PsQueryProcessExceptionFlags
__int64 __fastcall PsQueryProcessExceptionFlags(ULONG_PTR BugCheckParameter1, int a2, int *a3){
int v4;
int v6;
_ETHREAD *CurrentThread;
unsigned int v8;
int v9;
__int64 *v10;
__int64 v11;
__int64 v12;
int *v13;
int v14;
_KAPC_STATE ApcState;
memset(&ApcState, 0, sizeof(ApcState));
v4 = 0;
if( (a2 & 0xFFFFFFFE) != 0 )
return 3221225712i64;
if( !*(_QWORD *)(BugCheckParameter1 + 1360) )
return 3221225711i64;
v6 = a2 & 1;
if( (a2 & 1) != 0 && !*(_QWORD *)(BugCheckParameter1 + 1408) )
return 3221225711i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
if( *((_QWORD *)CurrentThread + 23) == BugCheckParameter1 )
{
v8 = 0;
if( *((_QWORD *)CurrentThread + 68) != BugCheckParameter1 )
v8 = 2;
if( v8 < 2 )
goto LABEL_13;
}
else
{
v8 = 3;
}
--*((_WORD *)CurrentThread + 242);
if( !ExAcquireRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112)) )
{
KeLeaveCriticalRegionThread((__int64)CurrentThread);
return 3221225738i64;
}
LABEL_13:
v9 = v8 & 1;
if( (v8 & 1) != 0 )
{
KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
v9 = v8 & 1;
}
if( v6 )
{
v10 = *(__int64 **)(BugCheckParameter1 + 1408);
if( !v10 || *((_WORD *)v10 + 4) != 0x8664 )
{
v12 = 0i64;
if( v10 )
v12 = *v10;
v13 = (int *)(v12 + 40);
goto LABEL_24;
}
v11 = *v10;
}
else
{
v11 = *(_QWORD *)(BugCheckParameter1 + 1360);
}
v13 = (int *)(v11 + 80);
LABEL_24:
v14 = *v13;
if( v9 )
KiUnstackDetachProcess(&ApcState, 0i64);
if( v8 >= 2 )
{
ExReleaseRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112));
KeLeaveCriticalRegionThread((__int64)CurrentThread);
}
*a3 = 0;
if( (v14 & 4) != 0 )
{
*a3 = 1;
v4 = 1;
}
if( (v14 & 8) != 0 )
*a3 = v4 | 2;
return 0i64;
}Referenced by:
No references.