RawMountVolume

INT64 __fastcall RawMountVolume(_IO_STACK_LOCATION *IrpSp){
  __int64 v2; 
  INT64 result; 
  PDEVICE_OBJECT v4; 
  unsigned int v5; 
  int v6; 
  FILE_OBJECT *StreamFileObjectLite; 
  _QWORD *v8; 
  __int64 v9; 
  FSRTL_ADVANCED_FCB_HEADER *v10; 
  UINT64 DeviceCharacteristics; 
  PDEVICE_OBJECT DeviceObject; 
  FILE_OBJECT *v13; 
  char Event[44]; 
  int v15; 
  int v16; 
  int v17; 
  wchar_t v18; 
  int v19; 
  DeviceObject = 0i64;
  RawScanDeletedList();
  v2 = *((_QWORD *)IrpSp + 2);
  if( *(_WORD *)(v2 + 304) > 0x1000u )
    return 3221225807i64;
  LODWORD(DeviceCharacteristics) = 0;
  LODWORD(result) = IoCreateDevice(
                      *(DRIVER_OBJECT **)(*((_QWORD *)IrpSp + 5) + 8i64),
                      0x150ui64,
                      0i64,
                      8ui64,
                      DeviceCharacteristics,
                      0,
                      &DeviceObject);
  if( (int)result >= 0 )
  {
    v4 = DeviceObject;
    v5 = *(_DWORD *)(v2 + 152);
    if( v5 > *((_DWORD *)DeviceObject + 38) )
      *((_DWORD *)DeviceObject + 38) = v5;
    *((_WORD *)v4 + 152) = *(_WORD *)(v2 + 304);
    *((_DWORD *)v4 + 12) |= 0x10u;
    v6 = RawInitializeVcb((_DWORD *)v4 + 84, *((_QWORD *)IrpSp + 2), *((_QWORD *)IrpSp + 1));
    if( v6 < 0 )
    {
      v10 = (FSRTL_ADVANCED_FCB_HEADER *)((char *)v4 + 336);
    }
    else
    {
      *(_QWORD *)(*((_QWORD *)v4 + 65) + 8i64) = v4;
      *(_DWORD *)(*((_QWORD *)v4 + 65) + 24i64) = -1;
      *(_WORD *)(*((_QWORD *)v4 + 65) + 6i64) = 0;
      *((_DWORD *)v4 + 12) &= ~0x80u;
      *((_BYTE *)v4 + 76) = *(_BYTE *)(v2 + 76) + 1;
      v13 = 0i64;
      memset(&Event[4], 0, 20);
      v19 = 0;
      StreamFileObjectLite = IoCreateStreamFileObjectLite(0i64, v4);
      v13 = StreamFileObjectLite;
      if( v6 >= 0 )
      {
        *((_DWORD *)v4 + 111) += 2;
        *((_DWORD *)v4 + 112) += 2;
        *(_DWORD *)Event = 4063233;
        *(_QWORD *)&Event[24] = 0i64;
        *(_DWORD *)&Event[32] = -1;
        *(_QWORD *)&Event[36] = 1i64;
        v15 = 6;
        v16 = 16;
        v17 = *(_DWORD *)L"RAW";
        v18 = aRaw[2];
        FsRtlNotifyVolumeEventEx(StreamFileObjectLite, 6ui64, (TARGET_DEVICE_CUSTOM_NOTIFICATION *)Event);
        HalPutDmaAdapter((PADAPTER_OBJECT)StreamFileObjectLite);
        *((_DWORD *)v4 + 111) -= 2;
        *((_DWORD *)v4 + 112) -= 2;
        ExAcquireFastMutex(&RawGlobalLock);
        v8 = (_QWORD *)((char *)v4 + 496);
        v9 = RawMountedQueue;
        if( *(__int64 **)(RawMountedQueue + 8) != &RawMountedQueue )
          __fastfail(3u);
        *v8 = RawMountedQueue;
        v8[1] = &RawMountedQueue;
        *(_QWORD *)(v9 + 8) = v8;
        RawMountedQueue = (__int64)v8;
        KeReleaseGuardedMutex(&RawGlobalLock);
        return(unsigned int)v6;
      }
      v10 = (FSRTL_ADVANCED_FCB_HEADER *)((char *)v4 + 336);
    }
    RawCleanupVcb(v10);
    IoDeleteDevice(v4);
    return(unsigned int)v6;
  }
  return result;
}

Referenced by:

RawFileSystemControl