ZwOpenFile

NTSTATUS __stdcall ZwOpenFile(
        VOID **FileHandle,
        UINT64 DesiredAccess,
        _OBJECT_ATTRIBUTES *ObjectAttributes,
        _IO_STATUS_BLOCK *IoStatusBlock,
        UINT64 ShareAccess,
        UINT64 OpenOptions){
  NTSTATUS result; 

  _disable();
  __readeflags();
  KiServiceInternal();
  return result;
}

Referenced by:

ApiSetpLoadSchemaImage
AslDoesDirectoryExistNtPath
AslDoesFileExistNtPath
AslpPathWildcardAllocMatchNode
BiCreatePartitionDevice
BiGetDriveLayoutInformation
BiGetNtPartitionPath
BiGetPartitionVhdFilePathFromUnicodeString
BiGetPhysicalDriveName
BiIsVolumePartitionInformationRetained
BiLogFileOwnerProcess
CMFFlushHitsFile
CMFSystemThreadRoutine
CmpLogHiveFileInaccessible
CmpOpenFileWithExtremePrejudice
DbgkPostModuleMessage
DbgkSendSystemDllMessages
DbgkpSectionToFileHandle
EtwpUpdateFileInfoDriverRegistration
ExpGetDriveGeometry
ExpGetGlobalLocaleSection
ExpGetPartitionTableInfo
ExpTranslateNtPath
HalpAcquirePccInterface
IoAttachDevice
IoGetDeviceObjectPointer
IoInitSystemPreDrivers
IopApplySystemPartitionProt
IopFileUtilClearAttributes
IopFileUtilRename
IopFileUtilWalkDirectoryTreeHelper
IopIsNotNativeDriverImage
IopMarkBootPartition
IopValidateJunctionTarget
KsepSdbMapToMemory
KsepShimDatabaseTime
MiCreateSectionForDriver
MiOpenHotPatchFile
NtGetNlsSectionPtr
PiDrvDbQuerySystemPathWin32
PiGetDriverImageDirectory
PiInitializeDDB
PiOpenDirectoryWithRoot
PipCriticalDeviceWaitCallback
PopPdcCsCheckSystemVolumeDevice
PopValidateHiberFileSize
PpLastGoodDeleteFilesCallback
PspLocateSystemDll
RamdiskStart
RtlLockBootStatusData
SiOpenDevice
VhdiGetVolumeNumber
VhdiInitializeBootDisk