in reply to File opened/closed in Windows.
18:06:33 notepad.exe:4008 IRP_MJ_CLOSE E:\test.txt SUCCES
Looks like is the system call used to close the file. so you would want to monitor the pid's. when you come across a FASTIO_QUERY_OPEN or a IRP_MJ_CLOSE it would open and close. I hope this is what you need to know, i am having some difficulty trying to understand what you are trying to do.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: File opened/closed in Windows.
by Ace128 (Hermit) on Mar 16, 2006 at 23:58 UTC | |
by Anonymous Monk on Mar 17, 2006 at 00:30 UTC |