ExpGetKernelDataProtection

__int64 __fastcall ExpGetKernelDataProtection(_EX_PUSH_LOCK *a1, _OWORD *a2){
  _EX_PUSH_LOCK *v4; 
  _OWORD **bf_0; 
  _OWORD *v6; 
  int v8; 
  _OWORD *v9; 

  if( !a2 )
    return 3221225485i64;
  v4 = a1 + 5878;
  ExAcquirePushLockSharedEx(a1 + 5878, 0i64);
  bf_0 = (_OWORD **)a1[5877]._bf_0;
  if( bf_0 )
  {
    v9 = *bf_0;
    v8 = sub_14061BF48((__int64 *)&v9);
    if( v8 >= 0 )
    {
      v6 = v9;
      *a2 = *v9;
      a2[1] = v6[1];
      a2[2] = v6[2];
    }
  }
  else
  {
    v8 = -1073741275;
  }
  if( _InterlockedCompareExchange64(&v4->_bf_0, 0i64, 17i64) != 17 )
    ExfReleasePushLockShared(v4);
  KeAbPostRelease(v4);
  return(unsigned int)v8;
}

Referenced by:

ExpGetLicenseTamperState
sub_14094D610