An IT technician at a regional freight forwarding logistics hub is troubleshooting a Windows 10 workstation that generates unprompted outbound network connections and displays rogue browser redirects. The technician has already disconnected the Ethernet cable to isolate the system from the network. According to standard CompTIA malware removal procedures, which of the following actions should the technician perform NEXT?
- Disable System Restore on the workstation.Answer
- BInstall the latest anti-malware definition updates using offline media.
- CCreate a new restore point to save current system configuration settings.
- DReplace the network interface card to fix the network anomaly.
Answer
The technician should disable System Restore on the workstation.
According to CompTIA's official 7-step malware remediation process, the proper sequence is: 1. Identify symptoms, 2. Isolate the infected system, 3. Disable System Restore, 4. Remediate infected systems (update anti-malware software, scan and use removal techniques), 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, and 7. Educate the end user. Since the technician has already identified symptoms and isolated the machine from the network, the immediate next action required is disabling System Restore to ensure infected files are not backed up or preserved.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure