ExInitializeLeapSecondData
INT64 __stdcall ExInitializeLeapSecondData(){
NTSTATUS v0;
_LOADER_PARAMETER_BLOCK *v1;
ULONG_PTR v2;
UINT64 v3;
_MDL *PoolWithTag;
struct _MDL *v5;
__int16 v6;
BOOL *v7;
PVOID *Object;
POBJECT_HANDLE_INFORMATION HandleInformation;
_LARGE_INTEGER v11[7];
PVOID MappedBase;
HANDLE Handle;
PVOID Section;
ULONG_PTR ViewSize;
Handle = 0i64;
v11[0].QuadPart = 4096i64;
LODWORD(HandleInformation) = 0x8000000;
LODWORD(Object) = 4;
v0 = ZwCreateSection(&Handle, 6ui64, 0i64, v11, (UINT64)Object, (UINT64)HandleInformation, 0i64);
if( v0 >= 0 )
{
Section = 0i64;
v0 = ObReferenceObjectByHandle(Handle, 6u, MmSectionObjectType, 0, &Section, 0i64);
if( v0 >= 0 )
{
MappedBase = 0i64;
ViewSize = 0i64;
v1 = (_LOADER_PARAMETER_BLOCK *)Section;
v0 = MmMapViewInSystemSpace(Section, &MappedBase, &ViewSize);
if( v0 >= 0 )
{
v2 = ViewSize;
v3 = MmSizeOfMdl(MappedBase, ViewSize);
PoolWithTag = (_MDL *)ExAllocatePoolWithTag(NonPagedPoolNx, v3, 0x6453704Cui64);
v5 = PoolWithTag;
if( !PoolWithTag )
goto LABEL_11;
PoolWithTag->Next = 0i64;
v6 = (__int16)MappedBase;
PoolWithTag->Size = 8 * (((((unsigned __int16)MappedBase & 0xFFF) + v2 + 4095) >> 12) + 6);
PoolWithTag->MdlFlags = 0;
PoolWithTag->StartVa = (void *)((unsigned __int64)MappedBase & 0xFFFFFFFFFFFFF000ui64);
PoolWithTag->ByteOffset = v6 & 0xFFF;
PoolWithTag->ByteCount = v2;
MmProbeAndLockPages(PoolWithTag, 0, IoWriteAccess);
v7 = (BOOL *)MmMapLockedPagesSpecifyCache(v5, 0, MmCached, 0i64, 0, 0x40000010u);
if( v7 )
{
v0 = MmUnmapViewInSystemSpace(MappedBase);
if( v0 >= 0 )
{
ExpLeapSecondDataLock = 0i64;
ExLeapSecondDataSectionPointer = v1;
memset((INT64)v7, 0i64);
ExpReadLeapSecondData(v7, 0);
ExLeapSecondData = v7;
}
}
else
{
LABEL_11:
v0 = -1073741801;
}
}
}
}
if( Handle )
ZwClose(Handle);
return(unsigned int)v0;
}Referenced by:
Phase1InitializationDiscard