FsRtlIssueFileNotificationFsctl
NTSTATUS __stdcall FsRtlIssueFileNotificationFsctl(_FILE_OBJECT *FileObject, UINT64 Flags, _GUID *FileTypeID){
_DEVICE_OBJECT *RelatedDeviceObject;
PIRP v6;
IRP *v7;
_GUID v8;
__int64 v9;
NTSTATUS result;
struct _KEVENT Event;
struct _IO_STATUS_BLOCK IoStatusBlock;
int v13[2];
_GUID v14;
memset(&Event, 0, sizeof(Event));
IoStatusBlock = 0i64;
KeInitializeEvent(&Event, NotificationEvent, 0);
RelatedDeviceObject = IoGetRelatedDeviceObject(FileObject);
v6 = IoBuildDeviceIoControlRequest(0x90204u, RelatedDeviceObject, 0i64, 0, 0i64, 0, 0, &Event, &IoStatusBlock);
v7 = v6;
if( !v6 )
return -1073741670;
v8 = *FileTypeID;
v13[0] = 1;
v13[1] = 1;
v14 = v8;
*((_QWORD *)v6 + 3) = v13;
v9 = *((_QWORD *)v6 + 23);
*(_QWORD *)(v9 - 24) = FileObject;
*(_BYTE *)(v9 - 72) = 13;
*(_DWORD *)(v9 - 56) = 24;
result = IofCallDriver(RelatedDeviceObject, v7);
if( result == 259 )
{
KeWaitForSingleObject(&Event, Executive, 0, 0, 0i64);
return IoStatusBlock.Status;
}
return result;
}Referenced by:
IopInitializeCrashDump
MiCreatePagingFile
PopResizeHiberFile