PsQueryProcessExceptionFlags

__int64 __fastcall PsQueryProcessExceptionFlags(ULONG_PTR BugCheckParameter1, int a2, int *a3){
  int v4; 
  int v6; 
  _ETHREAD *CurrentThread; 
  unsigned int v8; 
  int v9; 
  __int64 *v10; 
  __int64 v11; 
  __int64 v12; 
  int *v13; 
  int v14; 
  _KAPC_STATE ApcState; 
  memset(&ApcState, 0, sizeof(ApcState));
  v4 = 0;
  if( (a2 & 0xFFFFFFFE) != 0 )
    return 3221225712i64;
  if( !*(_QWORD *)(BugCheckParameter1 + 1360) )
    return 3221225711i64;
  v6 = a2 & 1;
  if( (a2 & 1) != 0 && !*(_QWORD *)(BugCheckParameter1 + 1408) )
    return 3221225711i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  if( *((_QWORD *)CurrentThread + 23) == BugCheckParameter1 )
  {
    v8 = 0;
    if( *((_QWORD *)CurrentThread + 68) != BugCheckParameter1 )
      v8 = 2;
    if( v8 < 2 )
      goto LABEL_13;
  }
  else
  {
    v8 = 3;
  }
  --*((_WORD *)CurrentThread + 242);
  if( !ExAcquireRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112)) )
  {
    KeLeaveCriticalRegionThread((__int64)CurrentThread);
    return 3221225738i64;
  }
LABEL_13:
  v9 = v8 & 1;
  if( (v8 & 1) != 0 )
  {
    KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
    v9 = v8 & 1;
  }
  if( v6 )
  {
    v10 = *(__int64 **)(BugCheckParameter1 + 1408);
    if( !v10 || *((_WORD *)v10 + 4) != 0x8664 )
    {
      v12 = 0i64;
      if( v10 )
        v12 = *v10;
      v13 = (int *)(v12 + 40);
      goto LABEL_24;
    }
    v11 = *v10;
  }
  else
  {
    v11 = *(_QWORD *)(BugCheckParameter1 + 1360);
  }
  v13 = (int *)(v11 + 80);
LABEL_24:
  v14 = *v13;
  if( v9 )
    KiUnstackDetachProcess(&ApcState, 0i64);
  if( v8 >= 2 )
  {
    ExReleaseRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112));
    KeLeaveCriticalRegionThread((__int64)CurrentThread);
  }
  *a3 = 0;
  if( (v14 & 4) != 0 )
  {
    *a3 = 1;
    v4 = 1;
  }
  if( (v14 & 8) != 0 )
    *a3 = v4 | 2;
  return 0i64;
}

Referenced by:

No references.