CHFI Mobile and Malware Forensics Practice Question
During dynamic analysis of a malware sample, an analyst uses Process Monitor to monitor file system activity. The malware creates a file named 'C:\Users\Admin\AppData\Roaming\svchost.exe'. What does this likely indicate?
⚠ Common exam trap
The CHFI exam often tests the misconception that any file named 'svchost.exe' is legitimate, but the key indicator is the path — a system process should never run from a user profile directory like AppData\Roaming.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The malware is attempting to achieve persistence by placing a copy in a user directory
The creation of a file named 'svchost.exe' in the user's AppData\Roaming directory is a classic persistence technique. By placing a copy of itself with the name of a legitimate Windows system process (svchost.exe) in a user-writable location, the malware aims to execute automatically at startup (e.g., via a registry Run key or scheduled task) while evading suspicion. This is not a legitimate Windows update, as system files reside in C:\Windows\System32, not in a user profile directory.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The malware is a legitimate Windows update
Why it's wrong here
Legitimate Windows updates originate from Microsoft's update infrastructure and deploy signed binaries to protected system directories such as C:\Windows\System32 or C:\Windows\WinSxS, not by creating a copy of svchost.exe in a user's AppData folder. The service host process svchost.exe is a trusted system binary that never executes from a user-writable profile directory, and its absence of a valid Microsoft Authenticode signature, combined with an anomalous full path and parent process, would immediately rule out an authentic update. Therefore, this observation is a classic masquerading technique, not a legitimate OS maintenance activity.
- ✗
The malware is extracting an archive
Why it's wrong here
Archive extraction would manifest as reading compressed files (e.g., opening .zip, .rar, or .7z headers) and writing out multiple decompressed files, often preserving directory structure and timestamps, whereas this observed behavior involves only a single executable copy appearing in a user directory. There is no evidence of an archive container, no extraction tool invoked, and no corresponding write burst of multiple files, so the 'extracting' hypothesis cannot account for the singular artifact seen in dynamic analysis. The behavior is more consistent with a self-copying or drop-and-install routine.
- ✗
The malware is cleaning up temporary files
Why it's wrong here
Temporary file cleanup is a destructive and subtractive operation, driving file deletion, directory purging, and possibly volume slack wiping; creating a new file named svchost.exe in AppData is the exact opposite of clean-up activity. Dynamic analysis would show unlink() or DeleteFile calls and reduced file-system population, but instead the sample is adding persistent artifacts to the user-profile namespace. Characterizing this additive, suspicious file placement as 'cleaning up' misinterprets the direction of the file system change.
- ✓
The malware is attempting to achieve persistence by placing a copy in a user directory
Why this is correct
By copying itself to a user-writable directory such as %APPDATA% or %LOCALAPPDATA% and renaming the copy to svchost.exe, the malware is likely staging itself for persistence — for example, by registering that executable path in a Run registry key or a scheduled task for automatic execution on boot. The AppData location is routinely writable by the unprivileged user, obviating the need for administrator privileges, while the system-process name is designed to evade casual user and security-tool inspection. In the dynamic sandbox, the mere creation of that file is a strong behavioral indicator of persistence planning, especially when followed by registry or task scheduler modifications.
Go deeper
Related to this question
About these practice questions
This CHFI question is part of Courseiva's 745-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CHFI practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CHFI exam.