An IT technician is troubleshooting a Windows 11 workstation used on the floor of an automated logistics fulfillment center. The workstation is exhibiting unauthorized background network requests and high CPU usage caused by an unrecognized process named sys_update.exe. The technician has confirmed a malware infection and disconnected the ethernet cable to isolate the system. According to the CompTIA 7-step malware removal process, which of the following actions should the technician take NEXT?
- Disable System Restore in Windows.Answer
- BUpdate anti-malware definitions and perform a full system scan.
- CReplace the system RAM module to address the high CPU and memory utilization.
- DRe-enable System Restore and create a clean system restore point.
Answer
The technician should disable System Restore in Windows as the immediate next step.
Under the CompTIA standard 7-step malware remediation process (1. Identify symptoms, 2. Isolate system, 3. Disable System Restore, 4. Remediate infected system, 5. Schedule scans/updates, 6. Enable System Restore and create restore point, 7. Educate end user), the technician has already completed steps 1 and 2. Step 3 explicitly specifies disabling System Restore before performing scans or updates to ensure restore points are not contaminated with malware.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Procedure