Potentially Suspicious Desktop Background Change Using Reg.EXE — Detection Rule

Detects the execution of "reg.exe" to alter registry keys that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.

Read the full analysis on IntelFusions