Which step in the best practice procedure for malware removal is performed specifically to prevent malware from using saved recovery states to reinfect a device?
System Restore should be disabled in Windows during the malware removal process to mitigate the chance that the malware infects the system's restore points. If a restore point is infected, the system can be reinfected when that restore point is used.
The CompTIA Malware Removal Steps are:
Investigate and verify malware symptoms
Quarantine infected systems
Disable System Restore in Windows
Remediate infected systems
Schedule scans and run updates
Enable System Restore and create a restore point in Windows
Educate the end user
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is it important to disable System Restore during malware removal?
Open an interactive chat with Bash
What does the term 'Quarantine infected systems' mean in the context of malware removal?
Open an interactive chat with Bash
Can you explain what the other steps in the CompTIA Malware Removal Steps involve?