to approach() ,这篇文章我也看过,不过我在Softice中就是看不出是ALTERNATIVE.两者的地址和反汇编代码完全不一样。
当然还有不少人的看法和这篇文章所说的不一样,即ajn_sailing(我心飞翔)的观点。
如果是后者,请问在NtCreateFile那里调用(或间接调用)ZwCreateFile?
The flow of control from a Win32 application executing a Win32 call (CreateFile()), through KERNEL32, NTDLL, and into kernel mode where control is transferred to the NtCreateFile system service.
Note that all of the Native APIs begin with "Nt". The export table in NTDLL.DLL also makes the Native API accessible through an alternate naming convention, one where command names begin with "Zw" instead of "Nt". Thus, ZwCreateFile() is an alias for NtCreateFile().