18:06:33 notepad.exe:4008 IRP_MJ_CLOSE E:\test.txt SUCCES
Looks like is the system call used to close the file. so you would want to monitor the pid's. when you come across a FASTIO_QUERY_OPEN or a IRP_MJ_CLOSE it would open and close. I hope this is what you need to know, i am having some difficulty trying to understand what you are trying to do.
In reply to Re: File opened/closed in Windows.
by zer
in thread File opened/closed in Windows.
by Ace128
| For: | Use: | ||
| & | & | ||
| < | < | ||
| > | > | ||
| [ | [ | ||
| ] | ] |