115 DPRINT1(
"RtlDQDB: Failed to free VM!\n");
142 DPRINT(
"RtlpQueryRemoteProcessModules Start\n");
164 Modules->NumberOfModules = 0;
165 ModulePtr = &Modules->Modules[0];
201 while(pleCurEntry != pleListHead)
238 DPRINT(
" Module %wZ\n", &Unicode);
244 else if (Modules !=
NULL)
269 Modules->NumberOfModules++;
280 DPRINT(
"RtlpQueryRemoteProcessModules End\n");
298 Buf->Flags = DebugInfoMask;
301 DPRINT(
"QueryProcessDebugInformation Start\n");
318 ULONG ReturnSize = 0;
328 DPRINT1(
"RtlQueryProcessDebugInformation: Unable to commit %u\n", ReturnSize);
358 Buf->OffsetFree = Buf->OffsetFree + HSize;
370 Buf->OffsetFree = Buf->OffsetFree + LSize;
373 DPRINT(
"QueryProcessDebugInformation end\n");
374 DPRINT(
"QueryDebugInfo : 0x%lx\n", Buf->OffsetFree);
404 ULONG ReturnSize = 0;
414 DPRINT1(
"RtlQueryProcessDebugInformation: Unable to commit %u\n", ReturnSize);
445 Buf->OffsetFree = Buf->OffsetFree + HSize;
457 Buf->OffsetFree = Buf->OffsetFree + LSize;
460 DPRINT(
"QueryProcessDebugInformation end\n");
461 DPRINT(
"QueryDebugInfo : 0x%lx\n", Buf->OffsetFree);
IN PUNICODE_STRING IN POBJECT_ATTRIBUTES ObjectAttributes
NTSTATUS NTAPI RtlpQueryRemoteProcessModules(HANDLE ProcessHandle, IN PRTL_PROCESS_MODULES Modules OPTIONAL, IN ULONG Size OPTIONAL, OUT PULONG ReturnedSize)
NTSTATUS NTAPI RtlDestroyQueryDebugBuffer(_In_ PRTL_DEBUG_INFORMATION Buf)
PRTL_DEBUG_INFORMATION NTAPI RtlCreateQueryDebugBuffer(_In_ ULONG Size, _In_ BOOLEAN EventPair)
PVOID NTAPI RtlpDebugBufferCommit(_Inout_ PRTL_DEBUG_INFORMATION Buffer, _In_ SIZE_T Size)
NTSTATUS NTAPI RtlQueryProcessDebugInformation(IN ULONG ProcessId, IN ULONG DebugInfoMask, IN OUT PRTL_DEBUG_INFORMATION Buf)
#define NT_SUCCESS(StatCode)
IN PFCB IN PFILE_OBJECT FileObject IN ULONG AllocationSize
IN PLARGE_INTEGER IN PLARGE_INTEGER PEPROCESS ProcessId
@ ProcessBasicInformation
NTSTATUS NTAPI LdrQueryProcessModuleInformation(_Out_writes_bytes_to_(Size, *ReturnedSize) PRTL_PROCESS_MODULES ModuleInformation, _In_ ULONG Size, _Out_opt_ PULONG ReturnedSize)
_In_ BOOL _In_ HANDLE hProcess
#define InitializeObjectAttributes(p, n, a, r, s)
_In_ HANDLE ProcessHandle
_In_ HANDLE _Outptr_result_bytebuffer_ ViewSize PVOID _In_ ULONG_PTR _In_ SIZE_T CommitSize
_In_ HANDLE _Outptr_result_bytebuffer_ ViewSize PVOID _In_ ULONG_PTR _In_ SIZE_T _Inout_opt_ PLARGE_INTEGER _Inout_ PSIZE_T ViewSize
#define RTL_DEBUG_QUERY_LOCKS
#define RTL_DEBUG_QUERY_HEAPS
struct _RTL_PROCESS_MODULE_INFORMATION RTL_PROCESS_MODULE_INFORMATION
#define RTL_DEBUG_QUERY_MODULES
struct _RTL_PROCESS_LOCKS * PRTL_PROCESS_LOCKS
struct _RTL_PROCESS_HEAPS RTL_PROCESS_HEAPS
struct _RTL_DEBUG_INFORMATION RTL_DEBUG_INFORMATION
struct _RTL_PROCESS_HEAPS * PRTL_PROCESS_HEAPS
struct _RTL_PROCESS_LOCKS RTL_PROCESS_LOCKS
#define RTL_DEBUG_QUERY_HEAP_TAGS
#define RTL_DEBUG_QUERY_HEAP_BLOCKS
NTSYSAPI NTSTATUS NTAPI RtlUnicodeStringToAnsiString(PANSI_STRING DestinationString, PUNICODE_STRING SourceString, BOOLEAN AllocateDestinationString)
#define PROCESS_ALL_ACCESS
#define NtCurrentProcess()
NTSTATUS NTAPI NtFreeVirtualMemory(IN HANDLE ProcessHandle, IN PVOID *UBaseAddress, IN PSIZE_T URegionSize, IN ULONG FreeType)
NTSTATUS NTAPI NtReadVirtualMemory(IN HANDLE ProcessHandle, IN PVOID BaseAddress, OUT PVOID Buffer, IN SIZE_T NumberOfBytesToRead, OUT PSIZE_T NumberOfBytesRead OPTIONAL)
NTSTATUS NTAPI NtAllocateVirtualMemory(IN HANDLE ProcessHandle, IN OUT PVOID *UBaseAddress, IN ULONG_PTR ZeroBits, IN OUT PSIZE_T URegionSize, IN ULONG AllocationType, IN ULONG Protect)
NTSTATUS NTAPI NtOpenProcess(OUT PHANDLE ProcessHandle, IN ACCESS_MASK DesiredAccess, IN POBJECT_ATTRIBUTES ObjectAttributes, IN PCLIENT_ID ClientId)
NTSTATUS NTAPI NtQueryInformationProcess(_In_ HANDLE ProcessHandle, _In_ PROCESSINFOCLASS ProcessInformationClass, _Out_ PVOID ProcessInformation, _In_ ULONG ProcessInformationLength, _Out_opt_ PULONG ReturnLength)
#define STATUS_ACCESS_VIOLATION
_CRT_RESTORE_GCC_WARNINGS _CRT_DISABLE_GCC_WARNINGS _Check_return_ _CRTIMP _CONST_RETURN char *__cdecl strrchr(_In_z_ const char *_Str, _In_ int _Ch)
PULONG MinorVersion OPTIONAL
UNICODE_STRING FullDllName
LIST_ENTRY InLoadOrderLinks
struct _LIST_ENTRY * Flink
LIST_ENTRY InLoadOrderModuleList
RTL_HEAP_INFORMATION Heaps[1]
RTL_PROCESS_LOCK_INFORMATION Locks[1]
#define CONTAINING_RECORD(address, type, field)
#define STATUS_INFO_LENGTH_MISMATCH
_Must_inspect_result_ _In_ WDFDEVICE _In_ PWDF_DEVICE_PROPERTY_DATA _In_ DEVPROPTYPE _In_ ULONG Size
_At_(*)(_In_ PWSK_CLIENT Client, _In_opt_ PUNICODE_STRING NodeName, _In_opt_ PUNICODE_STRING ServiceName, _In_opt_ ULONG NameSpace, _In_opt_ GUID *Provider, _In_opt_ PADDRINFOEXW Hints, _Outptr_ PADDRINFOEXW *Result, _In_opt_ PEPROCESS OwningProcess, _In_opt_ PETHREAD OwningThread, _Inout_ PIRP Irp Result)(Mem)) NTSTATUS(WSKAPI *PFN_WSK_GET_ADDRESS_INFO
_Out_ PCLIENT_ID ClientId