CHFI Mobile and Malware Forensics Practice Question
An analyst runs 'regshot' before and after executing a suspicious binary. The report shows that the binary added a value to HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to C:\Windows\system32\malware.exe and 'Start' set to 2. What is the MOST likely purpose?
⚠ Common exam trap
EC-Council often tests the distinction between creating a new service for persistence versus modifying an existing service's startup type or disabling it, and candidates may confuse the 'Start' value of 2 (auto-start) with a disabled state (value 4).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Persistence as a service
The binary added a service entry under HKLM\SYSTEM\CurrentControlSet\Services\MyService with 'ImagePath' pointing to malware.exe and 'Start' set to 2 (SERVICE_AUTO_START). This ensures the malware launches automatically at system boot, which is a classic persistence mechanism. The 'Start' value of 2 specifically configures the service to start automatically, making it persist across reboots.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hiding network connections
Why it's wrong here
Hiding network connections would involve runtime API hooking or rootkit techniques that intercept network queries, leaving no trace in a registry comparison. Regshot specifically snapshots the registry and filesystem state before and after execution, not network sockets or live network activity. Since the observed change is a newly created service key with Start=2, there are no network-related registry modifications such as Winsock catalog changes or firewall rule additions. Therefore, this option does not match the evidence.
- ✗
Encrypting files
Why it's wrong here
Encrypting files typically modifies file contents and appends extensions, but such behavior does not require altering the registry. The only registry change detected is the creation of a service entry designed to execute at boot; there are no encryption-related keys such as a cryptor's startup command or file association changes. Ransomware often adds a registry run key to repeat encryption, but here the service configuration points to a binary that persists, not to a file-encrypting routine. Thus, the evidence points to persistence, not data destruction.
- ✗
Disabling a legitimate service
Why it's wrong here
Disabling a legitimate service would be evidenced by modifying the Start value of an existing service key to 4 (disabled) or changing its ImagePath to a broken value. In this case, the registry comparison reveals a new service key, not an alteration to an existing one, and the Start value is set to 2, indicating automatic startup rather than disabled. There is also no corresponding deletion of the service's original configuration or dependency modifications. The creation of a new auto-start service is fundamentally different from disabling a pre-existing service.
- ✓
Persistence as a service
Why this is correct
The Start value of 2 (SERVICE_AUTO_START) in a newly created service registry key instructs the Service Control Manager to launch the service automatically during system startup, before a user logs on. This is a well-known persistence technique because the malicious binary is executed with SYSTEM privileges on every boot, surviving reboots. The presence of this service key, with its image path pointing to the suspect executable, is direct evidence that the malware has installed a persistent service. This matches the observed change exactly and explains why the analyst sees a new service entry rather than a modification to an existing one.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.