172
2 Computer Viruses, Malicious Logic, and Spyware
Interception of low-level API functions first of all allows such program to sufficiently
hide its presence in the system, protecting it from being detected by the user and
antivirus software.
Rootkit technologies, in turn, can be divided into two basic categories:
– User mode programs;
– Kernel mode programs.
The first category is based on intercepting functions of libraries and the second
one on installing a system driver intercepting kernel level APIs.
User mode also provides several methods of interception of functions:
– Modification of the machine code of an application;
– Modification of the import table of an executable;
– Interception of functions LoadLibrary and GetProcAddress;
– Modification of the software code of an API function;
– Modification of the program code of DLL libraries.
Let us consider the most popular method that combines interception of LoadLibrary and GetProcAddress functions and modification of the import table.
There are two ways of calling DLL-located functions:
– Static binding (statically imported functions);
– Dynamic binding (dynamically imported functions).
In the first case, the compiler knows the list of functions imported by the program.
Using these data, the compiler forms the import table of the EXE file, which contains
the list of libraries used by the program and the list of functions imported from every
library. The import table contains fields for storage of virtual address of each function.
During the compilation stage, the real RAM address is unknown. During loading of
an EXE file into RAM, the system analyzes its import table, loads all libraries listed
in it into RAM, and places real addresses of functions in the table. Items 1–3 in
Fig. 2.26 demonstrate the early binding process. When the code segment is loaded
into RAM, address fields in the import table are filled (1). When a function is called
Fig. 2.26 Interaction scheme characterizing the principle of API function call [14]
2 Computer Viruses, Malicious Logic, and Spyware
Interception of low-level API functions first of all allows such program to sufficiently
hide its presence in the system, protecting it from being detected by the user and
antivirus software.
Rootkit technologies, in turn, can be divided into two basic categories:
– User mode programs;
– Kernel mode programs.
The first category is based on intercepting functions of libraries and the second
one on installing a system driver intercepting kernel level APIs.
User mode also provides several methods of interception of functions:
– Modification of the machine code of an application;
– Modification of the import table of an executable;
– Interception of functions LoadLibrary and GetProcAddress;
– Modification of the software code of an API function;
– Modification of the program code of DLL libraries.
Let us consider the most popular method that combines interception of LoadLibrary and GetProcAddress functions and modification of the import table.
There are two ways of calling DLL-located functions:
– Static binding (statically imported functions);
– Dynamic binding (dynamically imported functions).
In the first case, the compiler knows the list of functions imported by the program.
Using these data, the compiler forms the import table of the EXE file, which contains
the list of libraries used by the program and the list of functions imported from every
library. The import table contains fields for storage of virtual address of each function.
During the compilation stage, the real RAM address is unknown. During loading of
an EXE file into RAM, the system analyzes its import table, loads all libraries listed
in it into RAM, and places real addresses of functions in the table. Items 1–3 in
Fig. 2.26 demonstrate the early binding process. When the code segment is loaded
into RAM, address fields in the import table are filled (1). When a function is called
Fig. 2.26 Interaction scheme characterizing the principle of API function call [14]
