A desktop support technician is servicing a Windows workstation at a hotel reception desk that exhibits severe browser redirects, persistent pop-up advertising, and unauthorized outbound network traffic. The technician has confirmed the malware infection and physically disconnected the system's Ethernet cable to isolate it from the network. Which of the following actions should the technician perform NEXT according to standard malware removal procedures?
- Disable System Restore in Windows.Cevap
- BBoot the system into Safe Mode and run a complete anti-malware scan.
- CReconnect the network cable to update anti-malware definition files.
- DEnable System Restore and create a clean restore point.
Cevap
Disable System Restore in Windows as the immediate next step following isolation.
According to the official CompTIA 7-step malware removal process, once malware symptoms are identified (Step 1) and the system is isolated from the network (Step 2), the technician must disable System Restore (Step 3) before attempting remediation. Disabling System Restore deletes existing restore points, ensuring that infected files stored in shadow copies cannot reinfect the workstation.
Adım Adım Çözüm
Anahtar Kavram
CompTIA 7-Step Malware Remediation Procedure