CHFI Mobile and Malware Forensics Practice Question
A security analyst detects that a known malware sample writes to the registry key 'HKLM\SYSTEM\CurrentControlSet\Services\<malware>\ImagePath' and creates a service. This behavior is characteristic of which type of persistence mechanism?
⚠ Common exam trap
The CHFI exam often tests the distinction between registry-based persistence mechanisms; the trap here is that candidates confuse the 'Services' registry key with other common persistence locations like 'Run' keys or 'AppInit_DLLs', but the specific 'ImagePath' value under a service subkey uniquely identifies Windows service persistence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Windows service
The malware writes to 'HKLM\SYSTEM\CurrentControlSet\Services\<malware>\ImagePath' and creates a service, which is the exact mechanism for registering a Windows service. This persistence method ensures the malware runs automatically when the system boots, as the Service Control Manager (SCM) loads services based on this registry key. Option D is correct because this behavior directly corresponds to the Windows service persistence technique.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scheduled task
Why it's wrong here
A scheduled task is a separate persistence mechanism managed by the Task Scheduler service, with its configuration stored in the Task Scheduler database (e.g., C:\Windows\System32\Tasks or via schtasks /create), not in the Services registry key. The detected path under HKLM\SYSTEM\CurrentControlSet\Services is specifically the database for Windows services, which are loaded and started by the Service Control Manager. While both can provide auto-execution, the registry evidence points to a service registration, not a scheduled task.
- ✗
AppInit_DLLs
Why it's wrong here
AppInit_DLLs is a registry value located under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, and it forces every loaded user-mode DLL to inject designated DLLs into processes via the user32.dll initialization path. This is a DLL hijacking/injection persistence method, not a service definition. It does not involve the Services registry key, which holds a service's ImagePath, Start type, and other parameters for the Service Control Manager. The presence of a subkey under Services indicates a true service, not an AppInit_DLLs mechanism.
- ✗
Startup folder entry
Why it's wrong here
A startup folder entry is a file or shortcut placed in a user's profile directories such as C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp or the per-user shell:startup folder, and it executes only when that user logs into the interactive desktop. In contrast, the Services registry key defines system-level services that are launched by the Service Control Manager at boot time, independent of any user logon. Detecting a registry path under Services is therefore inconsistent with a startup folder persistence technique, which would be visible as a file system artifact, not a service key.
- ✓
Windows service
Why this is correct
The registry key HKLM\SYSTEM\CurrentControlSet\Services\<malware> is the canonical storage location for a Windows service definition, including the ImagePath to the executable, the Start value (e.g., 2 for AUTO_START), and the service Type. The Service Control Manager (SCM) enumerates these keys at system boot and launches the service according to its Start value, typically with SYSTEM privileges. This gives malware a reliable, auto-starting, system-level persistence mechanism that survives reboots and runs even before any user logs in. Therefore, the evidence strongly indicates the malware was installed as a Windows service.
Go deeper
Related to this question
About these practice questions
One of 745 original CHFI practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.