Undocumented Native Win32 APIs

How do I figure out the parameters that undocumented Native Win32 APIs on Windows NT take and what the return type is?  (Please give an example for NtDeleteValueKey a.k.a. ZwDeleteValueKey)
keebler121698Asked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
jhanceConnect With a Mentor Commented:
Trial and error along with stepping through the functions with a debugger (like SoftICE) is the only way to learn about what is going on in the undocumented functions.
0
 
stsanzCommented:
Take a look at :
http://www.sysinternals.com/ntdll.htm
They say these native API are documented in WinNT DDK documentation.

0
 
keebler121698Author Commented:
Already looked there, you will notice that it says that only 25 of the calls are documented in the DDK.  My question is how do I get the parameters for the *undocumented* calls.

0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.