CHFI OS and Network Forensics Practice Question
A Windows system has been compromised. The analyst finds a registry run key at HKCU\Software\Microsoft\Windows\CurrentVersion\Run with value name 'UpdateService' pointing to C:\Users\Public\svchost.exe. Why is this particularly suspicious?
⚠ Common exam trap
In CHFI exams, a common trap is the misconception that any svchost.exe outside System32 is automatically malicious, but the real forensic indicator is the path anomaly. Candidates may overlook this and focus on the generic name or the fact that Run keys are for programs, not services, missing the core indicator of process masquerading.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The path is not typical for svchost.exe, which resides in System32
The legitimate svchost.exe is a critical Windows system binary located in C:\Windows\System32. An executable named svchost.exe running from C:\Users\Public\ is a classic masquerading technique used by malware to evade detection by mimicking a trusted process name while residing in a user-writable, non-standard directory. This path deviation is the primary red flag because system processes should never execute from user profile or public folders.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The path is not typical for svchost.exe, which resides in System32
Why this is correct
Svchost.exe is a critical Windows service host process that must reside in C:\Windows\System32 (or SysWOW64 on 64-bit systems for 32-bit services). A legitimate svchost.exe never runs from a user profile directory, such as C:\Users\<username>\AppData\Roaming, because that would violate Windows binary protection and signature requirements. The unexpected path alone is a strong indicator of malware, as attackers often name rogue executables svchost.exe to blend in with legitimate processes while locating them in writable, non-standard folders.
- ✗
Run keys are only for startup programs, not services
Why it's wrong here
This statement mischaracterizes the purpose of Run registry keys. While Run keys are commonly used to launch applications at logon, they are not restricted to startup programs—they can be used to start any executable, including a malicious one that mimics a service. In this scenario, the presence of a Run key that launches an exe is entirely consistent with persistence via the registry; the real anomaly is the executable's location, not the key's type.
- ✗
The run key is disabled in Windows 10
Why it's wrong here
Run keys, specifically HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run and HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run, remain fully functional in Windows 10 and Windows 11. They are a widely abused persistence mechanism and are not disabled by default, nor does Windows 10 deprecate them. Therefore, a run key entry is not inherently benign or inert, and an executable launched from such a key must be scrutinized.
- ✗
The registry value name 'UpdateService' is too generic
Why it's wrong here
While malware authors often use generic or service-like names such as 'UpdateService' to evade suspicion, the choice of value name is not a technical flaw. Registry value names are arbitrary strings and do not affect execution; the operating system simply reads the command line associated with the value. The stronger forensic indicator is the executable's path, which deviates from the legitimate svchost.exe location, making the path-based evidence more probative than the value name.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CHFI question from scratch — 745 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.