Kernel-mode file scanner.
Based heavily on
Detects file creation in a kernel-mode driver and then sends the file path to the user-mode application for signature scanning. Also prevents file deletion of its own files.
- Remove hard-coded file path of own critical files and place into registry to be used by
. - Integrate YARA C library.
- Add driver loading into the user-mode application.
- Change user-mode application into DLL.
- Complete C# GUI to be used with the user-mode DLL.