WbCreateHeapExecutedBlock
NTSTATUS __stdcall WbCreateHeapExecutedBlock(INT64 a1, INT64 a2, INT64 *a3){
NTSTATUS v5;
struct wil_details_FeatureReportingCache *v6;
struct wil_details_FeatureReportingCache *v7;
__int64 v8;
__int64 v9;
unsigned int v10;
__int64 v11;
unsigned __int64 v12;
struct wil_details_FeatureReportingCache *v13;
struct wil_details_FeatureReportingCache *v14;
__int64 v15;
__int64 v16;
unsigned __int64 v17;
__int64 v18;
const VOID *v19;
struct wil_details_FeatureReportingCache *v20;
struct wil_details_FeatureReportingCache *v21;
__int64 v22;
__int64 v23;
VOID *v24;
__int64 v25;
__int64 v26;
_EWOW64PROCESS *WoW64Process;
int v28;
unsigned __int16 Machine;
int v31;
_LARGE_INTEGER *StartingOffset;
_KEVENT *v33;
_IO_STATUS_BLOCK *v34;
int v35;
int v36;
int v37;
int v38;
int v39;
UINT64 Length;
VOID *Buffer;
__int64 v42;
char v44;
Buffer = 0i64;
Length = 0i64;
v44 = 0;
v42 = (unsigned int)dword_140C53B00;
v5 = WbAlloc(88);
if( v5 >= 0 )
{
memset(0i64, 0i64, 0x58u);
MEMORY[0x10] &= ~1u;
MEMORY[0x50] = 1i64;
if( *(_DWORD *)(a2 + 8) == 1 )
{
v10 = 248;
}
else
{
v37 = 3;
if( (unsigned int)wil_details_FeatureReporting_ReportUsageToServiceDirect(
v7,
v6,
v8,
v9,
wil_details_ServiceReportingKind_PotentialDeviceUsage)
&& g_wil_details_pfnFeatureLoggingHook )
{
g_wil_details_pfnFeatureLoggingHook(
0xE67B5Au,
&Feature_PdttSupport_logged_traits,
0i64,
0,
(const enum wil_ReportingKind *)&v37,
0i64,
0,
1ui64);
}
if( *(_DWORD *)(a2 + 8) )
{
v5 = -1073741811;
goto LABEL_52;
}
v10 = 240;
}
v5 = sub_14065D5DC((VOID *)(a2 + 16), v10);
if( v5 >= 0 )
{
v5 = sub_14065E218(*(PVOID *)(a2 + 328), v10, 1);
if( v5 >= 0 )
{
v5 = (unsigned int)WbAllocateUserMemory(
a1,
(_DEVICE_OBJECT *)*(unsigned int *)(a2 + 320),
&Buffer,
(UINT64)&Length,
StartingOffset,
v33,
v34);
if( v5 >= 0 )
{
v5 = WbAlloc(*(_DWORD *)(a2 + 320));
if( v5 >= 0 )
{
v11 = *(unsigned int *)(a2 + 284);
if( (_DWORD)v11 )
{
v12 = *(_QWORD *)(a2 + 272);
if( v12 + v11 > 0x7FFFFFFF0000i64 || v12 + v11 < v12 )
{
MEMORY[0x7FFFFFFF0000] = 0;
LODWORD(v11) = *(_DWORD *)(a2 + 284);
}
}
memmove((VOID *)*(unsigned int *)(a2 + 288), *(const VOID **)(a2 + 272), v11);
if( *(_DWORD *)(a2 + 8) == 1 )
{
if( *(_DWORD *)(a2 + 284) < 4u )
{
v5 = -1073741811;
goto LABEL_52;
}
*(_DWORD *)*(unsigned int *)(a2 + 288) = *(_DWORD *)(a2 + 292);
}
else
{
v38 = 3;
if( (unsigned int)wil_details_FeatureReporting_ReportUsageToServiceDirect(
v14,
v13,
v15,
v16,
wil_details_ServiceReportingKind_PotentialDeviceUsage)
&& g_wil_details_pfnFeatureLoggingHook )
{
g_wil_details_pfnFeatureLoggingHook(
0xE67B5Au,
&Feature_PdttSupport_logged_traits,
0i64,
0,
(const enum wil_ReportingKind *)&v38,
0i64,
0,
1ui64);
}
if( *(_DWORD *)(a2 + 8) )
{
v5 = -1073741811;
goto LABEL_52;
}
}
v5 = sub_14065F78C(
0,
(_BYTE *)*(unsigned int *)(a2 + 288),
(char *)*(unsigned int *)(a2 + 288),
*(_DWORD *)(a2 + 284),
(__int64 *)(a2 + 88),
*(_DWORD *)(a2 + 280),
(__int128 *)(a2 + 96),
v35,
&v44);
if( v5 >= 0 )
{
v5 = sub_14065E218(*(PVOID *)(a2 + 272), *(_DWORD *)(a2 + 284), 1);
if( v5 >= 0 )
{
v17 = *(_QWORD *)(a2 + 296);
if( !v17 )
goto LABEL_44;
v18 = *(unsigned int *)(a2 + 308);
v19 = *(const VOID **)(a2 + 296);
if( (_DWORD)v18 && (v17 + v18 > 0x7FFFFFFF0000i64 || v17 + v18 < v17) )
{
MEMORY[0x7FFFFFFF0000] = 0;
LODWORD(v18) = *(_DWORD *)(a2 + 308);
v19 = *(const VOID **)(a2 + 296);
}
memmove((VOID *)*(unsigned int *)(a2 + 312), v19, v18);
if( *(_DWORD *)(a2 + 8) == 1 )
{
if( *(_DWORD *)(a2 + 308) < 4u )
{
v5 = -1073741811;
goto LABEL_52;
}
*(_DWORD *)*(unsigned int *)(a2 + 312) = *(_DWORD *)(a2 + 316);
}
else
{
v39 = 3;
if( (unsigned int)wil_details_FeatureReporting_ReportUsageToServiceDirect(
v21,
v20,
v22,
v23,
wil_details_ServiceReportingKind_PotentialDeviceUsage)
&& g_wil_details_pfnFeatureLoggingHook )
{
g_wil_details_pfnFeatureLoggingHook(
0xE67B5Au,
&Feature_PdttSupport_logged_traits,
0i64,
0,
(const enum wil_ReportingKind *)&v39,
0i64,
0,
1ui64);
}
if( *(_DWORD *)(a2 + 8) )
{
v5 = -1073741811;
goto LABEL_52;
}
}
v5 = sub_14065F78C(
0,
(_BYTE *)*(unsigned int *)(a2 + 312),
(char *)*(unsigned int *)(a2 + 312),
*(_DWORD *)(a2 + 308),
(__int64 *)(a2 + 88),
*(_DWORD *)(a2 + 304),
(__int128 *)(a2 + 96),
v36,
&v44);
if( v5 >= 0 )
{
v5 = sub_14065E218(*(PVOID *)(a2 + 296), *(_DWORD *)(a2 + 308), 1);
if( v5 >= 0 )
{
LABEL_44:
v24 = Buffer;
memmove(Buffer, 0i64, *(_DWORD *)(a2 + 320));
MEMORY[0x40] = *(_QWORD *)a2;
MEMORY[0x28] = v24;
MEMORY[0x18] = Length + *(unsigned int *)(a2 + 288);
v25 = *(unsigned int *)(a2 + 312);
if( (_DWORD)v25 )
MEMORY[0x20] = Length + v25;
else
MEMORY[0x20] = 0i64;
MEMORY[0x48] = *(_DWORD *)(a2 + 320);
MEMORY[0x30] = *(_QWORD *)(a2 + 272);
v26 = *(_QWORD *)(a2 + 272) - MEMORY[0x18];
MEMORY[0x38] = v26;
WoW64Process = KeGetCurrentThread()->ApcState.Process->WoW64Process;
if( WoW64Process && ((Machine = WoW64Process->Machine, Machine == 332) || Machine == 452) )
*MEMORY[0x28] = MEMORY[0x40];
else
*MEMORY[0x28] = v26;
*(_QWORD *)(MEMORY[0x28] + 8i64) = v42;
ZwFlushInstructionCache();
v5 = v28;
if( v28 >= 0 )
{
if( !*(_QWORD *)(a2 + 296) || (ZwFlushInstructionCache(), v5 = v31, v31 >= 0) )
{
if( a3 )
*a3 = 0i64;
}
}
}
}
}
}
}
}
}
}
}
LABEL_52:
sub_14065EF2C((_EX_PUSH_LOCK *)a1, 0i64);
return v5;
}Referenced by:
WbGetHeapExecutedBlock