NtMapViewOfSection
NTSTATUS __stdcall NtMapViewOfSection(
VOID *SectionHandle,
VOID *ProcessHandle,
VOID **BaseAddress,
UINT64 ZeroBits,
UINT64 CommitSize,
_LARGE_INTEGER *SectionOffset,
UINT64 *ViewSize,
_SECTION_INHERIT InheritDisposition,
UINT64 AllocationType,
UINT64 Win32Protect){
NTSTATUS result;
_SECTION_INHERIT v14;
int v15;
_LARGE_INTEGER *v16;
UINT64 *v17;
int v18;
int v19;
UINT64 v20;
bool v21;
UINT64 v22;
_LARGE_INTEGER *v23;
UINT64 v24;
UINT64 v25;
UINT64 *v26;
_SECTION_INHERIT v27;
_KPROCESSOR_MODE v28;
UINT64 v29;
UINT64 v30;
UINT64 ProbeMode;
char ProbeModea;
INT64 v33[2];
UINT64 v34[2];
INT64 v35[2];
int v36;
__int64 v37[16];
UINT64 ZeroBitsa;
ZeroBitsa = ZeroBits;
memset(v37, 0i64, sizeof(v37));
*(_OWORD *)v33 = 0i64;
*(_OWORD *)v34 = 0i64;
*(_OWORD *)v35 = 0i64;
result = MiValidateZeroBits(&ZeroBitsa);
if( result >= 0 )
{
LOBYTE(ProbeMode) = KeGetCurrentThread()->PreviousMode;
LOBYTE(v28) = ProbeMode;
v14 = (int)ZeroBitsa;
v15 = Win32Protect;
LODWORD(v25) = Win32Protect;
v16 = SectionOffset;
v17 = ViewSize;
result = MiMapViewOfSectionCommon(
(INT64)ProcessHandle,
SectionHandle,
0i64,
(INT64 *)BaseAddress,
(UINT64)ViewSize,
(UINT64)SectionOffset,
v25,
ZeroBitsa,
v28,
v33);
if( result < 0 )
{
++*(&stru_140C4DB30 + 636);
return result;
}
v27 = v14;
v18 = AllocationType;
v19 = MiMapParametersInitialize(v37, v35[0], v35[1], v33[0], v33[1]);
if( v19 < 0 )
{
v21 = v33[0] == 0;
}
else
{
LODWORD(v26) = 0;
LODWORD(v23) = InheritDisposition;
v19 = MiMapViewOfSection(
(VOID *)v35[0],
(_EPROCESS *)v37,
(VOID **)v33,
CommitSize,
(UINT64)v34,
v23,
v26,
v27,
v29,
v30,
ProbeMode,
(VOID **)v33[0]);
v36 = v19;
if( v19 >= 0 )
{
if( (v37[9] & 4) != 0 )
DbgkMapViewOfSection((_EPROCESS *)v35[1], (VOID *)v35[0], (VOID *)v33[0], v20, v22);
if( (*(_DWORD *)(v35[0] + 56) & 0x20) == 0 && (v34[1] & 2) != 0 )
{
LODWORD(v24) = v15;
LODWORD(v22) = v18;
EtwTiLogMapExecView(v35[1], ProbeModea, v33[0], v33[1], v22, v24);
}
*v17 = v37[3];
*BaseAddress = (VOID *)v33[0];
if( v16 )
*v16 = (_LARGE_INTEGER)v34[0];
goto LABEL_12;
}
v21 = v33[0] == 0;
}
if( v21 )
++*(&stru_140C4DB30 + 636);
else
++*(&stru_140C4DB30 + 637);
LABEL_12:
HalPutDmaAdapter((PADAPTER_OBJECT)v35[0]);
ObfDereferenceObjectWithTag((VOID *)v35[1], 0x77566D4Dui64);
return v19;
}
return result;
}Referenced by:
No references.