CompTIA A+ Core 2 Malware Removal Best Practices: Step-by-Step Procedures for 220-1102

CompTIA A+ Core 2 Malware Removal Best Practices: Step-by-Step Procedures for 220-1102

Introduction and the official A+ sequence

For CompTIA A+ Core 2 (220-1102), malware-removal questions are usually about workflow, not obscure tool trivia. The exam wants the official best-practice order, and it is worth memorizing exactly as CompTIA teaches it:

1. Identify and research malware symptoms
2. Quarantine infected systems
3. Disable System Restore (in Windows)
4. Remediate infected systems
5. Schedule scans and run updates
6. Enable System Restore and create a restore point
7. Educate the end user

That is the exam order.

Now, in real enterprise environments, security teams may handle things a little differently. That’s just the way it goes when you’ve got incident-response policies, endpoint management tools, and business pressure all in the mix.

That’s just the reality of working in the field — sometimes you’ve got endpoint isolation tools, incident response policies, and backup/reimage decisions that change the flow a bit. They’ll use endpoint isolation, preserve evidence, reset credentials, and sometimes go straight to rapid reimaging instead of spending a long time doing manual cleanup. That’s not me contradicting the exam — it’s just real life being real life. For the exam, though, stick to the CompTIA sequence unless the scenario clearly points to escalation or rebuild.

A simple memory aid is I-Q-D-R-U-R-E: Identify/Research, Quarantine, Disable restore, Remediate, Update, Restore, Educate. Also remember the big logic behind it: contain first, clean second, harden third.

Step 1-2: Identify and research symptoms, then quarantine

Before calling it malware, verify the signs.

The red flags I usually look for are pop-ups, browser redirects, fake update prompts, antivirus suddenly turning off, weird startup items, unusual outbound traffic, encrypted files, account lockouts, and files that just won’t open anymore. In the field, that combo usually gets my attention pretty fast.

But some of those same symptoms can come from a full disk, failing SSD, Windows Update activity, indexing, cloud file synchronization, too many startup apps, or a damaged user profile.

A good support habit is to gather a short user report:

  • What changed recently?
  • Did the user open an attachment, click a suspicious item, install software, or use a USB device?
  • When did the symptoms start?
  • Is it one application, the browser, or the whole system?
  • Are shared drives, mapped drives, or cloud-synced folders involved?

If the symptoms strongly suggest active compromise, quarantine the system quickly.

On a home or small-office PC, that usually means pulling the Ethernet cable and turning off Wi-Fi immediately. If Bluetooth is part of the connection path, I’ll usually disable that too.

If Bluetooth is part of the connection path, I’d disable that too, just to be safe.

In a managed environment, quarantine might mean host isolation through endpoint security tools, network access controls, a switch-port shutdown, or moving the machine onto a separate remediation network. The exact method depends on the shop, but the goal’s the same: stop the spread and stop the chatter.

CompTIA uses the word quarantine for infected systems, but remember that it can also refer to a security product isolating malicious files. On the exam, read carefully: host isolation and file quarantine are not the same thing.

If the user is remote, tell them to disconnect from the network immediately and stop using the device. If cloud sync is active, think about impact beyond one endpoint. A ransomware event on a synced folder can spread damage to cloud storage platforms or mapped shares quickly.

Malware symptoms vs non-malware causes

SymptomPossible malware causePossible benign causeBest first action
Slow PCCryptominer, spyware, adwareLow storage, updates, indexing, too many startup appsCheck Task Manager, disk space, and recent changes
High CPU or diskMalicious processAntivirus scan, Windows Update, cloud file syncIdentify the process before killing anything
Pop-ups and redirectsBrowser hijacker, adwareBad extension, notification abuseInspect browser settings and extensions
AV disabledMalware tamperingPolicy change, expired product, service failureQuarantine and check security service health
Files renamed/encryptedRansomwareApplication-specific file conversionIsolate immediately and escalate
Unknown startup itemsPersistenceLegitimate software update helperReview path, publisher, and purpose

Containment and escalation triggers

Some signs mean you should stop routine cleanup and escalate fast: ransom notes, widespread encryption, repeated reinfection, suspicious use of admin credentials, signs of lateral movement, impact to shared drives, suspected rootkit behavior, or possible sensitive-data exposure. A+ isn’t a forensic certification, and that really matters here. You’re not trying to reverse engineer the malware here.

The goal is to respond safely and in the right order.

You’re not trying to look busy here — you’re trying to avoid making the situation worse.

If your organization has legal, compliance, or incident-response requirements, document what you see and escalate before making extensive changes that could destroy evidence.

Also think about credentials. If malware may have stolen passwords or tokens, a “clean” endpoint may still represent account risk. That is one reason enterprise teams often prefer reimage and redeploy over extended cleanup on high-confidence compromises.

Step 3: Disable System Restore in Windows

This is one of the most tested A+ malware-removal steps. If System Protection is enabled, disable it before remediation. Why? Because restore points can contain infected system state. If you clean the machine but preserve infected restore points, the malware may return later.

Important accuracy note: on modern Windows 10 and 11 systems, System Restore is not always enabled by default, especially in managed environments. So for the exam, know the step; in the real world, first verify whether System Protection is actually on.

In Windows 10 and 11, a common path is:
Start > search for “Create a restore point” > System Properties > System Protection

From there, select the system drive, choose Configure, and turn off protection if it is enabled. Disabling protection deletes existing restore points for that drive. That is exactly why the step matters in the exam workflow. In enterprise practice, though, help desk staff may be required to follow policy before altering recovery artifacts.

Step 4: Remediate infected systems

Now you clean the system using trusted tools. Start with approved security software such as Windows Security > Virus & threat protection or your organization’s endpoint protection platform. Avoid using unapproved “PC cleaner” tools on a compromised machine.

One technical nuance matters here: operationally, anti-malware definitions or engines are often updated before or during scanning if it is safe to do so. The exam still places “run updates” after remediation, so answer exam questions with the official order, but understand the real-world nuance.

Use scan types appropriately:

  • Quick scan: fast first pass of common infection areas
  • Full scan: broader coverage when you need more confidence
  • Custom scan: useful for a suspicious folder, download location, or removable drive
  • Microsoft Defender Offline scan: best built-in option when malware is persistent or loads early in boot

Be precise about recovery tools. WinRE helps with advanced startup and troubleshooting, but it is not itself a malware scanner. Actual offline scanning requires Microsoft Defender Offline or separate rescue media from an approved vendor.

If normal cleanup fails, Safe Mode can help by loading fewer drivers and services. In Windows 10 and 11, you can reach advanced startup through Settings > System > Recovery > Advanced startup, by holding Shift while selecting Restart, or with shutdown /r /o /t 0. Use Safe Mode with Networking only if network access is required for approved tools or updates, and ideally only on an isolated remediation network, not back on production.

Persistence mechanisms technicians should recognize

A+ does not expect deep malware analysis, but you should recognize common persistence locations:

  • Task Manager > Startup for startup apps
  • Startup folders for per-user or all-users autoruns
  • Services.msc for suspicious services or odd executable paths
  • Task Scheduler (taskschd.msc) for scheduled relaunch tasks
  • Registry Run and RunOnce keys for autoruns
  • Browser extensions and browser policies for hijacking
  • WMI event subscriptions at recognition level only
  • Drivers only as an escalation clue, not a casual removal target

When reviewing entries, check the executable path, publisher, digital signature, and whether the item matches installed business software. Malware often uses random-looking names, strange paths under AppData or Temp, or scheduled tasks that relaunch the payload at logon.

If it starts looking like driver-level or rootkit persistence, that’s usually your cue to escalate.

That is beyond normal A+ support cleanup.

Browser-focused malware cleanup

Browser hijackers and adware show up constantly in support scenarios. Do more than remove one extension. Check:

  • Extensions and toolbars
  • Homepage and startup pages
  • Default search engine
  • Notification permissions
  • Proxy settings
  • Installed programs that bundled the hijacker
  • Downloads folder for the original installer

Also watch browser sync.

If the browser is syncing settings through a cloud profile, a bad extension or homepage setting can come right back after you reset everything. I’ve seen that happen more than once, and it’s frustrating if you don’t catch it early.

In those cases, review or temporarily disable sync until the profile is clean.

Commands and tools reference

Tool/CommandUseKey caution
Task ManagerReview processes, startup items, performanceHigh usage alone does not prove malware
tasklistList running processesLists processes; does not prove maliciousness
taskkill /PID <pid> /FForce-stop a processLast resort; malware may respawn via tasks, services, or watchdogs
Event ViewerCheck crashes, service failures, odd startup eventsUseful context, not a malware detector
taskschd.mscReview scheduled-task persistenceDocument before deleting tasks
Services.mscInspect services and startup typeDo not disable critical services blindly
shutdown /r /o /t 0Reboot to advanced startup and WinREGets you to recovery tools, not scanning by itself
sfc /scannowRepair protected Windows system filesNot an anti-malware command
DISM /Online /Cleanup-Image /RestoreHealthRepair Windows image component storeMay require internet or a repair source; not malware removal

When to clean, restore, reimage, or escalate

Use judgment. Clean when the infection is limited and approved tools remove it with confidence. Restore data only from known-good backups and only after containment and eradication or rebuild decisions are made. Reimage when trust in the OS is low, reinfection keeps happening, credentials may be exposed, or the endpoint is business-critical. Escalate for ransomware, rootkit suspicion, lateral movement, sensitive-data concerns, or repeated persistence.

In managed enterprises, reimage and redeploy is often preferred over long cleanup for high-confidence compromise. It is faster, more consistent, and easier to trust afterward.

Step 5-7: Schedule scans and run updates, re-enable System Restore, educate the user

After remediation, verify protection is healthy.

Check that antivirus is enabled, real-time protection is on, the firewall is active, and there aren’t any suspicious exclusions or signs that tamper protection got switched off. That’s a basic but really important sanity check.

If malware disabled security tools, re-enabling them may require admin rights or escalation.

Then perform follow-up scans and confirm updates. For exam purposes, this is the step where you schedule scans and run updates. In practice, that means confirming current signatures and definitions, applying Windows and browser patches, and updating approved applications that may have been exploited.

Once you are confident the system is clean, go back to System Protection, re-enable protection if appropriate, and create a new restore point.

That gives the user a known-good recovery point to fall back on later.

Do not create that restore point too early, or you may preserve a compromised state.

Finally, educate the user.

Keep it practical: phishing awareness, safe downloads, attachment caution, browser pop-up scams, USB hygiene, least privilege, multifactor authentication, and reporting anything suspicious quickly. That’s the kind of advice users can actually remember.

User education is not optional in the A+ workflow; it is the last step.

Post-cleanup validation checklist

  • Original symptom is gone
  • Antivirus or Defender is enabled and updated
  • Firewall is enabled
  • No suspicious startup items, services, or scheduled tasks remain
  • Browser homepage, search engine, notifications, and proxy settings are normal
  • DNS settings and outbound behavior look normal
  • Shared drives and cloud-sync folders show no further impact
  • Scheduled scans are configured
  • System Restore is re-enabled if used, and a clean restore point exists
  • User confirms normal operation

Troubleshooting failed remediation

If the malware keeps returning, use a structured path: re-check persistence points, run an offline scan, verify the browser is not re-syncing bad settings, confirm antivirus services and tamper protection are healthy, and look for suspicious tasks or services relaunching the payload. If scans fail, security tools will not re-enable, or the machine still cannot be trusted, stop spending time and move to escalation or reimage.

If the user urgently needs files from an isolated machine, do not casually reconnect it to production. Use approved recovery procedures, backup systems, or a security-controlled method.

Mini lab: browser hijacker case

Scenario: The browser opens pop-ups, the search engine changed, and redirects started after the user installed a “video codec.”

  1. Identify and research symptoms. Confirm it is browser-wide, not one site.
  2. Quarantine the endpoint if behavior is actively reaching suspicious sites.
  3. Disable System Restore if System Protection is enabled.
  4. Run Windows Security scans and remove detected items.
  5. Remove suspicious extensions, reset homepage, search, and startup pages, clear notifications, and review proxy settings.
  6. Check Task Scheduler and startup items for a relaunch mechanism.
  7. Update signatures, browser, and Windows; run a follow-up scan.
  8. Re-enable System Restore and create a restore point.
  9. Document actions and educate the user about fake installers and pop-up scams.

Common exam traps and best-next-step logic

The most common wrong answers are tempting because they sound productive:

  • “Run a full scan first” — wrong if the system should be isolated first
  • “Install updates first” — wrong if active malware is still present
  • “Use System Restore immediately” — wrong because restore points may be infected
  • “Keep the user working while scanning” — wrong because activity can spread damage
  • “Treat ransomware like adware” — wrong; isolate and escalate

Use this exam drill:

  • First action for active encryption signs: quarantine and escalate
  • Next action after limited infection is removed: schedule scans and run updates
  • Final action in the standard workflow: educate the end user

One more exam reminder: CompTIA loves the exact wording Identify and research malware symptoms. Use that phrase in your head, even if in real support work you think of it as verify, investigate, and confirm.

Conclusion

If you remember one thing for 220-1102, remember the order: Identify and research symptoms, Quarantine, Disable System Restore, Remediate, Schedule scans and run updates, Enable System Restore and create a restore point, Educate. That order helps you answer “best next step” questions and keeps real support work safer.

For the exam, follow the official workflow. For real life, use the same logic, but respect enterprise policy, evidence requirements, and the fact that some infections are better handled by escalation, restore, or reimage than by trying to clean forever. compromises are better handled by escalation or reimage than by a long cleanup effort.