Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

A technician is troubleshooting a dedicated digital signage player in a public transit station. The system exhibits rogue security notifications and high CPU utilization. The technician has confirmed the presence of malware and has unplugged the network cable to isolate the system. According to the CompTIA standard 7-step malware removal procedure, which of the following actions should the technician perform NEXT?

  1. Disable System Restore in Windows.Answer
  2. B
    Update the anti-malware signatures and perform a full system scan.
  3. C
    Create an immediate fresh restore point and schedule automatic daily scans.
  4. D
    Replace the system's network interface card.

Answer

Disabling System Restore in Windows is the correct next step after isolating the infected machine.
Following the CompTIA standard 7-step malware removal procedure (1. Identify, 2. Isolate, 3. Disable System Restore, 4. Remediate, 5. Schedule scans/updates, 6. Enable System Restore, 7. Educate end user), the technician has already completed steps 1 and 2. The immediate next action required before remediation is to disable System Restore to prevent Windows from caching infected system files.

Step-by-Step Solution

1
Identify malware symptoms
Confirmed malware infection (rogue notifications and abnormal system behavior).
Establishes the initial problem context.
2
Isolate the infected system
Physical network cable unplugged.
Prevents the malware from spreading across the local network.
3
Disable System Restore
System Protection is turned off, preventing infected restore points from being created or preserved.
Ensures that malicious binaries are not saved in restore points or automatically restored during system recovery.

Key Concept

CompTIA 7-step malware removal process order
Rate this question