Courseiva

CHFI Mobile and Malware Forensics Practice Question

During dynamic analysis of a malware sample, an analyst uses Process Monitor to monitor file system activity. The malware creates a file named 'C:\Users\Admin\AppData\Roaming\svchost.exe'. What does this likely indicate?

⚠ Common exam trap

The CHFI exam often tests the misconception that any file named 'svchost.exe' is legitimate, but the key indicator is the path — a system process should never run from a user profile directory like AppData\Roaming.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The malware is attempting to achieve persistence by placing a copy in a user directory

The creation of a file named 'svchost.exe' in the user's AppData\Roaming directory is a classic persistence technique. By placing a copy of itself with the name of a legitimate Windows system process (svchost.exe) in a user-writable location, the malware aims to execute automatically at startup (e.g., via a registry Run key or scheduled task) while evading suspicion. This is not a legitimate Windows update, as system files reside in C:\Windows\System32, not in a user profile directory.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The malware is a legitimate Windows update

    Why it's wrong here

    Legitimate Windows updates originate from Microsoft's update infrastructure and deploy signed binaries to protected system directories such as C:\Windows\System32 or C:\Windows\WinSxS, not by creating a copy of svchost.exe in a user's AppData folder. The service host process svchost.exe is a trusted system binary that never executes from a user-writable profile directory, and its absence of a valid Microsoft Authenticode signature, combined with an anomalous full path and parent process, would immediately rule out an authentic update. Therefore, this observation is a classic masquerading technique, not a legitimate OS maintenance activity.

  • ✗

    The malware is extracting an archive

    Why it's wrong here

    Archive extraction would manifest as reading compressed files (e.g., opening .zip, .rar, or .7z headers) and writing out multiple decompressed files, often preserving directory structure and timestamps, whereas this observed behavior involves only a single executable copy appearing in a user directory. There is no evidence of an archive container, no extraction tool invoked, and no corresponding write burst of multiple files, so the 'extracting' hypothesis cannot account for the singular artifact seen in dynamic analysis. The behavior is more consistent with a self-copying or drop-and-install routine.

  • ✗

    The malware is cleaning up temporary files

    Why it's wrong here

    Temporary file cleanup is a destructive and subtractive operation, driving file deletion, directory purging, and possibly volume slack wiping; creating a new file named svchost.exe in AppData is the exact opposite of clean-up activity. Dynamic analysis would show unlink() or DeleteFile calls and reduced file-system population, but instead the sample is adding persistent artifacts to the user-profile namespace. Characterizing this additive, suspicious file placement as 'cleaning up' misinterprets the direction of the file system change.

  • ✓

    The malware is attempting to achieve persistence by placing a copy in a user directory

    Why this is correct

    By copying itself to a user-writable directory such as %APPDATA% or %LOCALAPPDATA% and renaming the copy to svchost.exe, the malware is likely staging itself for persistence — for example, by registering that executable path in a Run registry key or a scheduled task for automatic execution on boot. The AppData location is routinely writable by the unprivileged user, obviating the need for administrator privileges, while the system-process name is designed to evade casual user and security-tool inspection. In the dynamic sandbox, the mere creation of that file is a strong behavioral indicator of persistence planning, especially when followed by registry or task scheduler modifications.

About these practice questions

This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.