A tier-2 desktop analyst is remediating a confirmed rootkit and spyware infection on a dedicated workstation at a financial services firm. The analyst has already completed the initial identification of malware symptoms and fully isolated the workstation from the corporate network. According to CompTIA's standard malware removal procedures, which of the following actions should the analyst perform NEXT prior to running local remediation and scanning tools? (Select TWO.)
- Disable System Restore in Windows to prevent infected files from being stored in recovery snapshots.Answer
- Obtain updated anti-malware definition files from a uncompromised machine and apply them locally via removable media.Answer
- CReconnect the workstation's Ethernet interface temporarily to download the latest anti-malware signatures directly from vendor servers.
- DRe-enable System Restore and manually create a new system baseline restore point before starting the anti-malware scan.
Answer
The specialist must disable System Restore to prevent infected files from persisting in recovery points, and update anti-malware signatures locally using clean removable media while keeping the machine isolated.
Following system isolation (Step 2), the compulsory actions before running anti-malware removal tools (Step 4b) are to turn off/disable System Restore (Step 3) to prevent saving infected files into restore snapshots, and to update anti-malware signatures (Step 4a) out-of-band via clean external storage media to preserve isolation.
Step-by-Step Solution
Key Concept
CompTIA 7-Step Malware Removal Process