DbgkpWerInitializeDeferredLiveDump

INT64 __fastcall DbgkpWerInitializeDeferredLiveDump(INT64 a1){
  __int64 v1; 
  NTSTATUS v3; 
  int v4; 
  int v5; 
  struct _DMA_ADAPTER *v6; 
  UINT64 v7; 
  UINT64 v8; 
  _QWORD *v9; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  void *TimerHandle; 
  PADAPTER_OBJECT DmaAdapter; 
  v1 = *(_QWORD *)(a1 + 128);
  memset(&ObjectAttributes.Length + 1, 0, 20);
  memset(&ObjectAttributes.Attributes + 1, 0, 20);
  TimerHandle = 0i64;
  ObjectAttributes.Length = 48;
  ObjectAttributes.Attributes = 512;
  v3 = ZwCreateTimer(&TimerHandle, 0x1F0003ui64, &ObjectAttributes, NotificationTimer);
  v4 = v3;
  if( v3 >= 0 )
  {
    DmaAdapter = 0i64;
    v5 = ObpReferenceObjectByHandleWithTag(
           (ULONG_PTR)TimerHandle,
           2031619,
           (__int64)ExTimerObjectType,
           0,
           0x57676244u,
           (__int64)&DmaAdapter,
           0i64,
           0i64);
    v6 = DmaAdapter;
    v4 = v5;
    if( v5 >= 0 )
    {
      ZwClose(TimerHandle);
      TimerHandle = 0i64;
      *(_QWORD *)(v1 + 16) = v6;
      DbgkpWerAllocateNonpagedPool(v8, v7);
      if( !v9 )
      {
        DbgPrintEx(5u, 0, "DBGK: Could not allocate timer.\n");
        return 3221225495i64;
      }
      *(_QWORD *)(a1 + 120) = v9;
      *v9 = 0i64;
      v9[2] = DbgkpWerDeferredWriteRoutine;
      v9[3] = a1;
    }
    else
    {
      DbgPrintEx(5u, 0, "DBGK: Failed to reference timer, status 0x%X\n", (unsigned int)v5);
    }
    if( v4 < 0 )
    {
      if( v6 )
      {
        HalPutDmaAdapter(v6);
        *(_QWORD *)(v1 + 16) = 0i64;
      }
      if( TimerHandle )
        ZwClose(TimerHandle);
    }
  }
  else
  {
    DbgPrintEx(5u, 0, "DBGK: Failed to create timer, status 0x%X\n", (unsigned int)v3);
  }
  return(unsigned int)v4;
}

Referenced by:

DbgkpWerCaptureLiveFullDump