KeWaitForSingleObject
NTSTATUS __fastcall KeWaitForSingleObject(UINT64 a1, INT8 dl0, INT8 a3, INT8 a4, INT64 Timeout){
_ETHREAD *CurrentThread;
unsigned __int8 CurrentIrql;
UINT8 WaitIrql;
struct _KPRCB *CurrentPrcb;
UINT8 v10;
$BA6907B96C27CBFB414D9A454222AF19 *v11;
int v12;
struct _KPRCB *v13;
_DWORD *v14;
struct _KPRCB *v15;
volatile __int64 WaitStatus;
int v17;
char v18;
UINT64 v19;
_KDUE_TIME_TYPE v20;
UINT64 v21;
_LIST_ENTRY *v22;
VOID *v23;
int v24;
unsigned __int8 v25;
unsigned __int64 v26;
_KWAIT_STATUS_REGISTER v27;
__int64 ThreadTimerDelay;
unsigned __int64 v30;
int v31;
int v32;
struct _KPRCB *v33;
volatile unsigned __int8 DpcRoutineActive;
int v35;
char v36;
_LIST_ENTRY *Blink;
_LIST_ENTRY *v38;
VOID *AbWaitObject;
_KWAIT_STATUS_REGISTER v40;
struct _KPRCB *v41;
_DWORD *SchedulerAssist;
struct _KPRCB *v43;
_DWORD *v44;
_DWORD *v45;
VOID *v46;
_BYTE *v47;
int v48;
_BYTE *v49;
_DWORD *v50;
int v51;
struct _KPRCB *v52;
_DWORD *v53;
int v54;
int v55[8];
__int64 *v56;
char v57;
unsigned __int8 v58;
UINT64 DueTime;
VOID *LockHandle;
UINT64 SpinCount;
UINT64 v62;
UINT64 v63;
_SINGLE_LIST_ENTRY ReadyList;
_SINGLE_LIST_ENTRY a2;
__int64 v66;
__int128 v67;
__int64 v68;
__int64 v69;
int Timeouta;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v66 = 0i64;
DueTime = 0i64;
v57 = 0;
LockHandle = 0i64;
v69 = 0i64;
v58 = _bittestandreset((signed __int32 *)&CurrentThread->Tcb.116, 2u);
if( !v58 )
{
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
CurrentThread->Tcb.WaitIrql = CurrentIrql;
}
if( Timeout )
{
if( *(int *)(Timeout + 4) >= 0 )
{
DueTime = *(_QWORD *)Timeout;
Timeouta = 1;
}
else
{
Timeouta = 2;
DueTime = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart
- KUSER_SHARED_DATA.InterruptTimeBias
- (*(_QWORD *)Timeout
+ CurrentThread->Tcb.RelativeTimerBias);
}
}
else
{
Timeouta = 0;
}
while( 1 )
{
WaitIrql = CurrentThread->Tcb.WaitIrql;
while( 1 )
{
CurrentThread->Tcb._bf_0 &= ~0x10u;
CurrentThread->Tcb.WaitRegister.Flags = 0;
CurrentThread->Tcb.WaitMode = a3;
if( a4 )
CurrentThread->Tcb._bf_0 |= 0x10u;
CurrentPrcb = KeGetCurrentPrcb();
LODWORD(SpinCount) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)&CurrentThread->Tcb.ThreadLock, 0i64) )
{
do
KeYieldProcessorEx(&SpinCount);
while( CurrentThread->Tcb.ThreadLock );
SchedulerAssist = CurrentPrcb->SchedulerAssist;
if( SchedulerAssist && CurrentPrcb->NestingLevel <= 1u )
++SchedulerAssist[6];
}
if( !CurrentThread->Tcb.ApcState.KernelApcPending || WaitIrql || CurrentThread->Tcb.SpecialApcDisable )
break;
KiReleaseThreadLockSafe((INT64)CurrentThread);
__writecr8(1ui64);
KiDeliverApc(0, 0i64, 0i64);
KeGetCurrentIrql();
__writecr8(2ui64);
CurrentThread->Tcb.WaitIrql = 0;
}
v10 = v58;
v11 = &CurrentThread->Tcb.320;
if( a4 )
{
if( CurrentThread->Tcb.Alerted[a3] )
{
CurrentThread->Tcb.Alerted[a3] = 0;
v48 = 257;
goto LABEL_97;
}
if( a3
&& (unsigned __int8 *)CurrentThread->Tcb.ApcState.ApcListHead[1].Flink != &CurrentThread->Tcb.ApcStateFill[16] )
{
CurrentThread->Tcb.ApcState.UserApcPendingAll |= 2u;
LABEL_96:
v48 = 192;
LABEL_97:
KiReleaseThreadLockSafe((INT64)CurrentThread);
KiCheckForThreadDispatch(KeGetCurrentPrcb(), WaitIrql);
LODWORD(WaitStatus) = v48;
return WaitStatus;
}
if( CurrentThread->Tcb.Alerted[0] )
{
CurrentThread->Tcb.Alerted[0] = 0;
v48 = 257;
goto LABEL_97;
}
}
else if( (CurrentThread->Tcb.ApcState.UserApcPendingAll & 2) != 0 && a3 )
{
goto LABEL_96;
}
v12 = 0;
CurrentThread->Tcb.WaitBlockFill6[68] = 5;
CurrentThread->Tcb.WaitReason = dl0;
CurrentThread->Tcb.WaitBlock[2].SpareLong = KUSER_SHARED_DATA.TickCount.LowPart;
CurrentThread->Tcb.ThreadLock = 0i64;
v13 = KeGetCurrentPrcb();
v14 = v13->SchedulerAssist;
if( v14 && v13->NestingLevel <= 1u )
--v14[6];
v15 = KeGetCurrentPrcb();
LODWORD(WaitStatus) = 0;
CurrentThread->Tcb.WaitBlock[0].WaitType = 1;
CurrentThread->Tcb.WaitBlockFill4[17] = 4;
CurrentThread->Tcb.WaitBlock[0].WaitKey = 0;
CurrentThread->Tcb.WaitBlock[0].Object = (void *)a1;
while( _interlockedbittestandset((volatile signed __int32 *)a1, 7u) )
{
do
{
++v12;
_mm_pause();
}
while( (*(_DWORD *)a1 & 0x80u) != 0 );
}
v17 = *(_DWORD *)(a1 + 4);
if( (*(_BYTE *)a1 & 0x7F) == 2 )
break;
if( v17 > 0 )
{
if( (*(_BYTE *)a1 & 7) == 1 )
{
*(_DWORD *)(a1 + 4) = 0;
}
else if( (*(_BYTE *)a1 & 0x7F) == 5 )
{
*(_DWORD *)(a1 + 4) = v17 - 1;
}
goto LABEL_30;
}
v18 = v57;
LABEL_18:
v19 = DueTime;
v20 = Timeouta;
v21 = DueTime;
if( Timeouta == 2 )
{
ThreadTimerDelay = CurrentThread->Tcb.ThreadTimerDelay;
v30 = *(_QWORD *)&KUSER_SHARED_DATA.InterruptTime.LowPart
- CurrentThread->Tcb.RelativeTimerBias
- KUSER_SHARED_DATA.InterruptTimeBias;
v21 = DueTime;
if( CurrentThread->Tcb.WaitMode
&& !CurrentThread->Tcb.WaitBlock[3].SpareLong
&& !CurrentThread->Tcb.WaitIrql
&& !CurrentThread->Tcb.ApcState.InProgressFlags
&& (_DWORD)ThreadTimerDelay )
{
v21 = DueTime + ThreadTimerDelay;
}
}
else
{
if( !Timeouta )
goto LABEL_20;
if( !DueTime )
goto LABEL_29;
v30 = *(_QWORD *)&KUSER_SHARED_DATA.SystemTime.LowPart;
}
if( v30 > v21 )
{
LABEL_29:
LODWORD(WaitStatus) = 258;
LABEL_30:
_InterlockedAnd((volatile signed __int32 *)a1, 0xFFFFFF7F);
CurrentThread->Tcb.WaitBlockFill6[68] = 2;
_InterlockedOr(v55, 0);
if( CurrentThread->Tcb.ThreadLock )
{
v43 = KeGetCurrentPrcb();
HIDWORD(v62) = 0;
v44 = v43->SchedulerAssist;
if( v44 && v43->NestingLevel <= 1u )
++v44[6];
while( _interlockedbittestandset64((volatile signed __int32 *)&CurrentThread->Tcb.ThreadLock, 0i64) )
{
do
KeYieldProcessorEx((UINT64 *)((char *)&v62 + 4));
while( CurrentThread->Tcb.ThreadLock );
}
KiReleaseThreadLockSafe((INT64)CurrentThread);
}
v26 = CurrentThread->Tcb.WaitIrql;
v27.Flags = (unsigned __int8)CurrentThread->Tcb.WaitRegister;
if( (v27.Flags & 0x38) != 0 )
{
if( (v27.Flags & 0x18) != 0 )
{
if( (v27.Flags & 8) != 0 )
_interlockedbittestandset((volatile signed __int32 *)&CurrentThread->Tcb.116 + 1, 0xCu);
a2.Next = 0i64;
v52 = KeGetCurrentPrcb();
LODWORD(v63) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)&v15->PrcbLock, 0i64) )
{
do
KeYieldProcessorEx(&v63);
while( v15->PrcbLock );
v53 = v52->SchedulerAssist;
if( v53 && v52->NestingLevel <= 1u )
{
v54 = v53[6] + 1;
v53[6] = v54;
}
}
if( !v15->NextThread )
KiSelectNextThread(v15, &a2);
_InterlockedAnd64((volatile signed __int64 *)&v15->PrcbLock, 0i64);
KiProcessDeferredReadyList(v15, &a2, v26);
}
else
{
KiCheckForThreadDispatch(v15, 1u);
KiDeliverApc(0, 0i64, 0i64);
__writecr8(0i64);
}
return WaitStatus;
}
LABEL_32:
if( v10 )
KiCheckForThreadDispatch(v15, v26);
else
__writecr8(v26);
return WaitStatus;
}
LABEL_20:
v22 = *(_LIST_ENTRY **)(a1 + 16);
if( v22->Flink != (_LIST_ENTRY *)(a1 + 8) )
goto LABEL_129;
v11->WaitBlock[0].WaitListEntry.Flink = (_LIST_ENTRY *)(a1 + 8);
CurrentThread->Tcb.WaitBlock[0].WaitListEntry.Blink = v22;
v22->Flink = (_LIST_ENTRY *)v11;
*(_QWORD *)(a1 + 16) = v11;
_InterlockedAnd((volatile signed __int32 *)a1, 0xFFFFFF7F);
CurrentThread->Tcb.WaitBlockCount = 1;
if( v18 )
{
v46 = KeAbPreAcquire((VOID *)a1, 0i64, 0i64);
v19 = DueTime;
v23 = v46;
v20 = Timeouta;
LockHandle = v46;
}
else
{
v23 = LockHandle;
}
if( v23 )
{
KeAbPreWait(v23);
v19 = DueTime;
v20 = Timeouta;
}
v56 = &v66;
KiCommitThreadWait(CurrentThread, CurrentThread->Tcb.WaitBlock, v20, v19);
LODWORD(WaitStatus) = v24;
if( v23 )
{
v47 = KeAbPreAcquire((VOID *)a1, v23, 0i64);
if( (WaitStatus & 0xFFFFFF7F) != 0 )
{
KeAbPostReleaseEx((VOID *)a1, v47);
LockHandle = 0i64;
}
else
{
v47[26] |= 1u;
LockHandle = v47;
}
}
CurrentThread->Tcb.AbWaitObject = 0i64;
if( (_DWORD)WaitStatus != 256 )
return WaitStatus;
v58 = 0;
v25 = KeGetCurrentIrql();
__writecr8(2ui64);
CurrentThread->Tcb.WaitIrql = v25;
}
v18 = (*(_BYTE *)(a1 + 48) & 2) != 0;
v57 = v18;
if( v17 <= 0 && (CurrentThread != *(_ETHREAD **)(a1 + 40) || *(_BYTE *)(a1 + 2) != v15->DpcRoutineActive) )
goto LABEL_18;
v31 = *(_DWORD *)(a1 + 4);
if( v31 == 0x80000000 )
{
_InterlockedAnd((volatile signed __int32 *)a1, 0xFFFFFF7F);
KiFastExitThreadWait(v15, &CurrentThread->Tcb, v10);
RtlRaiseStatus(-1073741423);
}
v32 = v31 - 1;
*(_DWORD *)(a1 + 4) = v32;
if( v32 )
goto LABEL_30;
CurrentThread->Tcb.WaitStatus = 0i64;
v33 = KeGetCurrentPrcb();
HIDWORD(SpinCount) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)&CurrentThread->Tcb.ThreadLock, 0i64) )
{
do
KeYieldProcessorEx((UINT64 *)((char *)&SpinCount + 4));
while( CurrentThread->Tcb.ThreadLock );
v45 = v33->SchedulerAssist;
if( v45 && v33->NestingLevel <= 1u )
++v45[6];
}
if( *(_BYTE *)(a1 + 49) )
--CurrentThread->Tcb.KernelApcDisable;
if( v15->CurrentThread == CurrentThread )
DpcRoutineActive = v15->DpcRoutineActive;
else
DpcRoutineActive = 0;
v68 = 0i64;
v35 = *(_DWORD *)a1;
v67 = 0i64;
LODWORD(v67) = v35;
BYTE2(v67) = DpcRoutineActive;
*(_DWORD *)a1 = v67;
v36 = *(_BYTE *)(a1 + 48);
*(_QWORD *)(a1 + 40) = CurrentThread;
if( (v36 & 1) != 0 )
{
*(_BYTE *)(a1 + 48) = v36 & 0xFE;
CurrentThread->Tcb.WaitStatus |= 0x80ui64;
v36 = *(_BYTE *)(a1 + 48);
}
if( (v36 & 2) != 0 )
CurrentThread->Tcb.AbWaitObject = (void *volatile)a1;
else
CurrentThread->Tcb.AbWaitObject = 0i64;
Blink = CurrentThread->Tcb.MutantListHead.Blink;
v38 = (_LIST_ENTRY *)(a1 + 24);
if( Blink->Flink != &CurrentThread->Tcb.MutantListHead )
LABEL_129:
__fastfail(3u);
v38->Flink = &CurrentThread->Tcb.MutantListHead;
*(_QWORD *)(a1 + 32) = Blink;
Blink->Flink = v38;
CurrentThread->Tcb.MutantListHead.Blink = v38;
_InterlockedAnd((volatile signed __int32 *)a1, 0xFFFFFF7F);
CurrentThread->Tcb.WaitBlockFill6[68] = 2;
CurrentThread->Tcb.ThreadLock = 0i64;
WaitStatus = CurrentThread->Tcb.WaitStatus;
AbWaitObject = CurrentThread->Tcb.AbWaitObject;
if( AbWaitObject )
{
CurrentThread->Tcb.AbWaitObject = 0i64;
v49 = KeAbPreAcquire(AbWaitObject, 0i64, 1ui64);
if( v49 )
v49[26] |= 1u;
}
v26 = CurrentThread->Tcb.WaitIrql;
v40.Flags = (unsigned __int8)CurrentThread->Tcb.WaitRegister;
if( (v40.Flags & 0x38) == 0 )
goto LABEL_32;
if( (v40.Flags & 0x18) != 0 )
{
if( (v40.Flags & 8) != 0 )
_interlockedbittestandset((volatile signed __int32 *)&CurrentThread->Tcb.116 + 1, 0xCu);
ReadyList.Next = 0i64;
v41 = KeGetCurrentPrcb();
LODWORD(v62) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)&v15->PrcbLock, 0i64) )
{
do
KeYieldProcessorEx(&v62);
while( v15->PrcbLock );
v50 = v41->SchedulerAssist;
if( v50 && v41->NestingLevel <= 1u )
{
v51 = v50[6] + 1;
v50[6] = v51;
}
}
if( !v15->NextThread )
KiSelectNextThread(v15, &ReadyList);
_InterlockedAnd64((volatile signed __int64 *)&v15->PrcbLock, 0i64);
KiProcessDeferredReadyList(v15, &ReadyList, v26);
}
else
{
KiCheckForThreadDispatch(v15, 1u);
KiDeliverApc(0, 0i64, 0i64);
__writecr8(0i64);
}
return WaitStatus;
}Referenced by:
AlpcpSignalAndWait
AlpcpWaitForPortReferences
AlpcpWaitForSingleObject
AnFwFadeCompletion
ArbArbiterHandler
ArbBuildAssignmentOrdering
CancelTimerCallbacksAndDeleteTimer
CcCanIWrite
CcDeleteSectionsForPartition
CcInitializeCacheMapEx
CcQueueLazyWriteScanThread
CcSetValidData
CcUnmapVacbArray
CcWaitForCurrentLazyWriterActivityInternal
CcWaitForUninitializeCacheMap
CcWriteBehind
CmCompleteRegistryInitialization
CmLoadAppKey
CmUnregisterMachineHiveLoadedNotification
CmpDoFileRead
CmpDummyThreadRoutine
CmpFileFlushAndPurge
CmpFinishSystemHivesLoad
CmpGetVolumeClusterSize
CmpLazyWriteWorker
CmpLoadHiveThread
CmpLockRegistryFreezeAware
CmpOpenHiveFile
CmpParseKey
CmpWaitOnHiveWriteQueue
DbgkpLkmdLaunchSnapApc
DbgkpQueueMessage
DbgkpSendErrorMessage
EmPowerPagingEnabled
EtwDereferenceSpinLockCounters
EtwReferenceSpinLockCounters
EtwSetPerformanceTraceInformation
EtwpAcquireLoggerContextByLoggerId
EtwpAcquireLoggerContextByLoggerName
EtwpCovSampCaptureContextStop
EtwpCovSampCaptureFlush
EtwpCrimsonProvEnableCallback
EtwpDisableTraceProviders
EtwpEnableDisableUMGL
EtwpKsrCallback
EtwpLogger
EtwpSampledProfileRunDown
EtwpSetPmcProfileSource
EtwpStartLogger
EtwpStartTrace
EtwpStopTrace
EtwpSynchronizeWithLogger
EtwpTraceThreadRundownWithStack
EtwpUpdateDisallowedGuids
EtwpUpdateGlobalGroupMasks
EtwpUpdatePerProcessTracing
ExRegisterBootDevice
ExSwapinWorkerThreads
ExTimedWaitForUnblockPushLock
ExUnregisterCallback
ExWaitForRundownProtectionReleaseCacheAware
ExfAcquirePushLockExclusiveEx
ExfAcquirePushLockSharedEx
ExfWaitForRundownProtectionRelease
ExpAcquireFastMutexContended
ExpUnblockPushLock
ExpWaitForBootDevices
ExpWaitForResource
ExpWorkQueueDestroy
FsFilterAllocateCompletionStack
FsRtlBalanceReads
FsRtlCancellableWaitForMultipleObjects
FsRtlDeregisterUncProvider
FsRtlGetDirectImageOriginalBase
FsRtlGetFileSize
FsRtlGetVirtualDiskNestingLevel
FsRtlIssueDeviceIoControl
FsRtlIssueFileNotificationFsctl
FsRtlKernelFsControlFile
FsRtlQueryCachedVdl
FsRtlQueryInformationFile
FsRtlQueryKernelEaFile
FsRtlSetFileSize
FsRtlSetKernelEaFile
FsRtlWaitForSmssEvent
FsRtlpPostStackOverflow
FsRtlpRegisterUncProvider
FsRtlpWaitOnIrp
HalGetAdapterV2
HalGetAdapterV3
HalpAcquireSecondaryIcEntryExclusive
HalpCallWakeAlarmDriver
HalpDynamicDeviceInterfaceNotification
HalpGetDynamicDevicePointer
HalpQueryAcpiRealTimeClock
HalpQueryAcpiWakeAlarmSystemPowerState
HalpQueryPccInterface
HalpSetAcpiRealTimeClock
IoCancelFileOpen
IoDisconnectInterrupt
IoRegisterFsRegistrationChangeMountAware
IoReleaseRemoveLockAndWaitEx
IoReplacePartitionUnit
IoReportTargetDeviceChange
IoSetInformation
IoShutdownSystem
IoSynchronousCallDriver
IoVerifyVolume
IoVolumeDeviceNameToGuidPath
IoVolumeDeviceToDosName
IoVolumeDeviceToGuidPath
IoWMIAllocateInstanceIds
IoWMIRegistrationControl
IoWMISetNotificationCallback
IopAcquireReleaseConnectLockInternal
IopAcquireReleaseDispatcherLock
IopAllocateBackpocketIrp
IopAllocateBootResources
IopAllocateReserveIrp
IopAssignBootDriveLetter
IopCancelAlertedRequest
IopCancelIrpsInThreadList
IopCloseFile
IopCompleteUnloadOrDelete
IopCreateArcName
IopCreateArcNamesCd
IopDeleteFile
IopDestroyActiveConnectBlock
IopFilterResourceRequirementsCall
IopFreeBandwidthContract
IopGetBootDiskInformation
IopGetFileInformation
IopGetSetObjectId
IopGetSetSecurityObject
IopGetVolumeId
IopInsertLegacyBusDeviceNode
IopInvalidateVolumesForDevice
IopIssueSystemEnvironmentRequest
IopLegacyResourceAllocation
IopLoadDriverImage
IopLoadFileSystemDriver
IopMountVolume
IopParseDevice
IopQueryConflictList
IopQueryXxxInformation
IopSendMessageToTrackService
IopSetRemoteLink
IopShutdownBaseFileSystems
IopSynchronousApiServiceTail
IopSynchronousCall
IopSynchronousServiceTail
IopUncacheInterfaceInformation
IopUnloadDriver
IopWaitForLockAlertable
IopWaitForSynchronousIo
IopWarmEjectDevice
IovpUnloadDriver
KeAbCrossThreadDelete
KeSwapProcessOrStack
KeWaitForMultipleObjects
KiAcquireSecondaryPassiveConnectLock
KiExpandKernelStackAndCalloutOnStackSegment
KiInvokeInterruptServiceRoutine
KiParkUmsThread
KiSchedulerApc
KiSignalWaitDisconnectLock
KiSynchronizePassiveInterruptExecution
LdrUnloadAlternateResourceModuleEx
LdrpGetAlternateResourceModuleHandleEx
LdrpGetFromMUIMemCache
LdrpSetAlternateResourceModuleHandle
MiApplyCommitDelay
MiCheckHoldFaultForHotPatch
MiContractWsSwapPageFileWorker
MiDrainCrossPartitionUsage
MiInSwapStore
MiIssuePageExtendRequest
MiIssueSynchronousFlush
MiMakeOutswappedPageResident
MiModifiedPageWriter
MiPfCompleteCoalescedIo
MiQueueSyncModifiedWriterApc
MiQueueWorkingSetRequest
MiReadImageHeaders
MiRetryNonPagedAllocation
MiStoreEvictThread
MiTrimUnusedPageFileRegionsWorker
MiWaitForAvailablePages
MiWaitForCollidedFaultComplete
MiWaitForFreePage
MiWaitForFreePagesToZero
MiWaitForInPageComplete
MiZeroAllPageFiles
MiZeroLargePageThread
MiZeroLargePages
MiZeroPageCalibrate
MiZeroPageFileFirstPage
MiZeroPageWrite
MmCleanProcessAddressSpace
MmDuplicateMemory
MmReleaseCommitForMemResetPages
MmStoreFlushOutstandingEvictions
NT_DISK::Control
NtGetMUIRegistryInfo
NtInitiatePowerAction
NtMapCMFModule
NtNotifyChangeMultipleKeys
NtNotifyChangeSession
NtQueryInformationFile
NtReleaseKeyedEvent
NtSetInformationFile
NtSignalAndWaitForSingleObject
NtStartProfile
NtStopProfile
NtWaitForDebugEvent
NtWaitForKeyedEvent
ObWaitForSingleObject
PfTCleanup
PfpScenCtxPrefetchWait
PiControlGetSetDeviceStatus
PiDrvDbLoadNode
PiIrpQueryRemoveDevice
PiPagePathSetState
PiQueueDeviceRequest
PipProcessDevNodeTree
PipSendGuestAssignedNotification
PnpAllocateResources
PnpCallDriverEntry
PnpDeviceCompletionQueueGetCompletedRequest
PnpDeviceCompletionQueueRemoveCompletedRequest
PnpDeviceEventWorker
PnpDisableWatchdog
PnpLockDeviceActionQueue
PnpLockMountableDevice
PnpProcessRebalance
PnpQueryInterface
PnpQueueQueryAndRemoveEvent
PnpReallocateResources
PnpRequestHwProfileChangeNotification
PnpSerializeBoot
PnpShutdownDevices
PnpStartDeviceNode
PnpWaitForEmptyDeviceActionQueue
PnpWaitForEmptyDeviceEventQueue
PnprInitiateReplaceOperation
PnprQuiesce
PnprQuiesceWorker
PoFxActivateComponent
PoUnregisterPowerSettingCallback
PopAcquireTransitionLock
PopBatteryRemove
PopBatteryWorker
PopBuildDeviceNotifyList
PopCaptureTimeOnProcZero
PopCheckPowerSourceAfterRtcWakeCancel
PopClearHiberFileSignature
PopDeactiveThermalRequest
PopDirectedDripsWorkerRoutine
PopDisableCoolingExtension
PopEndMirroring
PopExecuteOnTargetProcessors
PopFanRemove
PopFlushVolumes
PopFxActivateComponent
PopFxActivateDevice
PopFxIssueComponentPerfStateChanges
PopFxNotifySxTransitionState
PopFxProcessWorkPool
PopFxUnregisterDevice
PopFxUnregisterDeviceOrWait
PopGetWakeSource
PopGracefulShutdown
PopHaltDeviceIdle
PopIgnoreBatteryStatusChange
PopInitSystemSleeperThread
PopIrpWorker
PopIrpWorkerControl
PopPepUnregisterDevice
PopPepUpdateConstraints
PopPowerAggregatorNotifySuspendResume
PopReadPagesFromHiberFile
PopResizeHiberFile
PopRunMaximumIrpWorkers
PopSanityCheckHiberFile
PopSetSystemAwayMode
PopSetWatchdog
PopSleepDeviceList
PopThermalZoneRemove
PopTimeoutWakeTracking
PopTransitionSystemPowerStateEx
PopTransitionToSleep
PopWakeDeviceList
PpProfileBeginHardwareProfileTransition
PpmAcquireLock
PpmCheckPeriodicStart
PpmTryAcquireLock
PsCallEnclave
PsSetVmProcessorHostProcess
PsTerminateVsmEnclave
PsWaitForAllProcesses
PspExitThread
PspIumFreePartitionState
PspQueueDeferredWorkAndWait
PspTeardownPartition
PspUserThreadStartup
PspWaitForUsermodeExit
RawPerformDevIoCtrl
RawQueryFileSystemInformation
RawQueryFsSizeInfo
RtlDecompressBufferLZNT1
RtlDecompressFragmentLZNT1
RtlpRtlpCtWaitForWnfQuiescentWorker
SMKM_STORE::SmStCleanup
SMKM_STORE::SmStWorkerThreadStartThread
SMKM_STORE_MGR::SmCompressCtxBalancerThread
SMKM_STORE_MGR::SmCompressCtxCreateThread
SMKM_STORE_MGR::SmCompressCtxWorkerThread
SMKM_STORE_MGR::SmFeAddInitiate
SMKM_STORE_MGR::SmPerformStoreMaintenance
SMKM_STORE_MGR::SmStoreContentsRundown
SPCallServerHandleQueryPolicy
SPCallServerHandleWaitForDisplayWindow
SbpAddTransportToInstance
SbpStartLanman
SbpWaitForVmbus
SepRmCommandServerThread
SmKmIsVolumeIoPossible
SmKmSendDeviceControl
SmKmSendUsageNotification
SmKmStoreDeleteWhenEmpty
SmKmStoreFileCreate
SmKmStoreFileDelete
SmKmStoreFileGetExtents
SmKmStoreFileWriteHeader
SmKmStoreHelperCleanup
SmKmStoreHelperWaitForCommand
SmKmStoreHelperWorker
SmProcessResizeRequest
SmProcessStatsRequest
SmStoreCompressionStop
SmStorePhysicalRequestIssue
SmWaitForSyncIo
SmpFpWaitForResource
VfDriverLock
VfIrpSendSynchronousIrp
VhdiMountVhdFile
VhdiVerifyBootDisk
ViFilterDispatchPnp
ViPendingCompleteAfterWait
ViPendingWorkerThread
ViPoolDelayFreeTrimThreadRoutine
VrpWaitForDiffHiveEntryTransitionOwnerToLeave
VslpEnterIumSecureMode
WheaAttemptClearPoison
WheaAttemptPhysicalPageOffline
WheaLogInternalEvent
WheapEtwEnableCallback
WheapProcessWorkQueueItem
WmiQueryTraceProviderCount
WmipAddDataSource
WmipAddMofResource
WmipBuildTraceDeviceList
WmipDSCleanup
WmipDereferenceEvent
WmipDeregisterDevice
WmipDeregisterRegEntry
WmipDetermineInstanceBaseIndex
WmipDisableCollectOrEvent
WmipDisableCollectionForRemovedGuid
WmipEnableCollectOrEvent
WmipEnableCollectionForNewGuid
WmipEnumerateGuids
WmipEnumerateMofResources
WmipFindGEByGuid
WmipFindISinGEbyName
WmipFindMRByNames
WmipFindRegEntryByDevice
WmipFindRegEntryByProviderId
WmipForwardWmiIrp
WmipGetGuidObjectInstanceInfo
WmipGetSysIds
WmipIncludeStaticNames
WmipIsQuerySetGuid
WmipLegacyEtwCallback
WmipLegacyEtwWorker
WmipOpenBlock
WmipPrepareForWnodeAD
WmipPrepareWnodeSI
WmipProcessEvent
WmipQueryGuidInfo
WmipReceiveNotifications
WmipRegisterDevice
WmipSendEnableDisableRequest
WmipSendWmiIrpToTraceDeviceList
WmipSetTraceNotify
WmipUnreferenceEntry
WmipUpdateDataSource
WmipUpdateDeviceStackSize
WmipWaitForCollectionEnabled
sub_1405BC6E0
sub_140961F8C
sub_140963760