSOFT WINDOWS XP MAINTAINING FILES AND CUSTOMIZING WINDOWS Section 2.
1 © 2001, Cisco Systems, Inc. All rights reserved. Session Number Presentation_ID SQL 2005.
Windows Operating System Internals - by David A. Solomon and Mark E. Russinovich with Andreas Polze Unit OS5: Memory Management 5.5. Lab Manual.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Five Windows Server 2008 Remote Desktop Services,
Copyright © 2007 Heathkit Company, Inc. All Rights Reserved PC Fundamentals Presentation 23 – The Registry.
Unit OS8: File System 8.6. Lab Manual. 2 Copyright Notice © David A. Solomon and Mark Russinovich These materials are part of the Windows Operating.
Windows management Unit objectives: Manage the operating system Configure Task Scheduler Manage resources on your computer Participate in a Remote Assistance.
MODULE 2 Microsoft® Windows 7 Chapter 1: Navigating around Windows Chapter 2: Managing Files and Folders Chapter 3: Working with Windows Settings, Gadgets,
Unit OS11: Performance Evaluation Lab Manual.
Computer Maintenance Windows Tips Windows Tips for Windows 7 Din Ravet 1D MSP3.
Troubleshooting Security Issues Lesson 6. Skills Matrix Technology SkillObjective Domain SkillDomain # Monitoring and Troubleshooting with Event Viewer.
Unit OS A: Windows Networking A.4. Lab Manual. 2 Copyright Notice © David A. Solomon and Mark Russinovich These materials are part of the Windows.
Unit OS6: Device Management 6.4. Lab Manual. 2 Copyright Notice © David A. Solomon and Mark Russinovich These materials are part of the Windows.
Lesson No: 6 Introduction to Windows XP CHBT-01 Basic Micro process & Computer Operation.
XP New Perspectives on Microsoft Office FrontPage 2003 Tutorial 7 1 Microsoft Office FrontPage 2003 Tutorial 8 – Integrating a Database with a FrontPage.
Copyright © 2006 Prentice-Hall. All rights reserved.1 Computer Literacy for IC 3 Unit 1: Computing Fundamentals Project 6: Using Windows.
IT1001 – Personal Computer Hardware & system Operations Week7- Introduction to backup & restore tools Introduction to user account with access rights.
Windows Operating System Internals - by David A. Solomon and Mark E. Russinovich with Andreas Polze Unit OS7: Security 7.4. Lab Manual.
IS493 INFORMATION SECURITY TUTORIAL # 1 (S ) ASHRAF YOUSSEF.
AL A. LAURIO Teacher Microsoft Windows Vista. DESKTOP is the main screen area that you see after you turn on your computer and log on to Windows. it serves.
Windows Operating System Internals - by David A. Solomon and Mark E. Russinovich with Andreas Polze Unit OS3: Concurrency 3.3. Advanced Windows Synchronization.
Creating and Editing a Web Page
COMPUTER SYSTEM TOOLS. SCANDISK MICROSOFT UTILITY PURCHASED FROM NORTON, WHICH IS NOW SYMANTEC; INCLUDED WITH MS-DOS 6.2 AND ON AS WELL AS ALL VERSIONS.
®® Microsoft Windows 7 Windows Tutorial 2 Organizing Your Files.
 The Registry contains configuration information for Windows.  Newly installed hardware components are updated and reflected in the Registry.
FORENSICS ANALYSIS OF THE REGISTRY OF WINDOWS 7 “SYSTEM ANALYSIS” 시스템 포렌식 실습 NURHALIMATUSADIAH SYARA 시스템 포렌식 실습.
Fixing Windows 10 Automatic Updates Install Problem
/alexwaston14/fix-pc-error u/0/b/ /pages/Fix-PC- Error/
Copyright 2007, EMC Paradigm Publishing Inc. WINDOWS VISTA BACKNEXTEND 1-1 LINKS TO OBJECTIVES Starting Windows Using the Taskbar, open & switch programs.
Computer Literacy BASICS
Unit OS7: Security 7.4. Quiz Windows Operating System Internals - by David A. Solomon and Mark E. Russinovich with Andreas Polze.
Unit OSC: Interoperability
Unit OS9: Real-Time and Embedded Systems
Unit OS4: Scheduling and Dispatch
Unit OS11: Performance Evaluation
Unit OS A: Windows Networking
Unit OS8: File System 8.6. Quiz
Unit OS2: Operating System Principles
Unit OS10: Fault Tolerance
Unit OSB: Comparing the Linux and Windows Kernels
Exploring Microsoft® Access® 2016 Series Editor Mary Anne Poatsy
Unit OS5: Memory Management
How to add Loopback adapter in windows 7
Presentation transcript:

Unit OS12: Scripting Lab Manual

2 Copyright Notice © David A. Solomon and Mark Russinovich These materials are part of the Windows Operating System Internals Curriculum Development Kit, developed by David A. Solomon and Mark E. Russinovich with Andreas Polze Microsoft has licensed these materials from David Solomon Expert Seminars, Inc. for distribution to academic organizations solely for use in academic environments (and not for commercial use)

3 Roadmap for Section Lab experiments investigating: WMI Scripts WMI Classes and Objects Registry Structure and Keys Registry Hives Monitoring the Registry with Regmon

4 Lab: Using Example WMI Scripts List running processes with Resource Kit “ps.vbs” List services with “service.vbs” Extra credit: Go to the Technet Scripting Center and pick a script Copy and paste it into Notepad and save it as testscript.vbs Run the script

5 Lab: WMI Jobs Run Process Explorer and select Options|Highlight Jobs Run Psinfo.exe or wmic.exe Uses WMI to query XP/Server 2003 Product Activation Note the child of a Svchost that appears Find the service in the Svchost View the properties of the Job object in the Properties tab of the child process

6 Lab: Viewing WMI Classes Use WBEMTEST (included with Windows 2000 and higher) Connect to root\cimv2 Select Enum Classes and check Recursive Then double-click on one to view its defined properties

7 Lab: Viewing WMI Objects Double click on any class from the class list and click Instances Then double click on one to open its properties

8 Lab: Fun with the Hardware Key Open Regedit and navigate to HKLM\Hardware\Description\System\CentralPro cessor\0 Change ProcessorNameString to “Cray Supercomputer 10,000GHz” Right-click on My Computer and view Properties

9 Lab: Viewing the List of Profiles Stored on a Computer Open Regedit and navigate to HKLM\Software\Microsoft\ Windows NT\CurrentVersion\ProfileList Examine the list of profiles stored on the system Find the LOCAL_SERVICE and NETWORK_SERVICE profiles Find your own profile information View the corresponding list in Control Panel-> System->Advanced->Settings in the User Profile section

10 Lab: Registry Hives 1. Examine hivelist key (HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\hivelist ) 2. Use RUNAS to create a process under a different account than the one you are using Notice new hive loaded in Hivelist Exit the CMD & notice hive is unloaded 3. Load, examine, and unload a hive (e.g. to fix a registry key) Run REGEDT32 Select HKEY_LOCAL_MACHINE window Click on HKEY_LOCAL_MACHINE (on left pane) Click on “Registry->Load Hive” Browse to \windows\repair (saved copy of registry from date of install) Load “system” When asked for name of key, enter “testhive” Examine this new registry hive (double click and drill down) -- could make changes at this point Click on “Registry->Unload hive”

11 Regmon Lab 1. Run Notepad 2. Change Font and point size 3. Enable Word wrap 4. Run Regmon & filter to Notepad.exe 5. Exit Notepad 6. In Regmon log, find location of user-specific Notepad settings 7. Double click on a line to jump to Regedit 8. Delete top level Notepad user settings key 9. Re-run Notepad and confirm font and word wrap reset to default setting