Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

An IT technician is troubleshooting a Windows 11 workstation used on the floor of an automated logistics fulfillment center. The workstation is exhibiting unauthorized background network requests and high CPU usage caused by an unrecognized process named sys_update.exe. The technician has confirmed a malware infection and disconnected the ethernet cable to isolate the system. According to the CompTIA 7-step malware removal process, which of the following actions should the technician take NEXT?

  1. Disable System Restore in Windows.Answer
  2. B
    Update anti-malware definitions and perform a full system scan.
  3. C
    Replace the system RAM module to address the high CPU and memory utilization.
  4. D
    Re-enable System Restore and create a clean system restore point.

Answer

The technician should disable System Restore in Windows as the immediate next step.
Under the CompTIA standard 7-step malware remediation process (1. Identify symptoms, 2. Isolate system, 3. Disable System Restore, 4. Remediate infected system, 5. Schedule scans/updates, 6. Enable System Restore and create restore point, 7. Educate end user), the technician has already completed steps 1 and 2. Step 3 explicitly specifies disabling System Restore before performing scans or updates to ensure restore points are not contaminated with malware.

Step-by-Step Solution

1
Determine current progress in the 7-step malware removal process.
Step 1 (Identify malware symptoms) and Step 2 (Isolate the infected system) are complete.
Symptoms were identified and the physical network connection was severed.
2
Identify the mandatory next step prior to scanning.
Step 3 requires disabling System Restore.
Disabling System Restore prevents infected files from being archived in Windows shadow copies during malware removal.

Key Concept

CompTIA 7-Step Malware Removal Procedure
Rate this question