================================================================================ PRAVEENTECHWORLD MALWARE BENCHMARK & RECOVERY CHEATSHEET (2026 EDITION) Empirical Sandbox Results: 10 Malware Types vs. 3 Windows Recovery Methods ================================================================================ 1. SEARCHGOO ADWARE: - Keep My Files: SURVIVED (Preserved in AppData\Local\Google\Chrome\User Data) - Remove Everything: DESTROYED - Clean USB Format: DESTROYED 2. AGENTTESLA KEYLOGGER: - Keep My Files: SURVIVED (Startup Run key intact) - Remove Everything: DESTROYED - Clean USB Format: DESTROYED 3. LOCKBIT 3.0 RANSOMWARE: - Keep My Files: SURVIVED (Encrypted headers preserved) - Remove Everything: DESTROYED - Clean USB Format: DESTROYED 4. XMRIG CRYPTO MINER: - Keep My Files: DESTROYED (Scheduled Task wiped) - Remove Everything: DESTROYED - Clean USB Format: DESTROYED 5. REDLINE STEALER: - Keep My Files: SURVIVED (AppData token stealer payload preserved) - Remove Everything: DESTROYED - Clean USB Format: DESTROYED 6. ASYNCRAT TROJAN: - Keep My Files: DESTROYED (WMI persistence purged) - Remove Everything: DESTROYED - Clean USB Format: DESTROYED 7. COBALT STRIKE BEACON: - Keep My Files: DESTROYED (System DLL replacement overwritten) - Remove Everything: DESTROYED - Clean USB Format: DESTROYED 8. KILLDISK MBR ROOTKIT: - Keep My Files: SURVIVED (MBR table remains altered) - Remove Everything: PARTIAL (Partition wipe does not clean MBR block) - Clean USB Format: DESTROYED (Bootsect /fixmbr + diskpart clean) 9. HERMETICWIPER: - Keep My Files: SURVIVED (GPT headers corrupted) - Remove Everything: PARTIAL - Clean USB Format: DESTROYED 10. MOONBOUNCE UEFI SPI BOOTKIT: - Keep My Files: SURVIVED (Flash chip payload persists) - Remove Everything: SURVIVED - Clean USB Format: SURVIVED (Requires motherboard SPI hardware reflash) Published by PraveenTechWorld Engineering (https://www.praveentechworld.com)