Best Practice Procedures for Malware Removal Flashcards
Step 1: Identify Malware Symptoms - Best Practice Procedures for Malware Removal
- Odd error messages, application failures, security alerts
* System performance issues - slow boot, slow applications
Step 2. Quarantine infected systems - Best Practice Procedures for Malware Removal
- Disconnect from the network - Keep it contained
- Isolate all removable media
- Prevent the spread - Don’t transfer files, don’t try to backup
Step 3. Disable System Restore - Best Practice Procedures for Malware Removal
- Malware infects restore points, so a restore will reinfect the PC
- Disable System Protection
- No reason to save an infected config
- Delete all restore points
- Remove all infection locations
Step 4a. Remediate: Update antivirus - Best Practice Procedures for Malware Removal
- Signature and engine updates
- Automatic vs. manual
- Manual updates are almost pointless
- Your malware may prevent the update process
Step 4b. Remediate: Scan and remove - Best Practice Procedures for Malware Removal
- Use a known-good anti-virus scanner
- Consider antimalware-specific scanner such as Malwarebytes, etc.
- The virus may have a stand-alone removal app
- The only guaranteed removal is to delete it all and rebuild
- May require Safe Mode or working at the Recovery Console
- May also require repair of boot records and sectors
Step 5. Schedule scans and run updates - Best Practice Procedures for Malware Removal
- Built into the antivirus software
- Automated signature updates and scans
- Automate the operating system updates
Step 6. Enable System Protection - Best Practice Procedures for Malware Removal
- Now that you’re clean, put things back to normal
* Create an initial restore point as a starting point
Step 7. Educate the end user - Best Practice Procedures for Malware Removal
- One on one - Personal training
- Posters and signs - High visibility
- Message board posting - Physical postings in a visible area
- Login message - These become invisible over time
- Intranet page - Always available