ExRaiseHardError
INT64 __stdcall ExRaiseHardError(
INT64 ErrorStatus,
UINT64 NumberOfParameters,
UINT64 UnicodeStringParameterMask,
UINT64 *Parameters,
UINT64 ValidResponseOptions,
UINT64 *Response){
unsigned int v7;
unsigned int v8;
unsigned int v9;
INT64 result;
UINT64 *v11;
ULONG_PTR v12;
__int64 i;
char *v14;
char *v15;
UNICODE_STRING *v16;
__int64 v17;
__int64 v18;
char *v19;
__int64 v20;
unsigned int v21;
UINT64 AllocationType;
UINT64 Protect;
PVOID BaseAddress;
UINT64 v25;
ULONG_PTR RegionSize;
int v27;
unsigned int v28;
int v29;
int v30;
int v31;
UNICODE_STRING *v32;
UINT64 *v33;
UINT64 *v34;
UNICODE_STRING *v35;
__int128 v36[5];
v7 = UnicodeStringParameterMask;
v8 = NumberOfParameters;
v9 = ErrorStatus;
v28 = ErrorStatus;
v29 = ErrorStatus;
v30 = NumberOfParameters;
v31 = UnicodeStringParameterMask;
v33 = Parameters;
v34 = Response;
LODWORD(v25) = 0;
RegionSize = 0i64;
if( ExpTooLateForErrors )
{
*(_DWORD *)Response = 1;
return 0i64;
}
*(_DWORD *)Response = 0;
if( (unsigned int)NumberOfParameters > 5 )
return 3221225712i64;
v11 = 0i64;
BaseAddress = 0i64;
if( Parameters )
{
if( (_DWORD)UnicodeStringParameterMask )
{
v12 = 136i64;
RegionSize = 136i64;
for( i = 0i64; (unsigned int)i < v8; i = (unsigned int)(i + 1) )
{
if( _bittest((const int *)&v7, i) )
{
v36[(unsigned int)i] = *(_OWORD *)Parameters[i];
v12 += WORD1(v36[(unsigned int)i]);
RegionSize = v12;
}
}
LODWORD(Protect) = 4;
LODWORD(AllocationType) = 4096;
LODWORD(result) = ZwAllocateVirtualMemory(
(PVOID)0xFFFFFFFFFFFFFFFFi64,
&BaseAddress,
0i64,
&RegionSize,
AllocationType,
Protect);
if( (int)result < 0 )
return result;
v11 = (UINT64 *)BaseAddress;
v14 = (char *)BaseAddress;
v15 = (char *)BaseAddress + 40;
v16 = (UNICODE_STRING *)((char *)BaseAddress + 120);
v32 = (UNICODE_STRING *)((char *)BaseAddress + 120);
v17 = 0i64;
v27 = 0;
while( (unsigned int)v17 < v8 )
{
if( _bittest((const int *)&v7, v17) )
{
*(_QWORD *)&v14[8 * v17] = &v15[16 * (unsigned int)v17];
v18 = (unsigned int)v17;
v19 = &v15[v18 * 16];
*((_QWORD *)v19 + 1) = v16;
v20 = WORD1(v36[v18]);
*((_WORD *)v19 + 1) = v20;
RtlCopyUnicodeString((UNICODE_STRING *)&v15[v18 * 16], (UNICODE_STRING *)&v36[v18], v16);
v16 = (UNICODE_STRING *)((char *)v32 + v20);
v32 = v16;
v35 = v16;
v15 = v14 + 40;
}
else
{
*(_QWORD *)&v14[8 * v17] = Parameters[v17];
}
v17 = (unsigned int)(v17 + 1);
v27 = v17;
v11 = (UINT64 *)BaseAddress;
}
v9 = v28;
}
else
{
v11 = Parameters;
BaseAddress = Parameters;
}
}
LODWORD(Protect) = ValidResponseOptions;
v21 = ExpRaiseHardError(v9, v8, v7, v11, v11, Protect, &v25);
if( BaseAddress && BaseAddress != Parameters )
{
RegionSize = 0i64;
ZwFreeVirtualMemory((PVOID)0xFFFFFFFFFFFFFFFFi64, &BaseAddress, &RegionSize, 0x8000ui64);
}
*(_DWORD *)Response = v25;
return v21;
}Referenced by:
CmpDiskFullWarningWorker
CmpLoadHiveThread
CmpMountPreloadedHives
CmpQuotaWarningWorker
ExpExpirationThread
IopHardErrorThread
IopRaiseHardError
IopRaiseInformationalHardError
NtRaiseHardError