2.5 Basic Operating Principles of Rootkit Technologies
171
method does not require rebooting of the examined PC and is implemented in the
free utility RootkitRevealer by SysInternals (http://www.sysinternals.com). Another
example is the KLister utility program (www.rootkit.com), which is used to generate
the list of running processes and consists of the driver and the console program using
this driver.
Analysis in the function memory of basic libraries for the presence of alterations of
their machine code. This method is most effective to combat rootkits in the user mode.
This method helps not only detect interception of functions, but also restore normal
operation of damaged functions. Moreover, the comparison of system snapshots
taken before and after recovery of API functions in many cases helps reveal disguised
processes, services, and drivers. This method does not require rebooting; one of the
variants is implemented in my utility program AVZ.
Analysis and recovery of the ServiceDescriptor Table. This method helps combat
a number of hooks operating in kernel mode (in particular, with the hooks based on
SDT modification). It is practically implemented in the utility SDTRestore (http://
www.security.org.sg/code/sdtrestore.html). However, SDT recovery affects operation of the entire system and can cause extremely unpleasant effects (in the simplest
case—to complete system freezing with exit to BSoD, in the worst case—to unpredictable violations of normal operation of the applications intercepting NativeAPIs
for implementation of their functions).
The above methods of function interception explain the main principles of rootkit
operations. However, it is worth remembering that developers of rootkit technologies
don’t stand still; as a result, new developments, approaches, and methods emerge all
the time.
Practice shows that developers of malware (viruses, Trojans, spyware) are using
rootkit technologies more and more frequently, which makes detection and deletion
of malware created by them much more difficult. Methods of interception of functions in user mode are most popular; however, extremely effective implementations
employing drivers have appeared recently. In this regard, according to my statistics,
the most “famous” one is Backdoor.Win32.Haxdoor, which installs several drivers
into the system; the installation allows it to effectively mask itself from being detected
by the user.
In the next section, we are going to talk about keyloggers: we will consider their
design, operating principles, and detection methods in detail.
2.5.5 Typical Mechanism of Penetration of Rootkit Trojans
into the System
Let us consider the operating mechanism of rootkit programs—the hazard that
becomes more and more topical lately.
In Windows, rootkits are the programs that penetrate the system unauthorized,
intercepts system function calls (API), and performs modification of system libraries.
Précédent

- 192/839

Suivant