168
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.22 Interception of functions LoadLibrary and GetProcAddress
difficult, since it can be implemented with the help of specialized API functions,
which allow working with the program image in memory. Source text of such hook
in C language takes several pages of printed text.
Even though the functions LoadLibrary and GetProcAddress can be implemented
by any method, classic implementation usually employs the method shown in
Fig. 2.22—modification of the import table. The idea behind this method is simple:
after intercepting GetProcAddress, it is possible during address requests to provide
the program with hook addresses instead of addresses of the functions required by
the program. As with the method in Fig. 2.21, the program won’t notice any difference. When GetProcAddress is called, the program receives the address and calls
the function. This method has a downside—it cannot intercept statically imported
functions (Fig. 2.23).
In this method, the import table is modified (Fig. 2.24); moreover, the functions LoadLibrary and GetProcAddress of the kernel32.dll library must be mandatorily intercepted. In this case, when calling statically imported functions, distorted
addresses are taken from the import table; when dynamically determining the address,
the intercepted function GetProcAddress is called, which returns addresses of the
hooks. In this case, the program is absolutely unable to determine the correct address
of the function.
Fig. 2.23 Combination of methods 2 and 3
2 Computer Viruses, Malicious Logic, and Spyware
Fig. 2.22 Interception of functions LoadLibrary and GetProcAddress
difficult, since it can be implemented with the help of specialized API functions,
which allow working with the program image in memory. Source text of such hook
in C language takes several pages of printed text.
Even though the functions LoadLibrary and GetProcAddress can be implemented
by any method, classic implementation usually employs the method shown in
Fig. 2.22—modification of the import table. The idea behind this method is simple:
after intercepting GetProcAddress, it is possible during address requests to provide
the program with hook addresses instead of addresses of the functions required by
the program. As with the method in Fig. 2.21, the program won’t notice any difference. When GetProcAddress is called, the program receives the address and calls
the function. This method has a downside—it cannot intercept statically imported
functions (Fig. 2.23).
In this method, the import table is modified (Fig. 2.24); moreover, the functions LoadLibrary and GetProcAddress of the kernel32.dll library must be mandatorily intercepted. In this case, when calling statically imported functions, distorted
addresses are taken from the import table; when dynamically determining the address,
the intercepted function GetProcAddress is called, which returns addresses of the
hooks. In this case, the program is absolutely unable to determine the correct address
of the function.
Fig. 2.23 Combination of methods 2 and 3
