ExpSaInitialize
UINT8 __stdcall ExpSaInitialize(){
UINT8 v0;
VOID **PoolWithTag;
unsigned int v2;
size_t v3;
unsigned int v4;
VOID **v5;
unsigned int v6;
unsigned int v7;
__int64 v8;
struct _KPRCB *v9;
UINT64 v10;
VOID *PoolWithTagFromNode;
_KPRCB *Prcb;
VOID **v13;
VOID **v14;
INT64 arg20;
v0 = 0;
*(&WheapDeferredInternalLogsEventLock + 51) = 0i64;
*(&WheapDeferredInternalLogsEventLock + 52) = 0i64;
*(&WheapDeferredInternalLogsEventLock + 48) = 0i64;
*(&WheapDeferredInternalLogsEventLock + 50) = 0i64;
*(&WheapDeferredInternalLogsEventLock + 49) = 0i64;
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, 0x80ui64, 1632860229i64);
*(&WheapDeferredInternalLogsEventLock + 51) = PoolWithTag;
if( PoolWithTag )
{
memset(PoolWithTag, 0i64, 0x80u);
KeQueryMaximumProcessorCountEx(0xFFFFu);
v3 = 8 * v2;
v4 = v2;
v5 = ExAllocatePoolWithTag(0x200ui64, 8i64 * v2, 1632860229i64);
*(&WheapDeferredInternalLogsEventLock + 52) = v5;
if( v5 )
{
memset(v5, 0i64, v3);
v6 = KeNumberProcessors_0;
v7 = 0;
if( v4 )
{
v8 = 0i64;
while( 1 )
{
v9 = v7 >= v6 ? KeGetCurrentPrcb() : KeGetPrcb(v7);
LODWORD(arg20) = 0;
v10 = v9->ParentNode->Affinity.Reserved[0];
LODWORD(v10) = v10 | 0x80000000;
PoolWithTagFromNode = ExpAllocatePoolWithTagFromNode(0x200ui64, 0x80u, 0x61537845ui64, v10, arg20);
*(_QWORD *)(v8 + *(&WheapDeferredInternalLogsEventLock + 52)) = PoolWithTagFromNode;
if( !PoolWithTagFromNode )
break;
memset(PoolWithTagFromNode, 0i64, 0x80u);
Prcb = KeGetPrcb(v7);
if( Prcb )
Prcb->ExSaPageArray = *(void **)(v8 + *(&WheapDeferredInternalLogsEventLock + 52));
++v7;
v8 += 8i64;
if( v7 >= v4 )
goto LABEL_11;
}
}
else
{
LABEL_11:
v13 = ExAllocatePoolWithTag(0x200ui64, 0x48ui64, 1632860229i64);
*(&WheapDeferredInternalLogsEventLock + 48) = v13;
if( v13 )
{
ExpSaAllocatorInitialize(v13, 0);
v14 = ExAllocatePoolWithTag(1ui64, 0x48ui64, 1632860229i64);
*(&WheapDeferredInternalLogsEventLock + 50) = v14;
if( v14 )
{
ExpSaAllocatorInitialize(v14, 1);
return 1;
}
}
}
}
}
return v0;
}Referenced by:
ExpInitSystemPhase1