MiImageProtoChargedCommit

_BOOL8 __fastcall MiImageProtoChargedCommit(__int64 a1, unsigned __int64 a2){
  unsigned int SessionId; 
  __int64 i; 
  unsigned __int64 v6; 
  unsigned int v7; 
  __int64 SubsectionDriverProtos; 
  __int64 *SharedProtosAtDpcLevel; 
  unsigned __int64 v11; 
  unsigned __int64 v12; 
  SessionId = MmGetSessionIdEx(*((_QWORD *)KeGetCurrentThread() + 23));
  for( i = a1 + 128; ; i = *(_QWORD *)(i + 16) )
  {
    if( !i )
      return 0i64;
    v6 = *(_QWORD *)(i + 8);
    v7 = (*(unsigned __int16 *)(i + 32) >> 1) & 0x1F;
    if( a2 >= v6 && a2 < v6 + 8i64 * *(unsigned int *)(i + 44) )
      return v7 >= 4;
    if( (*(_BYTE *)(i + 34) & 2) == 0 || (*(_DWORD *)(a1 + 56) & 0x4000000) == 0 )
      break;
    SharedProtosAtDpcLevel = MiGetSharedProtosAtDpcLevel(a1, SessionId, i);
    if( SharedProtosAtDpcLevel )
    {
      v11 = SharedProtosAtDpcLevel[9];
      if( a2 >= v11 && a2 < v11 + 8i64 * *(unsigned int *)(i + 44) )
        return v7 >= 4;
    }
LABEL_6:
    ;
  }
  SubsectionDriverProtos = MiGetSubsectionDriverProtos((_QWORD *)i);
  if( !SubsectionDriverProtos )
    goto LABEL_6;
  v12 = *(_QWORD *)(SubsectionDriverProtos + 72);
  if( a2 < v12 || a2 >= v12 + 8i64 * *(unsigned int *)(i + 44) )
    goto LABEL_6;
  v7 = 4;
  return v7 >= 4;
}

Referenced by:

MiDeleteSystemPagableVm