WbGetWowTrapFrame
INT64 __fastcall WbGetWowTrapFrame(UINT64 *a1, INT64 a2){
__int64 v4;
__int16 v5;
int v6;
int v7;
int ContextThread;
v4 = *(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1408i64);
if( !v4 )
return(unsigned int)-1073741637;
v5 = *(_WORD *)(v4 + 8);
if( !v5 )
return(unsigned int)-1073741637;
if( v5 == 332 )
{
v6 = 65537;
v7 = 716;
goto LABEL_7;
}
if( v5 != 452 )
return(unsigned int)-1073741637;
v6 = 2097153;
v7 = 416;
LABEL_7:
*((_DWORD *)a1 + 12) = v6;
ContextThread = PspWow64GetContextThread((__int64)KeGetCurrentThread(), (int *)a1 + 12, v7, 0);
if( ContextThread >= 0 )
{
if( v5 == 332 )
{
*(_QWORD *)(a2 + 8) = *((unsigned int *)a1 + 58);
*(_QWORD *)a2 = *((unsigned int *)a1 + 61);
*(_DWORD *)(a2 + 16) = *((_DWORD *)a1 + 60);
}
else
{
*(_QWORD *)(a2 + 8) = *((unsigned int *)a1 + 28);
*(_QWORD *)a2 = *((unsigned int *)a1 + 26);
*(_DWORD *)(a2 + 16) = *((_DWORD *)a1 + 29);
}
}
return(unsigned int)ContextThread;
}Referenced by:
WbGetTrapFrame