my project executable files
reads amcache information sha1 values given and queries it using virustotal api
reads things to check unicode characters in that things
better file system scanner [it queries virustotal too]
parses syscache.hve to get the sha1 values and query it to virustotal [again]
scans javaw instance to detect DoomsDay client. [used client in 1.9+]
scans minecraft instance to detect doomsday client (again) but in linux