1.4 KiB
1.4 KiB
Lab SEC-6: Malware Removal Process Tabletop
Domain:
- 2.0 Security
Works on:
- Windows
- Tabletop/scenario practice
Goal
Practice the malware removal order without working on live malware.
Safe Windows Inspection
Run or open:
windowsdefender:
taskmgr
resmon
SystemPropertiesProtection
Optional reboot command to know, but do not run unless you are ready to restart:
shutdown /r /o /t 0
Record:
- Defender status:
- Highest CPU process:
- System Protection enabled:
- Where you would find Advanced Startup:
Process Drill
Write the 10 steps from memory:
Next-Step Scenarios
Identify the next correct step.
- User reports browser redirects and fake security alerts.
- You verify symptoms and identify likely malware.
- The infected system is still on the network.
- The system is quarantined.
- System Restore is disabled.
- Remediation is complete.
- Anti-malware is updated.
- Scan/removal fails and system trust is low.
- Known-good image is restored.
- Scheduled scans and updates are enabled.
- System Protection is re-enabled.
What You Should Learn
- Quarantine comes early.
- Disable System Restore before remediation.
- Update anti-malware before scanning/removal.
- Reimage/reinstall when cleanup cannot be trusted.
- Re-enable System Protection only after cleanup.
- User education is part of the process.