NtOpenFile
NTSTATUS __stdcall NtOpenFile(
VOID **FileHandle,
UINT64 DesiredAccess,
_OBJECT_ATTRIBUTES *ObjectAttributes,
_IO_STATUS_BLOCK *IoStatusBlock,
UINT64 ShareAccess,
UINT64 OpenOptions){
UINT64 v7;
UINT64 v8;
UINT64 Disposition;
UINT64 CreateOptions;
UINT64 v11;
UINT64 v12;
UINT64 InternalFlags;
LODWORD(InternalFlags) = 32;
LODWORD(v12) = 0;
LODWORD(v11) = 0;
LODWORD(CreateOptions) = OpenOptions;
LODWORD(Disposition) = 1;
LODWORD(v8) = ShareAccess;
LODWORD(v7) = 0;
return IopCreateFile(
FileHandle,
DesiredAccess,
ObjectAttributes,
IoStatusBlock,
0i64,
v7,
v8,
Disposition,
CreateOptions,
0i64,
v11,
CreateFileTypeNone,
0i64,
v12,
InternalFlags,
0i64);
}Referenced by:
PfSnGetPrefetchInstructions
RtlpSysVolTakeOwnership