220-1002 · Question #299
A technician recently removed a malware infection from a client's computer. After removing the computer from the network, the technician used an approved customized tool to remove the malware, then…
The correct answer is A. The technician did not disable the System Restore utility. Windows System Restore automatically creates restore points that capture system state, including the registry and certain files. If the malware was present when a restore point was created, that restore point contains the malware. If the technician does not disable System…
Question
A technician recently removed a malware infection from a client's computer. After removing the computer from the network, the technician used an approved customized tool to remove the malware, then updated the antivirus suite, and performed a scan that reported the system was clean. A week later, the client reports the same malware infection has returned. Which of the following is MOST likely the cause of the reinfection?
Options
- AThe technician did not disable the System Restore utility
- BThe technician ran the malware remover before the antivirus scan
- CThe technician did not install a second antivirus suite to complement the first suite
- DThe technician did not put the computer back onto the network
How the community answered
(24 responses)- A67% (16)
- B13% (3)
- C17% (4)
- D4% (1)
Explanation
Windows System Restore automatically creates restore points that capture system state, including the registry and certain files. If the malware was present when a restore point was created, that restore point contains the malware. If the technician does not disable System Restore before removing the malware, Windows can automatically or manually restore the infected state from a saved restore point, causing reinfection. Disabling System Restore before remediation - and re-enabling it after the system is clean - is a required step in the CompTIA malware removal process. The order of running tools (B) is not the cause here, a second AV suite (C) is not required, and network access (D) is unrelated to the reinfection mechanism described.
Topics
Community Discussion
No community discussion yet for this question.