MiImageProtoChargedCommit
_BOOL8 __fastcall MiImageProtoChargedCommit(__int64 a1, unsigned __int64 a2){
unsigned int SessionId;
__int64 i;
unsigned __int64 v6;
unsigned int v7;
__int64 SubsectionDriverProtos;
__int64 *SharedProtosAtDpcLevel;
unsigned __int64 v11;
unsigned __int64 v12;
SessionId = MmGetSessionIdEx(*((_QWORD *)KeGetCurrentThread() + 23));
for( i = a1 + 128; ; i = *(_QWORD *)(i + 16) )
{
if( !i )
return 0i64;
v6 = *(_QWORD *)(i + 8);
v7 = (*(unsigned __int16 *)(i + 32) >> 1) & 0x1F;
if( a2 >= v6 && a2 < v6 + 8i64 * *(unsigned int *)(i + 44) )
return v7 >= 4;
if( (*(_BYTE *)(i + 34) & 2) == 0 || (*(_DWORD *)(a1 + 56) & 0x4000000) == 0 )
break;
SharedProtosAtDpcLevel = MiGetSharedProtosAtDpcLevel(a1, SessionId, i);
if( SharedProtosAtDpcLevel )
{
v11 = SharedProtosAtDpcLevel[9];
if( a2 >= v11 && a2 < v11 + 8i64 * *(unsigned int *)(i + 44) )
return v7 >= 4;
}
LABEL_6:
;
}
SubsectionDriverProtos = MiGetSubsectionDriverProtos((_QWORD *)i);
if( !SubsectionDriverProtos )
goto LABEL_6;
v12 = *(_QWORD *)(SubsectionDriverProtos + 72);
if( a2 < v12 || a2 >= v12 + 8i64 * *(unsigned int *)(i + 44) )
goto LABEL_6;
v7 = 4;
return v7 >= 4;
}Referenced by:
MiDeleteSystemPagableVm