Advice Request Can all antivirus programs detected malware that uses hooks?

Please provide comments and solutions that are helpful to the author of this topic.
Status
Not open for further replies.

Prayag

Level 4
Thread author
Verified
Well-known
Mar 27, 2017
160
517
266
India
What a malware can do if it uses hooks functionality of windows os?
How much damage it could do to the system?
How efficient are the antiviruses at detecting such malicious attempts?
 
Last edited:
Probably you mean SSDT patching to perform API hooking within the kernel instead of the classic user mode hooking using remote threads and things like that.
SSDT hooking is as far as I know, the lowest level technique to replace/hook/intercept/whatever API and for this reason has been used for years both by malcoders and AV vendors.

But in 2005 Microsoft introduced a Kernel Patching Protection (also known as “PatchGuard”) for 64 bit systems, making this technique uneffective in the worst case or quite harder to perform in the average case.
 
Status
Not open for further replies.