CompTIA A+ Core 2 (220-1202)Software TroubleshootingMedium
A technician removes a piece of malware and its files from a Windows workstation, but the malicious process reappears every time the computer is rebooted, even though real-time antivirus protection is active. Where should the technician check for the persistence mechanism causing this?
- ADisk Management
- BWindows Update history
- CTask Scheduler
- DDevice Manager
Show answer & explanationAnswer & explanation
Correct answer: C. Task Scheduler
Malware commonly creates hidden scheduled tasks in Task Scheduler to relaunch itself at startup or at intervals, surviving file deletion and standard antivirus removal. Checking and removing malicious scheduled tasks is a key step in thorough remediation.
Why the other options are wrong
- A. Disk Management manages partitions/volumes, not process persistence.
- B. Windows Update history shows patch history, unrelated to malware persistence.
- D. Device Manager manages hardware drivers, not startup persistence.
Malware Persistence via Scheduled Tasks
A technique where malware creates a Windows scheduled task to automatically relaunch itself after removal or reboot.
- Task Scheduler entries can be hidden or disguised with legitimate-sounding names
- Persistence mechanisms must be removed for successful remediation
- Other persistence spots include Registry Run keys and startup folders
Memory trick: Task Scheduler = malware's 'alarm clock' to wake back up