A systems administrator at an automated distribution facility notices that a Windows-based picking console is periodically dropping local service responses, running unprompted background tasks, and generating unauthorized outbound connections. The administrator confirms a malware infection and immediately quarantines the console by disconnecting its Ethernet cable and turning off all wireless radios. According to CompTIA's standard 7-step malware removal procedures, which of the following actions should the administrator perform NEXT?
- Disable System Restore in Windows.Answer
- BBoot the computer into Safe Mode and run a full anti-malware scan using pre-downloaded signature updates.
- CTemporarily re-enable the network interface to download updated malware signature files from an internal repository server.
- DCreate an immediate restore point to save the current configuration in case remediation damages system files.
Answer
The administrator should disable System Restore in Windows before attempting remediation.
CompTIA's official 7-step malware remediation process specifies the following sequence: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore (in Windows), 4. Remediate infected systems (update anti-malware software / scan and use removal techniques), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate the end user. Because the technician has already identified the symptoms and isolated the system, the mandatory next step is disabling System Restore.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Remediation Best Practices