An IT support specialist at a regional transit authority is troubleshooting a Windows 11 workstation used for schedule dispatching. The computer exhibits active malware symptoms, including unexpected browser pop-ups and unusual background network traffic. The technician has confirmed the presence of malware and has already disconnected the network cable and disabled Wi-Fi to isolate the system. According to standard CompTIA 7-step malware remediation procedures, which of the following steps should the technician take NEXT?
- Disable System Restore in Windows.Answer
- BBoot into Safe Mode and run a full anti-malware scan.
- CCreate a new System Restore point to save the current system state.
- DReplace the system storage drive due to suspected physical disk failure.
Answer
The technician should disable System Restore in Windows before proceeding to remediation.
According to the official CompTIA 7-step malware removal process (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore/create restore point, 7. Educate end user), the immediate step after isolating the system is to disable System Restore in Windows. This prevents Windows from taking automatic snapshots that include infected files or malware registry keys.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure