| Malware Identification Decision Tree |
| 1. Suspect Worm |
![]() | 1.1. Manual Analysis and Remediation Steps |
![]() | 1.2. Wipe/Restore Machine |
![]() | 1.3. Widespread? |
![]() | 1.4. Post-op Prevent Recurrence Policy |
| 2. Suspect Advanced Persistent Threat |
| 3. Incident Response Phases |
| 4. Suspect Virus |
| 5. Suspect Trojan |
| 6. Symantec Specific Analysis Steps |
| 7. Information References |