A desktop support specialist is servicing a dedicated CAD engineering workstation in a manufacturing plant. The machine was disconnected from the network immediately after exhibiting severe performance degradation and launching unauthorized processes. The technician has confirmed the presence of active malware and successfully disabled System Restore. According to standard CompTIA malware removal procedures, which of the following actions should the technician perform NEXT?
- Update the antimalware definition files using a verified external medium, then perform a comprehensive system scan.Answer
- BReconnect the ethernet cable briefly to allow the installed antimalware software to pull the latest definitions directly from the vendor cloud.
- CEnable System Restore and create an immediate restore point to preserve system state before initiating file deletion.
- DExecute the sfc /scannow command from an elevated prompt to replace corrupted system binaries prior to scanning for virus signatures.
Answer
Update the antimalware definition files using a verified external medium, then perform a comprehensive system scan.
Following the CompTIA 7-step malware remediation process (Identify, Isolate, Disable System Restore, Remediate, Schedule scans/updates, Enable System Restore/Create restore point, Educate user), after disabling System Restore, the technician enters the Remediate phase. This requires updating the antimalware software and definitions—using clean offline media since the machine is network-isolated—and executing thorough scans to remove the threat.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure - Remediation Phase