PspTrySetProcessPebThrottlingFlags

VOID __stdcall PspTrySetProcessPebThrottlingFlags(_EPROCESS *a1, CHAR a2){
  _PEB *Peb; 
  volatile signed __int32 *v5; 
  _EWOW64PROCESS *WoW64Process; 
  _KAPC_STATE ApcState; 

  memset(&ApcState, 0, sizeof(ApcState));
  KiStackAttachProcess(a1, 0i64, &ApcState);
  Peb = a1->Peb;
  if( Peb )
  {
    v5 = 0i64;
    WoW64Process = a1->WoW64Process;
    if( WoW64Process )
      v5 = (volatile signed __int32 *)WoW64Process->Peb;
    if( a2 )
    {
      _InterlockedOr((volatile signed __int32 *)&Peb->80, 0x60u);
      if( v5 )
        _InterlockedOr(v5 + 10, 0x60u);
    }
    else
    {
      _InterlockedAnd((volatile signed __int32 *)&Peb->80, 0xFFFFFFBF);
      if( v5 )
        _InterlockedAnd(v5 + 10, 0xFFFFFFBF);
    }
  }
  KiUnstackDetachProcess(&ApcState, 0i64);
}

Referenced by:

No references.