Courseiva

CHFI Mobile and Malware Forensics Practice Question

An analyst runs 'regshot' before and after executing a suspicious binary. The report shows that the binary added a value to HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to C:\Windows\system32\malware.exe and 'Start' set to 2. What is the MOST likely purpose?

⚠ Common exam trap

EC-Council often tests the distinction between creating a new service for persistence versus modifying an existing service's startup type or disabling it, and candidates may confuse the 'Start' value of 2 (auto-start) with a disabled state (value 4).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Persistence as a service

The binary added a service entry under HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to malware.exe and 'Start' set to 2 (SERVICE_AUTO_START). This ensures the malware launches automatically at system boot, which is a classic persistence mechanism. The 'Start' value of 2 specifically configures the service to start automatically, making it persist across reboots.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hiding network connections

    Why it's wrong here

    Hiding network connections would involve runtime API hooking or rootkit techniques that intercept network queries, leaving no trace in a registry comparison. Regshot specifically snapshots the registry and filesystem state before and after execution, not network sockets or live network activity. Since the observed change is a newly created service key with Start=2, there are no network-related registry modifications such as Winsock catalog changes or firewall rule additions. Therefore, this option does not match the evidence.

  • ✗

    Encrypting files

    Why it's wrong here

    Encrypting files typically modifies file contents and appends extensions, but such behavior does not require altering the registry. The only registry change detected is the creation of a service entry designed to execute at boot; there are no encryption-related keys such as a cryptor's startup command or file association changes. Ransomware often adds a registry run key to repeat encryption, but here the service configuration points to a binary that persists, not to a file-encrypting routine. Thus, the evidence points to persistence, not data destruction.

  • ✗

    Disabling a legitimate service

    Why it's wrong here

    Disabling a legitimate service would be evidenced by modifying the Start value of an existing service key to 4 (disabled) or changing its ImagePath to a broken value. In this case, the registry comparison reveals a new service key, not an alteration to an existing one, and the Start value is set to 2, indicating automatic startup rather than disabled. There is also no corresponding deletion of the service's original configuration or dependency modifications. The creation of a new auto-start service is fundamentally different from disabling a pre-existing service.

  • ✓

    Persistence as a service

    Why this is correct

    The Start value of 2 (SERVICE_AUTO_START) in a newly created service registry key instructs the Service Control Manager to launch the service automatically during system startup, before a user logs on. This is a well-known persistence technique because the malicious binary is executed with SYSTEM privileges on every boot, surviving reboots. The presence of this service key, with its image path pointing to the suspect executable, is direct evidence that the malware has installed a persistent service. This matches the observed change exactly and explains why the analyst sees a new service entry rather than a modification to an existing one.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.