Книга: Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
Назад: Hook Injection
Дальше: APC Injection

shows a PEview of Detours being used to trojanize notepad.exe. Notice in the .detour section at that the new import table contains evil.dll, seen at . Evil.dll will now be loaded whenever Notepad is launched. Notepad will continue to operate as usual, and most users would have no idea that the malicious DLL was executed.

Instead of using the official Microsoft Detours library, malware authors have been known to use alternative and custom methods to add a .detour section. The use of these methods for detour addition should not impact your ability to analyze the malware.

sss
sss

© RuTLib.com 2015-2018