PsQueryProcessExceptionFlags
NTSTATUS __stdcall PsQueryProcessExceptionFlags(
ULONG_PTR TargetProcess,
UINT64 Flags,
PS_EXCEPTION_FLAGS *ExceptionFlags){
_EX_RUNDOWN_REF *v3;
int v4;
int v6;
_ETHREAD *CurrentThread;
unsigned int v8;
int v9;
unsigned __int64 Count;
unsigned __int64 v11;
unsigned __int64 v12;
int *v13;
int v14;
_KAPC_STATE ApcState;
v3 = *(_EX_RUNDOWN_REF **)&TargetProcess;
memset(&ApcState, 0, sizeof(ApcState));
v4 = 0;
if( (Flags & 0xFFFFFFFE) != 0 )
return -1073741584;
if( !*(_QWORD *)(*(_QWORD *)&TargetProcess + 1360i64) )
return -1073741585;
v6 = Flags & 1;
if( (Flags & 1) != 0 && !*(_QWORD *)(*(_QWORD *)&TargetProcess + 1408i64) )
return -1073741585;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
if( CurrentThread->Tcb.ApcState.Process == *(_EPROCESS **)&TargetProcess )
{
v8 = 0;
if( CurrentThread->Tcb.Process != *(_EPROCESS **)&TargetProcess )
v8 = 2;
if( v8 < 2 )
goto LABEL_13;
}
else
{
v8 = 3;
}
--CurrentThread->Tcb.KernelApcDisable;
if( !ExAcquireRundownProtection((_EX_RUNDOWN_REF *)(*(_QWORD *)&TargetProcess + 1112i64)) )
{
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
return -1073741558;
}
LABEL_13:
v9 = v8 & 1;
if( (v8 & 1) != 0 )
{
KiStackAttachProcess(v3, 0i64, &ApcState);
v9 = v8 & 1;
}
if( v6 )
{
Count = v3[176].Count;
if( !Count || *(_WORD *)(Count + 8) != 0x8664 )
{
v12 = 0i64;
if( Count )
v12 = *(_QWORD *)Count;
v13 = (int *)(v12 + 40);
goto LABEL_24;
}
v11 = *(_QWORD *)Count;
}
else
{
v11 = v3[170].Count;
}
v13 = (int *)(v11 + 80);
LABEL_24:
v14 = *v13;
if( v9 )
KiUnstackDetachProcess(&ApcState, 0i64);
if( v8 >= 2 )
{
ExReleaseRundownProtection(v3 + 139);
KeLeaveCriticalRegionThread(&CurrentThread->Tcb);
}
*ExceptionFlags = 0;
if( (v14 & 4) != 0 )
{
*ExceptionFlags = 1;
v4 = 1;
}
if( (v14 & 8) != 0 )
*ExceptionFlags = v4 | 2;
return 0;
}Referenced by:
No references.