100分求教 minifilter文件驱动开发 关于irp_mj_create 获取信息疑问?
各位大虾:
小弟最近在研究 minifilter 文件过滤驱动开发 有个疑问 望各位给予解惑 谢谢!!
如果可以能加QQ便于交流 更加感谢 谢谢!
问题如下:
``````````````````````````````````````````````````````````````````````````````````````````````
我在驱动中过滤所有涉及到IRP_MJ_CREATE 的文件操作 但出现这样状况:
我的期望预见的是:
例 我打开一个 任意文件(比如 test.txt)我只要截取test.txt 这个有IRP_MJ_CREATE 的操作文件
```````````````````````````````````````````````````````````````````````````````````````````````
但是我获取的是 包含了很多的 库文件 exe 等等文件 (100+ 多个有IRP_MJ_CREATE 操作的文件)
这个我到明白 是在进行打开 test.txt 文件时 系统内部进行的加载活动 (我想杀毒 就是如此吧)
``````````````````````````````````````````````````````````````````````````````````````````````
各位大虾 ,有没有什么解决办法或建议
我只想获得我 想获取的最终目标文件 test.txt 其他的放过 不进行任何处理(就是在100+ 或更多文件中获取我的目标文件 test.txt )!!!