Topic: FS Minifilter. How to make count of a hash of a file
Namely not that file with which work - and that executed which works. Its checksum at present. Invented such decision: - in the filter the information (including a way to it exe) is not added at once in global queue of record in a broad gull, and there is a new flow and it is transferred in it - this flow tries to open a file and to count MD5, the result adds in global queue - a flow , as well as now, everyone N time checks, whether queue if it is full is empty - creates a file of a broad gull and writes it all But there are questions: - about opening of files, the chance will be how much great, what it can open an EXE file which, most likely, is now fulfilled? - Whether it can open it so that not to damage to it it (if that reads itself(himself) - SFX, for example)? - Whether there is all the same no more ready method to receive though any hash of an EXE file? Which not only lies on a disk as a file, but also boots as process. - How it is better to arrange all it? Now each record of a broad gull is dated by interception time, the broad gull file name is dated by outswapping time in a flow . We look a broad gull "12:00", we see in it events between the previous broad gull and 12:00. And with it MD5 we receive the broken order everywhere... If it is short, a question: it is better to driver to hammer on it absolutely (let the utility for reading of dens arranges) or to try to result all the same in a normal type?