bool __fastcall KeIsThreadRunning(__int64 a1){ return *(_BYTE *)(a1 + 388) == 2 && *(_DWORD *)(a1 + 536) == *((_DWORD *)KeGetPcr() + 105); }