160
2 Computer Viruses, Malicious Logic, and Spyware
to the logging system (step 4). After that, IRP is returned into the RawInputThread,
and the entire process is repeated. It is evident that the presence of a correctly written
filter driver has no effect on the work of applications and ensures global interception
of keyboard input.
Detection of the described logger is not difficult: in order to find it, it is only
necessary to examine the keyboard driver stack for the presence of unidentified filter
drivers.
2.4.2.7 Rootkit-Based Keyloggers in User Mode
Operating principle of such keyloggers is based on interruption of a number of
USER32.DLL functions for monitoring of their calls. Such malware programs are not
widely popular yet; however, this is only a matter of time. The danger of application
of rootkit technologies in keyloggers is explained by the fact that, firstly, many antikeyloggers are not designed to detect spies of such type and cannot combat them,
and, secondly, anti-rootkit programs often don’t check interceptions of function of
the user32.dll library.
Operating principle of such keylogger is fairly simple: using any of the known
rootkit technologies, one or several functions providing control over the information
input from the keyboard are intercepted. The simplest task is interception of functions
GetMessage and PeekMessage (Fig. 2.15).
Operation of this keylogger is organized in the following manner. The application
calls the function PeekMessage in order to find out whether there are messages of
the specified type in the queue. This call is intercepted using the rootkit principle
(method used is irrelevant in this case). After that, the hook calls the real function
PeekMessage from user32.dll and analyzes the returned results. If the function returns
true, it means that the message was in the queue, and that is was extracted into the
buffer referenced as the first parameter of the function. In this case, the hook checks
messages in the buffer for the presence of messages like WM_KEYDOWN (key
pressing), WM_KEYUP (key release), and WM_CHAR (sent to the window after
Fig. 2.15 Principles of organization of function interception
Précédent

- 181/839

Suivant