162
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.16 Rootkit-based keylogger in kernel mode
and the machine code of the hook will be modified, which will make detection of
the keylogger even more difficult.
The hook, in turn, will call the real function (step 3) and analyze the returned
results. In case of successful extraction of a message of the type required by the
keylogger, it will analyze this message and log the results (step 4). Operation of the
spyware is absolutely invisible for all applications; it can be detected only by special
programs performing search of interceptions and modifications of machine code of
the kernel modules.
Based on the above, it is already possible to list several practical recommendations
for users:
– Special attention shall be paid to interceptions of the user32.dll function;
– It is necessary to ensure control of standard drivers according to the Microsoft
catalog to promptly detect driver replacement;
– It is necessary to perform analysis to identify possible kernel mode interceptions
and modification of the win32k.sys machine code using anti-rootkit means;
– Due to the fact that almost any keylogger stores its protocols, monitoring of
file operations during active input of information using keyboard helps detect
keylogger of almost any type. Exceptions are specialized programs that only log
input in certain applications or in given windows—e.g., in the password window.
Précédent

- 183/839

Suivant