ExpGetPartitionTableInfo
NTSTATUS __stdcall ExpGetPartitionTableInfo(PWCHAR pDeviceName, DRIVE_LAYOUT_INFORMATION_EX **ppDriveLayout){
WCHAR v2;
NTSTATUS result;
UINT64 OutputBufferLength;
UINT64 i;
int v7;
DRIVE_LAYOUT_INFORMATION_EX *OutputBuffer;
struct _UNICODE_STRING DestinationString;
struct _IO_STATUS_BLOCK IoStatusBlock;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
UNICODE_STRING FileHandle;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
*(_QWORD *)&FileHandle.Length = 0i64;
DestinationString = 0i64;
IoStatusBlock = 0i64;
RtlInitUnicodeString(&DestinationString, pDeviceName, v2);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
result = ZwOpenFile(&FileHandle, (PWCHAR)0x100080);
if( result >= 0 )
{
LODWORD(OutputBufferLength) = 2352;
for( i = 2352i64; ; i = OutputBufferLength )
{
OutputBuffer = (DRIVE_LAYOUT_INFORMATION_EX *)ExAllocatePoolWithTag(NonPagedPoolNx, i, 0x72766E45ui64);
if( !OutputBuffer )
{
ZwClose(*(HANDLE *)&FileHandle.Length);
return -1073741670;
}
v7 = ZwDeviceIoControlFile(
*(HANDLE *)&FileHandle.Length,
0i64,
0i64,
0i64,
&IoStatusBlock,
0x70050u,
0i64,
0,
OutputBuffer,
OutputBufferLength);
if( v7 >= 0 )
break;
ExFreePoolWithTag(OutputBuffer, 0);
if( v7 != -1073741789 )
goto LABEL_10;
OutputBufferLength = (unsigned int)(2 * OutputBufferLength);
}
*ppDriveLayout = OutputBuffer;
LABEL_10:
ZwClose(*(HANDLE *)&FileHandle.Length);
return v7;
}
return result;
}Referenced by:
ExpFindDiskSignature