CompTIA A+

The malware removal steps

Core 2 asks for these steps in order, or for the step that comes next. The two System Restore steps are the ones people mix up.

Where it is testedCore 2 (220-1202), Security, objective 2.6
StepsSeven, with three parts inside remediation

The steps

StepWhy
1. Investigate and verify malware symptomsMake sure it really is malware
2. Quarantine the infected systemStop it spreading or sending data
3. Disable System Restore in WindowsOld restore points may hold the malware
4. Remediate: update anti-malware, scan and remove (safe mode or a preinstallation environment), or reimageClean the system
5. Schedule scans and run updatesKeep it clean
6. Enable System Restore and create a restore pointSave the clean state
7. Educate the end userStop it happening again

When removal does not work

  • Scan from Safe Mode or a preinstallation environment: some malware hides from tools running inside normal Windows.
  • If the malware keeps coming back, reimage or reinstall and restore only scanned data. Both are part of remediation in the objectives.

Try 3 questions

Question 1Core 2 · 2.0

A user says pop-ups appear and his browser home page keeps changing. Following the CompTIA malware removal steps, what should the technician do first?

Question 2Core 2 · 2.0

A technician has confirmed malware on a desktop in an office. What is the next step?

Question 3Core 2 · 2.0

Why does the CompTIA malware removal procedure disable System Restore in Windows before remediation?

Next step

Questions people ask

Why disable System Restore before removing malware?

Restore points can contain the malware, so a later restore could bring it back. It is turned on again once the PC is clean.

What is the last malware removal step?

Educate the end user.

When do you quarantine?

Right after confirming the symptoms are malware, before cleaning.