NtSetEvent
NTSTATUS __stdcall NtSetEvent(VOID *EventHandle, INT64 *PreviousState){
char PreviousMode;
__int64 v5;
NTSTATUS v6;
int v7;
_KEVENT *v8;
int v9;
PVOID v11;
PVOID v12;
INT64 v13;
PVOID Object;
LODWORD(v13) = 0;
PreviousMode = KeGetCurrentThread()->PreviousMode;
if( PreviousState && PreviousMode )
{
v5 = (__int64)PreviousState;
if( (unsigned __int64)PreviousState >= 0x7FFFFFFF0000i64 )
v5 = 0x7FFFFFFF0000i64;
*(_DWORD *)v5 = *(_DWORD *)v5;
}
Object = 0i64;
v6 = ObReferenceObjectByHandle(EventHandle, 2ui64, (_OBJECT_TYPE *)ExEventObjectType, PreviousMode, &Object, 0i64);
v7 = v6;
v8 = (_KEVENT *)Object;
v12 = Object;
LODWORD(Object) = v6;
if( v6 < 0 )
{
if( v6 == -1073741788 )
{
if( *(&WheapDeferredInternalLogsEventLock + 55) )
{
v11 = 0i64;
v7 = ObReferenceObjectByHandle(
EventHandle,
2ui64,
*(&WheapDeferredInternalLogsEventLock + 55),
PreviousMode,
&v11,
0i64);
v8 = (_KEVENT *)v11;
v12 = v11;
LODWORD(Object) = v7;
if( v7 >= 0 )
{
v7 = ExpSetCrossVmEvent((INT64)v11, (INT64)&v13);
LODWORD(Object) = v7;
}
}
}
v9 = v13;
}
else
{
v9 = KeSetEvent(v8, 1, 0);
LODWORD(v13) = v9;
}
if( v7 >= 0 && PreviousState )
*(_DWORD *)PreviousState = v9;
if( v8 )
HalPutDmaAdapter((PADAPTER_OBJECT)v8);
return v7;
}Referenced by:
SepAdtInitializeAuditingOptions