An IT technician is troubleshooting a Windows workstation at a remote branch office that has been infected with browser-hijacking spyware and persistent adware. The technician has already identified the malware symptoms, disconnected the workstation from the local network, and turned off Windows System Protection (disabled System Restore). According to the CompTIA standard 7-step malware removal procedures, which of the following actions should the technician perform NEXT?
- Update the anti-malware signature files and perform a full remediation scan using targeted removal tools.Answer
- BSchedule recurring daily background scans and configure automatic operating system updates.
- CRe-enable System Protection and generate a new clean system restore point.
- DReplace the network interface card and storage drive assuming hardware failure is causing the performance degradation.
Answer
Update the anti-malware signature files and perform a full remediation scan using targeted removal tools.
CompTIA follows a strict 7-step malware removal process: (1) Identify malware symptoms, (2) Isolate infected systems, (3) Disable System Restore, (4) Remediate infected systems, (5) Schedule scans and run updates, (6) Enable System Restore and create a restore point, and (7) Educate the end user. Since the technician has already completed steps 1 through 3, the immediate next action required is Step 4: Remediating the infected system by updating anti-malware signatures and scanning/removing the threat.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure