3.3 - Recognising malware symptoms and responding

CompTIA A+ Core 2 objective 3.3 covers recognising malware symptoms and responding safely. Constant pop-ups and redirects to unknown sites usually mean adware or a browser hijacker. Pop-ups warning that the PC is 'infected' and demanding payment for a tool you never installed are rogue antivirus or scareware - and desktop alerts telling you to call a phone number are a support scam, so never call. If a user's files are renamed with a new extension and a ransom note appears, that is ransomware: isolate the device and report it rather than paying. If a browser warns that a site certificate is not trusted, verify the URL and system clock and do not enter credentials. Expect scenario questions that describe the symptom and ask for the correct, safe response.

Memory hook
Pop-ups/redirects = adware/browser hijacker. 'Infected, pay now' = scareware. Call this number = support scam (never call). Files renamed + ransom note = ransomware (isolate + report, don't pay). Untrusted cert = check URL/clock, don't log in.

Practice questions

1. Pop-ups warn the PC is 'infected' and demand payment to a tool you didn't install. This is:

  • A legitimate antivirus tool
  • Rogue antivirus / scareware (correct answer)
  • A normal Windows update
  • A device driver alert

Fake 'your PC is infected, pay now' alerts are rogue antivirus/scareware — don't pay; remove with reputable anti-malware.

2. A browser constantly opens pop-ups and redirects to unknown sites. The MOST likely cause is:

  • A failing power supply
  • Adware or a browser hijacker (correct answer)
  • Insufficient disk space
  • A dead CMOS battery

Constant pop-ups and redirects indicate adware/browser-hijacking malware. Remove rogue extensions and run anti-malware.

3. A user's important files were renamed with a new extension and a ransom note appeared. What is the FIRST response?

  • Pay the ransom quickly
  • Isolate the device and report it (correct answer)
  • Reboot the PC several times
  • Delete the encrypted files

Ransomware: disconnect/isolate to stop spread, then report and follow the incident response plan; restore from clean backups. Don't pay.

4. A browser shows a warning that a site's security certificate is not trusted. What should a user do?

  • Always just click straight through it
  • Verify the URL/clock; don't enter credentials (correct answer)
  • Turn off the host software firewall
  • Reinstall the whole operating system

Certificate warnings can mean an expired/mismatched cert, wrong system clock, or a malicious site — don't blindly proceed.

5. A user gets desktop alerts claiming malware and asking to call a phone number. What is the BEST guidance?

  • Call the number provided
  • Don't call; it's a support scam (correct answer)
  • Pay the requested fee now
  • Reinstall Windows right away

Fake malware alerts with a 'call this number' are tech-support scams — never call; remove the adware and educate the user.

6. A user can't reach internal file shares but the internet works. Many shares used to be mapped. What to check?

  • The external display monitor
  • Credentials, mapped drives, domain/DNS (correct answer)
  • The office printer's toner level
  • The connected desktop mouse

If internet works but internal shares don't, check authentication/credentials, mapped drives, VPN, and internal DNS/domain reachability.

Related objectives