官术网_书友最值得收藏!

Persistence

One of the changes malware makes in the system is to make itself resident.  Malware persistence means that the malware will still be running in background and, as much as possible, all the time. For example, malware gets executed after every boot-up of the system, or malware gets executed at a certain time of the day. The most common way for malware to achieve persistence is to drop a copy of itself in some folder in the system and make an entry in the registry.

The following view of the registry editor shows a registry entry by the GlobeImposter ransomware:  

Any entries made under the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Run
 are expected to run every time Windows starts. In this case, the GlobeImposter ransomware's executable file stored in C:\Users\JuanIsip\AppData\Roaming\huVyja.exe becomes persistent.   BrowserUpdateCheck is the registry value, while the path is the registry data. What matters under this registry key are the paths, regardless of the registry value name.

There are several areas in the registry that can trigger the execution of a malware executable file. 

主站蜘蛛池模板: 三亚市| 鄂伦春自治旗| 石城县| 扬州市| 伊春市| 藁城市| 河北省| 康保县| 修武县| 武冈市| 偏关县| 明星| 互助| 政和县| 名山县| 金华市| 台湾省| 中宁县| 荥阳市| 郓城县| 乌兰察布市| 枣阳市| 云龙县| 秦安县| 句容市| 南木林县| 东阿县| 扶风县| 曲松县| 保靖县| 吉首市| 五台县| 桂东县| 北票市| 万盛区| 汝州市| 玛纳斯县| 乌拉特后旗| 郎溪县| 满洲里市| 滕州市|