Description: ScDetective - Full Source
A kernel level Anti-Rootkit tool which runs on the windows platform.
## Basic information
- GUI : VS2008 - MFC
- Driver :VS2005 - ddkwizard
- DDK Version:7600.16385.1
- Debug : Windbg - VirtualKD - VMware
- Platform :XPSP3 & WIN7
- Finished : 2010.12
- Author: kedebug (Wei Sun)
To Search:
File list (Check if you may need any files):
ScDetective-master
..................\Common
..................\......\DataStruct.h
..................\......\IoControlCmd.h
..................\......\MajorFunctionName.h
..................\......\VistaShadowSSDT.h
..................\......\W2K3ShadowSSDT.h
..................\......\W2KShadowSSDT.h
..................\......\Win7ShadowSSDT.h
..................\......\XPShadowSSDT.h
..................\......\ring3common.h
..................\README.md
..................\ScDetective
..................\...........\ScDetective.sln
..................\...........\ScDetective
..................\...........\...........\Function
..................\...........\...........\........\Driver
..................\...........\...........\........\......\Driver.cpp
..................\...........\...........\........\......\Driver.h
..................\...........\...........\........\File
..................\...........\...........\........\....\File.cpp
..................\...........\...........\........\....\File.h
..................\...........\...........\........\OS
..................\...........\...........\........\..\OS.cpp
..................\...........\...........\........\..\OS.h
..................\...........\...........\........\PE
..................\...........\...........\........\..\PE.cpp
..................\...........\...........\........\..\PE.h
..................\...........\...........\........\module
..................\...........\...........\........\......\Module.cpp
..................\...........\...........\........\......\Module.h
..................\...........\...........\........\......\Process.cpp
..................\...........\...........\........\......\Process.h
..................\...........\...........\........\ssdt
..................\...........\...........\........\....\ssdt.cpp
..................\...........\...........\........\....\ssdt.h
..................\...........\...........\Page1.cpp
..................\...........\...........\Page1.h
..................\...........\...........\Page2.cpp
..................\...........\...........\Page2.h
..................\...........\...........\Page3.cpp
..................\...........\...........\Page3.h
..................\...........\...........\Page4.cpp
..................\...........\...........\Page4.h
..................\...........\...........\Page5.cpp
..................\...........\...........\Page5.h
..................\...........\...........\PageFile.cpp
..................\...........\...........\PageFile.h
..................\...........\...........\ReadMe.txt
..................\...........\...........\ScDetective.aps
..................\...........\...........\ScDetective.cpp
..................\...........\...........\ScDetective.h
..................\...........\...........\ScDetective.rc
..................\...........\...........\ScDetective.vcproj
..................\...........\...........\ScDetectiveDlg.cpp
..................\...........\...........\ScDetectiveDlg.h
..................\...........\...........\res
..................\...........\...........\...\1442.ico
..................\...........\...........\...\870.ico
..................\...........\...........\...\ScDetective.ico
..................\...........\...........\...\ScDetective.rc2
..................\...........\...........\...\disk.ico
..................\...........\...........\...\dvd.ico
..................\...........\...........\...\floder.ico
..................\...........\...........\...\floppy.ico
..................\...........\...........\...\pc.ico
..................\...........\...........\...\remote.ico
..................\...........\...........\...\remove.ico
..................\...........\...........\resource.h
..................\...........\...........\stdafx.cpp
..................\...........\...........\stdafx.h
..................\...........\...........\targetver.h
..................\ScDetective_Driver
..................\..................\ScDetective.sln
..................\..................\ScDetective.suo
..................\..................\ScDetective
...........