CompTIA A+ Core 2 (220-1202)Software TroubleshootingHard
A technician suspects a rootkit infection on a Windows workstation because standard antivirus scans repeatedly report the system as clean, yet suspicious network traffic continues. What is the BEST approach to remove the infection?
- ATemporarily disable the Windows firewall
- BRestore the last System Restore point
- CBoot the system using antivirus rescue media from a USB drive
- DRun Windows Defender Full Scan again in normal mode
Show answer & explanationAnswer & explanation
Correct answer: C. Boot the system using antivirus rescue media from a USB drive
Rootkits operate at the kernel level and can hide themselves from antivirus software running within the infected OS. Booting from external rescue media allows the scan to run outside the compromised OS, exposing and removing the hidden rootkit.
Why the other options are wrong
- A. Disabling the firewall increases risk and does nothing to remove a hidden rootkit.
- B. System Restore does not remove rootkits and may not even affect files outside the OS's visibility.
- D. Repeating the same scan in the same infected OS will yield the same false-clean result.
Rootkit Removal via Rescue Media
Rootkits hide from OS-level antivirus scans by operating at the kernel level; removal requires booting from external rescue media to scan the system offline.
- Rootkits evade in-OS antivirus detection
- Bootable rescue/USB antivirus media scans outside the OS
- Standard scans repeatedly reporting 'clean' is a red flag for rootkits
Memory trick: Rootkit roots deep underground — dig it out with rescue media from outside