PopGetCurrentWakeInfos
__int64 __fastcall PopGetCurrentWakeInfos(_QWORD *a1, __int64 a2, INT64 a3){
VOID **v4;
unsigned int v5;
VOID **PoolWithTag;
volatile signed __int32 *v7;
__int64 i;
__int64 result;
_KLOCK_QUEUE_HANDLE LockHandle;
memset(&LockHandle, 0, sizeof(LockHandle));
v4 = 0i64;
KeAcquireInStackQueuedSpinLock((PKSPIN_LOCK)&stru_140C23628 + 355, &LockHandle);
v5 = *(&stru_140C23628 + 708);
if( *(&stru_140C23628 + 708) )
{
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, 8i64 * *(&stru_140C23628 + 708), 544040269i64);
v4 = PoolWithTag;
if( PoolWithTag )
{
v7 = (volatile signed __int32 *)*(&stru_140C23628 + 359);
for( i = 0i64;
v7 != (volatile signed __int32 *)((char *)&stru_140C23628 + 2872) && (unsigned int)i < v5;
i = (unsigned int)(i + 1) )
{
PoolWithTag[i] = (VOID *)v7;
_InterlockedIncrement(v7 + 4);
v7 = *(volatile signed __int32 **)v7;
}
}
else
{
v5 = 0;
}
}
KeReleaseInStackQueuedSpinLockFromDpcLevel(&LockHandle);
__writecr8(LockHandle.OldIrql);
result = v5;
*a1 = v4;
return result;
}Referenced by:
PopGetWakeSource