ExpAllocateOwnerEntryForLegacyShim
CHAR *__stdcall ExpAllocateOwnerEntryForLegacyShim(){
CHAR *PoolWithTag;
CHAR *v1;
_ETHREAD *CurrentThread;
CHAR *result;
do
{
PoolWithTag = (CHAR *)ExAllocatePoolWithTag(NonPagedPoolNx, 0x48ui64, 0x454F5246ui64);
v1 = PoolWithTag;
}
while( !PoolWithTag );
memset((INT64)PoolWithTag, 0i64);
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
result = v1;
v1[17] |= 2u;
*((_QWORD *)v1 + 4) = CurrentThread;
return result;
}Referenced by:
ExAcquireResourceSharedLite
ExEnterCriticalRegionAndAcquireResourceShared
ExEnterPriorityRegionAndAcquireResourceShared
ExpFastResourceLegacyAcquireExclusive
ExpFastResourceLegacyAcquireSharedStarveExclusive
SeSecurityAttributePresent
SepMandatoryIntegrityCheck