官术网_书友最值得收藏!

Persistence

One of the changes malware makes in the system is to make itself resident.  Malware persistence means that the malware will still be running in background and, as much as possible, all the time. For example, malware gets executed after every boot-up of the system, or malware gets executed at a certain time of the day. The most common way for malware to achieve persistence is to drop a copy of itself in some folder in the system and make an entry in the registry.

The following view of the registry editor shows a registry entry by the GlobeImposter ransomware:  

Any entries made under the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
 are expected to run every time Windows starts. In this case, the GlobeImposter ransomware's executable file stored in C:\Users\JuanIsip\AppData\Roaming\huVyja.exe becomes persistent.   BrowserUpdateCheck is the registry value, while the path is the registry data. What matters under this registry key are the paths, regardless of the registry value name.

There are several areas in the registry that can trigger the execution of a malware executable file. 

主站蜘蛛池模板: 永泰县| 松原市| 上杭县| 习水县| 临高县| 洪洞县| 贡嘎县| 和林格尔县| 卢龙县| 泽库县| 应用必备| 谷城县| 庄浪县| 库伦旗| 耿马| 都江堰市| 东港市| 万安县| 巩义市| 安达市| 鸡东县| 祥云县| 五常市| 淄博市| 扎赉特旗| 女性| 罗山县| 南宫市| 浦县| 平果县| 巢湖市| 米脂县| 衡山县| 永泰县| 连山| 桃江县| 厦门市| 大姚县| 竹溪县| 通州区| 陕西省|