Thanks, interesting stuff. This all should be covered by a good behavior blocker. SpyShelter, OSArmor, HMPA and CIS are probably the best solutions for home users, although they don't monitor all of the behaviors mentioned in this article. https://www.elastic.co/security-labs/unveiling-malware-behavior-trends