DbgkMapViewOfSection
VOID __stdcall DbgkMapViewOfSection(
_EPROCESS *Process,
PVOID SectionObject,
PVOID BaseAddress,
UINT64 SectionOffset,
UINT64 ViewSize){
BYTE *v8;
_EPROCESS **CurrentThread;
_ETHREAD *v10;
TEB *v11;
int v12;
IMAGE_NT_HEADERS *v13;
INT64 result[5];
int v15;
HANDLE Handle;
PVOID v17;
unsigned int PointerToSymbolTable;
unsigned int NumberOfSymbols;
void **p_ArbitraryUserPointer;
int v21;
int v22;
memset((INT64)result, 0i64);
if( *((_BYTE *)KeGetCurrentThread() + 562) )
{
CurrentThread = (_EPROCESS **)KeGetCurrentThread();
if( ((_DWORD)CurrentThread[162] & 4) == 0 )
{
if( *((_QWORD *)Process + 175) )
{
v10 = (_ETHREAD *)KeGetCurrentThread();
if( (*((_DWORD *)v10 + 29) & 0x400) != 0 || *((_BYTE *)v10 + 586) == 1 )
v11 = 0i64;
else
v11 = (TEB *)*((_QWORD *)v10 + 30);
if( v11 && Process == CurrentThread[68] )
{
DbgkpSuppressDbgMsg(v11, v8);
if( v12 )
return;
p_ArbitraryUserPointer = &v11->NtTib.ArbitraryUserPointer;
}
if( SectionObject )
Handle = DbgkpSectionToFileHandle(SectionObject);
else
Handle = 0i64;
v17 = BaseAddress;
PointerToSymbolTable = v21;
NumberOfSymbols = v22;
if( BaseAddress )
v13 = RtlImageNtHeader(BaseAddress);
else
v13 = 0i64;
if( v13 )
{
PointerToSymbolTable = v13->FileHeader.PointerToSymbolTable;
NumberOfSymbols = v13->FileHeader.NumberOfSymbols;
}
result[0] = 0x800500028i64;
v15 = 5;
DbgkpSendApiMessage(Process, 1, (__int64)result);
if( Handle )
ObCloseHandle(Handle, 0);
}
}
}
}Referenced by:
MiMapViewOfSectionExCommon
NtLoadEnclaveData
NtMapViewOfSection
PsDispatchIumService