I have an application similar to an anti-spyware program. I use a list of MD5 hashes to detect infected files. I also use a FileSystemWatcher to watch and monitor newly rena