PfSnQueryVolumeInfo
__int64 __fastcall PfSnQueryVolumeInfo(__int64 a1, const WCHAR *a2, _OWORD *a3, _QWORD *a4, _DWORD *a5){
__int64 v6;
int v9;
__int128 v10;
__int128 v11;
INT64 FsInformationClass;
INT64 v14;
INT64 v15;
INT64 v16;
__m256i FileHandle;
struct _UNICODE_STRING DestinationString;
struct _IO_STATUS_BLOCK IoStatusBlock;
__int128 FsInformation;
__int64 v21;
memset(&FileHandle, 0, 24);
v21 = 0i64;
v6 = 0x200000000i64;
FsInformation = 0i64;
FileHandle.m256i_i64[3] = 0x200000000i64;
DestinationString = 0i64;
IoStatusBlock = 0i64;
RtlInitUnicodeString(&DestinationString, a2, (WCHAR)a3);
v9 = PfpOpenHandleCreate((__int64)&FileHandle, a1, (__int64)&DestinationString, 0i64, 1048960, 0, 0, 0i64);
if( v9 < 0
|| (LODWORD(FsInformationClass) = 1,
v9 = NtQueryVolumeInformationFile(
(VOID *)FileHandle.m256i_i64[0],
&IoStatusBlock,
&FsInformation,
24i64,
FsInformationClass,
v14,
v15,
v16),
(v9 & 0xC0000000) == -1073741824) )
{
v6 = FileHandle.m256i_i64[3];
}
else
{
v10 = *(_OWORD *)FileHandle.m256i_i8;
v11 = *(_OWORD *)&FileHandle.m256i_u64[2];
FileHandle.m256i_i64[0] = 0i64;
*a4 = FsInformation;
v9 = 0;
*a5 = DWORD2(FsInformation);
*a3 = v10;
FileHandle.m256i_i64[3] = 0x200000000i64;
*(_OWORD *)&FileHandle.m256i_u64[1] = 0i64;
a3[1] = v11;
}
if( (v6 & 0x400000000i64) != 0 )
PfpOpenHandleClose(&FileHandle, a1);
return(unsigned int)v9;
}Referenced by:
PfSnOpenVolumesForPrefetch