Question

Difficulty: EasyMalware Symptoms and Standard Removal Procedures

A remote worker reports that their workstation has developed unusual file associations and unauthorized system settings modifications. A technician confirms a malware infection and immediately disconnects the device from the network to isolate it. According to the CompTIA standard malware removal procedures, which action should the technician perform NEXT?

  1. Disable System Restore in the operating systemAnswer
  2. B
    Initiate a full system scan with updated anti-malware software
  3. C
    Schedule recurring scans and OS security updates
  4. D
    Re-enable System Restore and create a clean restore point

Answer

Disable System Restore in the operating system
Disabling System Restore is Step 3 of the CompTIA 7-step malware removal procedure. Once an infected system is isolated (Step 2), System Restore must be turned off to clear existing restore points and prevent infected files from being backed up during cleanup.

Step-by-Step Solution

1
Identify the current step in the CompTIA 7-step malware removal procedure
The technician has completed Step 1 (Identify symptoms) and Step 2 (Isolate infected system).
The scenario states that the malware was verified and the laptop was disconnected from all network interfaces.
2
Determine the next sequential step in the process
Step 3 is to disable System Restore in Windows.
System Restore must be disabled before remediation to prevent malware scripts from creating or embedding within saved restore points.

Key Concept

CompTIA 7-Step Malware Removal Procedure Order
Estimated Time:1m 0s
Rate this question