ExpHpCompactSessionPools
INT64 __fastcall ExpHpCompactSessionPools(INT64 a1, UINT64 a2){
INT64 result;
void *i;
UINT64 v4;
__int64 v5;
__int64 v6;
__int64 v7;
unsigned __int64 v8;
__int64 v9;
__int64 v10;
unsigned __int64 v11;
KAPC_STATE ApcState;
memset(&ApcState, 0, sizeof(ApcState));
LODWORD(result) = MiGetNextSession(0i64, a2);
for( i = (void *)result; result; i = (void *)result )
{
if( MmAttachSession(i, &ApcState) >= 0 )
{
v5 = *(_QWORD *)(*(_QWORD *)(*((_QWORD *)KeGetCurrentThread() + 23) + 1368i64) + 672i64);
v6 = *(_QWORD *)(v5 + 14560);
if( v6 )
{
v7 = *(__int16 *)(v6 + 278);
v8 = *(_QWORD *)(v7 + v6 + 264) >> *(_BYTE *)(v6 + 267);
if( v8 <= 8 )
v8 = 8i64;
if( *(_QWORD *)(v7 + v6 + 272) + *(_QWORD *)(v7 + v6 + 280) > v8 )
RtlpHpHeapCompact(*(_QWORD *)(v5 + 14560));
}
v9 = *(_QWORD *)(v5 + 14568);
if( v9 )
{
v10 = *(__int16 *)(v9 + 278);
v11 = *(_QWORD *)(v10 + v9 + 264) >> *(_BYTE *)(v9 + 267);
if( v11 <= 8 )
v11 = 8i64;
if( *(_QWORD *)(v10 + v9 + 272) + *(_QWORD *)(v10 + v9 + 280) > v11 )
RtlpHpHeapCompact(*(_QWORD *)(v5 + 14568));
}
MmDetachSession(i, &ApcState);
}
LODWORD(result) = MiGetNextSession(i, v4);
}
return result;
}Referenced by:
ExpHpCompactionRoutine