DbgkpWerInitializeDeferredLiveDump
INT64 __fastcall DbgkpWerInitializeDeferredLiveDump(INT64 a1){
__int64 v1;
NTSTATUS v3;
int v4;
int v5;
struct _DMA_ADAPTER *v6;
UINT64 v7;
UINT64 v8;
_QWORD *v9;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
void *TimerHandle;
PADAPTER_OBJECT DmaAdapter;
v1 = *(_QWORD *)(a1 + 128);
memset(&ObjectAttributes.Length + 1, 0, 20);
memset(&ObjectAttributes.Attributes + 1, 0, 20);
TimerHandle = 0i64;
ObjectAttributes.Length = 48;
ObjectAttributes.Attributes = 512;
v3 = ZwCreateTimer(&TimerHandle, 0x1F0003ui64, &ObjectAttributes, NotificationTimer);
v4 = v3;
if( v3 >= 0 )
{
DmaAdapter = 0i64;
v5 = ObpReferenceObjectByHandleWithTag(
(ULONG_PTR)TimerHandle,
2031619,
(__int64)ExTimerObjectType,
0,
0x57676244u,
(__int64)&DmaAdapter,
0i64,
0i64);
v6 = DmaAdapter;
v4 = v5;
if( v5 >= 0 )
{
ZwClose(TimerHandle);
TimerHandle = 0i64;
*(_QWORD *)(v1 + 16) = v6;
DbgkpWerAllocateNonpagedPool(v8, v7);
if( !v9 )
{
DbgPrintEx(5u, 0, "DBGK: Could not allocate timer.\n");
return 3221225495i64;
}
*(_QWORD *)(a1 + 120) = v9;
*v9 = 0i64;
v9[2] = DbgkpWerDeferredWriteRoutine;
v9[3] = a1;
}
else
{
DbgPrintEx(5u, 0, "DBGK: Failed to reference timer, status 0x%X\n", (unsigned int)v5);
}
if( v4 < 0 )
{
if( v6 )
{
HalPutDmaAdapter(v6);
*(_QWORD *)(v1 + 16) = 0i64;
}
if( TimerHandle )
ZwClose(TimerHandle);
}
}
else
{
DbgPrintEx(5u, 0, "DBGK: Failed to create timer, status 0x%X\n", (unsigned int)v3);
}
return(unsigned int)v4;
}Referenced by:
DbgkpWerCaptureLiveFullDump