iam creating a filter driver to block malware application, currently iam able to block malware application but windows is showing message like this
i don’t want to show such messages, i want to do it silently plz help
this is my code
VOID
OnCreateProcessEx(PEPROCESS pEProcess,
HANDLE hProcessId,
PPS_CREATE_NOTIFY_INFO pCreateInfo)
{
if (pCreateInfo)
{
UNICODE_STRING usBlockingApp;
.
RtlInitUnicodeString(&usBlockingApp,
L"\\??\\C:\\Windows\\System32\\calculator.exe");
//Comparing the image of the process that has just been created
// with the path I used above.
if (RtlEqualUnicodeString(&usBlockingApp,
pCreateInfo->ImageFileName,
TRUE))
{
DbgPrint("[Process] Action = Blocking\n"
" Process Id = 0x%x\n"
" Parent Id = 0x%x\n"
" Image name = %wZ\n\n",
hProcessId,
pCreateInfo->ParentProcessId,
pCreateInfo->ImageFileName);
//Changes the status of the process creation to stop.
pCreateInfo->CreationStatus = STATUS_ACCESS_DENIED;
}
else
{
DbgPrint("[Process ] Action = Starting\n"
" Process Id = 0x%x\n"
" Parent Id = 0x%x\n"
" Image name = %wZ\n\n",
hProcessId,
pCreateInfo->ParentProcessId,
pCreateInfo->ImageFileName);
}
}
else
{
DbgPrint("[Process Tracer] Action = Finishing\n"
" Process Id = 0x%x\n\n",
hProcessId);
}
}
plz help