Best Practice Procedures for Malware Removal Flashcards

1
Q

Step 1: Identify Malware Symptoms - Best Practice Procedures for Malware Removal

A
  • Odd error messages, application failures, security alerts

* System performance issues - slow boot, slow applications

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Step 2. Quarantine infected systems - Best Practice Procedures for Malware Removal

A
  • Disconnect from the network - Keep it contained
  • Isolate all removable media
  • Prevent the spread - Don’t transfer files, don’t try to backup
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Step 3. Disable System Restore - Best Practice Procedures for Malware Removal

A
  • Malware infects restore points, so a restore will reinfect the PC
  • Disable System Protection
    • No reason to save an infected config
  • Delete all restore points
    • Remove all infection locations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Step 4a. Remediate: Update antivirus - Best Practice Procedures for Malware Removal

A
  • Signature and engine updates
  • Automatic vs. manual
  • Manual updates are almost pointless
  • Your malware may prevent the update process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Step 4b. Remediate: Scan and remove - Best Practice Procedures for Malware Removal

A
  • Use a known-good anti-virus scanner
  • Consider antimalware-specific scanner such as Malwarebytes, etc.
  • The virus may have a stand-alone removal app
  • The only guaranteed removal is to delete it all and rebuild
  • May require Safe Mode or working at the Recovery Console
  • May also require repair of boot records and sectors
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Step 5. Schedule scans and run updates - Best Practice Procedures for Malware Removal

A
  • Built into the antivirus software
  • Automated signature updates and scans
  • Automate the operating system updates
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Step 6. Enable System Protection - Best Practice Procedures for Malware Removal

A
  • Now that you’re clean, put things back to normal

* Create an initial restore point as a starting point

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Step 7. Educate the end user - Best Practice Procedures for Malware Removal

A
  • One on one - Personal training
  • Posters and signs - High visibility
  • Message board posting - Physical postings in a visible area
  • Login message - These become invisible over time
  • Intranet page - Always available
How well did you know this?
1
Not at all
2
3
4
5
Perfectly