SmKmSendUsageNotification

NTSTATUS __stdcall SmKmSendUsageNotification(PIRP Irp, PFILE_OBJECT FileObject, UINT64 Remove){
  int v3; 
  _IO_STACK_LOCATION *CurrentStackLocation; 
  UINT64 v7; 
  _IO_STACK_LOCATION *v8; 
  NTSTATUS result; 
  char Object[40]; 

  v3 = Remove;
  KeInitializeEvent((INT64)Object, 0, 0);
  CurrentStackLocation = Irp->Tail.CurrentStackLocation;
  LODWORD(v7) = IoGetRelatedDeviceObject((INT64)FileObject);
  *(_WORD *)&CurrentStackLocation[-1].MajorFunction = 5659;
  CurrentStackLocation[-1].Parameters.Options = 1;
  CurrentStackLocation[-1].FileObject = FileObject;
  LOBYTE(CurrentStackLocation[-1].Parameters.SecurityContext) = v3 == 0;
  v8 = Irp->Tail.CurrentStackLocation;
  Irp->IoStatus.Status = -1073741637;
  v8[-1].CompletionRoutine = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *, void *))SmKmGenericCompletion;
  v8[-1].Context = Object;
  v8[-1].Control = -32;
  result = IofCallDriver(v7, (UINT64)Irp);
  if( result == 259 )
  {
    KeWaitForSingleObject((UINT64)Object, 0, 0, 0, 0i64);
    return Irp->IoStatus.Status;
  }
  return result;
}

Referenced by:

SmKmFileInfoCleanup
SmKmIsVolumeIoPossible