FsRtlIssueFileNotificationFsctl

NTSTATUS __stdcall FsRtlIssueFileNotificationFsctl(_FILE_OBJECT *FileObject, UINT64 Flags, _GUID *FileTypeID){
  _DEVICE_OBJECT *RelatedDeviceObject; 
  PIRP v6; 
  IRP *v7; 
  _GUID v8; 
  __int64 v9; 
  NTSTATUS result; 
  struct _KEVENT Event; 
  struct _IO_STATUS_BLOCK IoStatusBlock; 
  int v13[2]; 
  _GUID v14; 
  memset(&Event, 0, sizeof(Event));
  IoStatusBlock = 0i64;
  KeInitializeEvent(&Event, NotificationEvent, 0);
  RelatedDeviceObject = IoGetRelatedDeviceObject(FileObject);
  v6 = IoBuildDeviceIoControlRequest(0x90204u, RelatedDeviceObject, 0i64, 0, 0i64, 0, 0, &Event, &IoStatusBlock);
  v7 = v6;
  if( !v6 )
    return -1073741670;
  v8 = *FileTypeID;
  v13[0] = 1;
  v13[1] = 1;
  v14 = v8;
  *((_QWORD *)v6 + 3) = v13;
  v9 = *((_QWORD *)v6 + 23);
  *(_QWORD *)(v9 - 24) = FileObject;
  *(_BYTE *)(v9 - 72) = 13;
  *(_DWORD *)(v9 - 56) = 24;
  result = IofCallDriver(RelatedDeviceObject, v7);
  if( result == 259 )
  {
    KeWaitForSingleObject(&Event, Executive, 0, 0, 0i64);
    return IoStatusBlock.Status;
  }
  return result;
}

Referenced by:

IopInitializeCrashDump
MiCreatePagingFile
PopResizeHiberFile