CHFI Mobile and Malware Forensics Practice Question
A security analyst suspects malware infection on a Windows workstation. They run Process Monitor and observe that a process named 'svch0st.exe' creates a mutex named 'Global\Mutex_1234' and writes to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run'. Which malware persistence mechanism is being used?
⚠ Common exam trap
EC-Council often tests the distinction between user-level persistence (HKCU Run key) and system-level persistence (HKLM Run key or service installation), and candidates may confuse the 'Run' key with scheduled tasks or services because all three can launch executables at startup.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run key persistence
The process 'svch0st.exe' writes to the registry key 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run', which is a classic Run key used for automatic program execution at user logon. This is the most common malware persistence mechanism, as any executable referenced there will start each time the user logs in. The creation of a mutex named 'Global\Mutex_1234' is a common anti-reinfection technique to ensure only one instance of the malware runs, but the persistence is established via the Run key.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scheduled task creation
Why it's wrong here
Scheduled task creation is a separate persistence technique that relies on the Task Scheduler service and stores job definitions in %SystemRoot%\System32\Tasks (or the Task Scheduler database) rather than in the Windows Run registry keys. Unlike Run key entries, which simply enumerate commands to execute at user logon, scheduled tasks include triggers, time-based conditions, and specific user contexts that are managed through schtasks.exe or the Task Scheduler API. Therefore, an analyst observing a value in a Run key should attribute it to autorun/startup persistence, not scheduled task creation, which would require inspecting scheduled tasks for persistent malicious payloads.
- ✗
Service installation
Why it's wrong here
Service installation is implemented by creating a service record under HKLM\SYSTEM\CurrentControlSet\Services with an ImagePath value pointing to the executable and a Start value controlling whether it loads at boot or manually. Services are managed by the Service Control Manager and can run in the session 0 context, often with SYSTEM privileges, which is fundamentally different from the user-space logon notification provided by the Run registry key. Because the Run key contains simple command strings executed at logon, it is not a service registration, and a malicious service would leave its own distinct registry footprint in the Services branch.
- ✗
DLL search order hijacking
Why it's wrong here
DLL search order hijacking involves subverting the order in which Windows loads required DLLs, for instance by placing a malicious DLL in a directory that is searched before the legitimate one, often using techniques like .local files or changing the PATH. This attack does not modify the Run registry key at all; instead it influences application loading behavior when the application itself is launched, whereas the Run key launches an arbitrary executable or command directly at logon. Thus a Run key entry points to a direct execution persistence, not a DLL injection or replacement through search order tampering.
- ✓
Run key persistence
Why this is correct
Run key persistence is an established autostart extensibility point where malware creates a value in the HKCU or HKLM Run key so that the associated program executes automatically at user logon. Both HKCU\Software\Microsoft\Windows\CurrentVersion\Run and HKLM\Software\Microsoft\Windows\CurrentVersion\Run are commonly monitored, but malware often abuses them because they are simple and reliable, often without requiring elevated privileges for the HKCU variant. From an analyst's perspective, finding an unexpected value in these keys is a strong indicator of persistence, and the command or path of the value can be used for further triage.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.