Volatility-browserhooks is a Volatility Framework plugin to detect various types of hooks as performed by recent banking Trojans.
-
Move
browserhooks.py
tovolatility/plugins/malware
in the Volatilty Framework path. -
Run:
python vol.py -f dump_from_compromised_windows_system.vmem --profile=Win7SP1x64 browserhooks (-D _store_mods)