An IT support technician is assisting a financial analyst whose Windows 11 laptop displays multiple unexpected pop-up notifications claiming the system is compromised, alongside severe performance degradation. The technician has confirmed the symptoms, disconnected all physical network cables, and disabled the Wi-Fi card to quarantine the infected host from the enterprise network. According to standard CompTIA malware removal procedures, which action should the technician perform NEXT?
- Disable System Protection and delete existing restore points on the infected system.Answer
- BConnect an external storage drive to perform an immediate full system backup before scanning.
- CRun an anti-malware definition update and execute a full background scan.
- DConduct end-user training on identifying phishing vectors and suspicious browser pop-ups.
Answer
Disable System Protection and delete existing restore points on the infected system.
According to the official CompTIA 7-step malware removal process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate end user), the immediate next step after isolating the system is to disable System Restore/System Protection. This prevents Windows from saving copies of malware into restore points during remediation.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Process