NtResetEvent
NTSTATUS __stdcall NtResetEvent(PVOID EventHandle, INT64 *PreviousState){
KPROCESSOR_MODE v4;
NTSTATUS v5;
UINT64 v6;
UINT8 v7;
UINT8 v8;
NTSTATUS v9;
struct _DMA_ADAPTER *v10;
__int64 v12;
IRP *Object;
INT64 v14;
PVOID VirtualAddress;
PVOID v16;
LODWORD(v14) = 0;
v4 = *((_BYTE *)KeGetCurrentThread() + 562);
if( PreviousState && v4 )
{
v12 = 0x7FFFFFFF0000i64;
if( (unsigned __int64)PreviousState < 0x7FFFFFFF0000i64 )
v12 = (__int64)PreviousState;
*(_DWORD *)v12 = *(_DWORD *)v12;
}
VirtualAddress = 0i64;
v5 = ObReferenceObjectByHandle(EventHandle, 2u, (POBJECT_TYPE)ExEventObjectType, v4, &VirtualAddress, 0i64);
v9 = v5;
v10 = (struct _DMA_ADAPTER *)VirtualAddress;
LODWORD(VirtualAddress) = v5;
if( v5 < 0 )
{
if( v5 == -1073741788 )
{
if( ExCrossVmEventObjectType )
{
v16 = 0i64;
v9 = ObReferenceObjectByHandle(EventHandle, 2u, ExCrossVmEventObjectType, v4, &v16, 0i64);
v10 = (struct _DMA_ADAPTER *)v16;
LODWORD(VirtualAddress) = v9;
if( v9 >= 0 )
{
v9 = ExpResetCrossVmEvent((INT64)v16, (INT64)&v14);
LODWORD(VirtualAddress) = v9;
}
}
}
}
else
{
LODWORD(v14) = (unsigned int)KeResetEvent(v10, v6, v7, v8, Object);
}
if( v9 >= 0 && PreviousState )
*(_DWORD *)PreviousState = v14;
if( v10 )
HalPutDmaAdapter(v10);
return v9;
}Referenced by:
PfSnPrefetchFileMetadata