Question

Difficulty: MediumMalware Symptoms and Standard Removal Procedures

A video editing workstation at an animation studio exhibits persistent ad pop-ups, degraded rendering performance, and unexpected outbound network traffic. A desktop technician identifies and confirms a Trojan infection, then immediately disconnects the system's Ethernet cable and disables its wireless adapter to isolate it. According to the CompTIA 7-step malware removal procedure, what is the VERY NEXT action the technician should perform?

  1. Disable System Restore in Windows.Answer
  2. B
    Boot the computer into Safe Mode and run a full anti-malware scan.
  3. C
    Create a fresh restore point to save current system settings before scanning.
  4. D
    Conduct a security awareness training session for the video editor.

Answer

Disable System Restore in Windows.
The CompTIA 7-step malware removal workflow follows a specific sequential order: 1. Identify malware symptoms, 2. Isolate infected systems, 3. Disable System Restore, 4. Remediate infected systems, 5. Schedule scans and run updates, 6. Enable System Restore and create a restore point, 7. Educate the end user. Since the scenario specifies that identification (Step 1) and isolation (Step 2) have occurred, the immediate next step is to disable System Restore.

Step-by-Step Solution

1
Identify symptoms and verify infection
Malware symptoms (pop-ups, network traffic) confirmed as a Trojan infection.
Step 1 of the CompTIA 7-step process is already completed.
2
Isolate the infected system
Ethernet cable unplugged and Wi-Fi disabled.
Step 2 of the CompTIA 7-step process is already completed.
3
Disable System Restore
Existing restore points containing malicious payload copies are purged.
Step 3 must occur before scanning and remediation (Step 4) so that infected files are not preserved in system snapshots.

Key Concept

CompTIA 7-Step Malware Remediation Best Practices
Rate this question