MALWARE INCIDENT AND RECOVERY RECORD Instructions: Record observations and actions without opening more suspicious content. Keep the completed record private; exclude passwords/recovery codes. For a work device, suspected ransomware, sensitive-data exposure or multiple affected machines, contact the designated responder before cleanup or erasure. Date/time/time zone first observed: ____________________ Device and owner (private inventory reference): ____________________ What was seen? Exact alert/detection/file name if visible: __________________ Recent downloads, sign-ins or changes: ____________________ Affected accounts, shared storage or other devices: ____________________ Evidence reference (photo/log location, access restricted): __________________ CONTAINMENT AND CONTACT Network isolation action and time, if needed: ____________________ Responder contacted from trusted device / time: ____________________ Instructions received and responsible person: ____________________ Avoid attaching backup drives to a potentially infected system. Avoid cleanup/deletion that could destroy business-incident evidence. ACTION LOG — repeat as needed Time | person | action | result | evidence reference ____________________________________________________________ ____________________________________________________________ ____________________________________________________________ PERSONAL-DEVICE INVESTIGATION, IF APPROPRIATE Operating system / active security provider: ____________________ Update and security intelligence status: ____________________ Scan type / time / result / blocked, quarantined or allowed: _________________ Recurring detection or unresolved symptom: ____________________ For Defender Offline, save work before the restart and have any necessary device-recovery information available. macOS uses a different workflow. RECOVERY VERIFICATION [ ] Responder cleared cleanup/rebuild and evidence requirements, if applicable. [ ] Trusted system established using supported remediation/reinstallation. [ ] Exposed accounts secured from a trusted device; sessions and recovery reviewed. [ ] Suitable backup point chosen; sample files opened and checked. [ ] Applications restored from trusted sources; suspect installer excluded. [ ] Updates and protection active; remaining alerts reviewed. [ ] Entry point addressed; recurrence monitoring and owner assigned. Outstanding issue / owner / next action: ____________________ Return-to-use decision / approver / date: ____________________ Source context: CISA ransomware response and official OS guidance in the guide. A clean scan does not prove that previously exposed credentials stayed secret. https://www.cisa.gov/stopransomware/ransomware-guide Yenra | Updated September 9, 2026 Guide: https://yenra.com/computer-virus/