NtResetEvent

NTSTATUS __stdcall NtResetEvent(PVOID EventHandle, INT64 *PreviousState){
  KPROCESSOR_MODE v4; 
  NTSTATUS v5; 
  UINT64 v6; 
  UINT8 v7; 
  UINT8 v8; 
  NTSTATUS v9; 
  struct _DMA_ADAPTER *v10; 
  __int64 v12; 
  IRP *Object; 
  INT64 v14; 
  PVOID VirtualAddress; 
  PVOID v16; 
  LODWORD(v14) = 0;
  v4 = *((_BYTE *)KeGetCurrentThread() + 562);
  if( PreviousState && v4 )
  {
    v12 = 0x7FFFFFFF0000i64;
    if( (unsigned __int64)PreviousState < 0x7FFFFFFF0000i64 )
      v12 = (__int64)PreviousState;
    *(_DWORD *)v12 = *(_DWORD *)v12;
  }
  VirtualAddress = 0i64;
  v5 = ObReferenceObjectByHandle(EventHandle, 2u, (POBJECT_TYPE)ExEventObjectType, v4, &VirtualAddress, 0i64);
  v9 = v5;
  v10 = (struct _DMA_ADAPTER *)VirtualAddress;
  LODWORD(VirtualAddress) = v5;
  if( v5 < 0 )
  {
    if( v5 == -1073741788 )
    {
      if( ExCrossVmEventObjectType )
      {
        v16 = 0i64;
        v9 = ObReferenceObjectByHandle(EventHandle, 2u, ExCrossVmEventObjectType, v4, &v16, 0i64);
        v10 = (struct _DMA_ADAPTER *)v16;
        LODWORD(VirtualAddress) = v9;
        if( v9 >= 0 )
        {
          v9 = ExpResetCrossVmEvent((INT64)v16, (INT64)&v14);
          LODWORD(VirtualAddress) = v9;
        }
      }
    }
  }
  else
  {
    LODWORD(v14) = (unsigned int)KeResetEvent(v10, v6, v7, v8, Object);
  }
  if( v9 >= 0 && PreviousState )
    *(_DWORD *)PreviousState = v14;
  if( v10 )
    HalPutDmaAdapter(v10);
  return v9;
}

Referenced by:

PfSnPrefetchFileMetadata