WheapReportPersistedErrorRecord
UINT8 __stdcall WheapReportPersistedErrorRecord(_WHEA_ERROR_RECORD *Record){
_WHEAP_WORK_QUEUE **WheaInfo;
size_t v3;
VOID **PoolWithTag;
VOID **v5;
WheaInfo = (_WHEAP_WORK_QUEUE **)KeGetPcr()->Prcb.WheaInfo;
if( !WheaInfo )
return 0;
v3 = Record->Header.Length + 40;
PoolWithTag = ExAllocatePoolWithTag(1ui64, v3, 1634035799i64);
v5 = PoolWithTag;
if( !PoolWithTag )
return 0;
memset(PoolWithTag, 0i64, v3);
*((_DWORD *)v5 + 4) = v3;
*((_DWORD *)v5 + 6) = 2;
memmove(v5 + 5, Record, Record->Header.Length);
WheapWorkQueueAddItem(WheaInfo[2], (_LIST_ENTRY *)v5);
return 1;
}Referenced by:
WheapCheckForAndReportErrorsFromPreviousSession