EmonRemoveProfileSource

NTSTATUS __stdcall EmonRemoveProfileSource(INT64 *a1){
  unsigned int v1; 
  NTSTATUS v2; 
  unsigned int ActiveProcessorCount; 
  unsigned int v6; 
  int *v7; 
  unsigned int v8; 
  unsigned __int64 v9; 
  char v10; 
  _HALP_ALLOC_CONTEXT *v11; 
  VOID *v12; 
  _HALP_ALLOC_CONTEXT *v13; 
  VOID *Memory; 

  v1 = *(_DWORD *)a1;
  v2 = 0;
  Memory = 0i64;
  if( v1 <= 0x24 )
    return -1073741637;
  ActiveProcessorCount = KeQueryActiveProcessorCountEx(0xFFFFu);
  v6 = 0;
  if( ActiveProcessorCount )
  {
    v7 = KiProcessorIndexToNumberMappingTable;
    while( (((unsigned __int64)a1[((unsigned int)*v7 >> 6) + 2] >> (*(_BYTE *)v7 & 0x3F)) & 1) == 0
         || !*(&CmpDummyThreadEvent + 1217) )
    {
LABEL_11:
      ++v6;
      ++v7;
      if( v6 >= ActiveProcessorCount )
        goto LABEL_12;
    }
    v8 = v6 * *(&CmpDummyThreadEvent + 1217);
    while( *(_DWORD *)(*(&CmpDummyThreadEvent + 620) + 16i64 * v8) == 3
         || *(_DWORD *)(*(&CmpDummyThreadEvent + 620) + 16i64 * v8 + 4) != v1 )
    {
      if( ++v8 - v6 * *(&CmpDummyThreadEvent + 1217) >= *(&CmpDummyThreadEvent + 1217) )
        goto LABEL_11;
    }
    return -2147483631;
  }
  else
  {
LABEL_12:
    v9 = (unsigned __int8)HalpAcquireHighLevelLock((UINT64 *)&CmpDummyThreadEvent + 610);
    v10 = HalpRemoveProfileSourceFromList((int *)a1, (_QWORD **)&CmpDummyThreadEvent + 612, &Memory);
    KxReleaseSpinLock((UINT64 *)&CmpDummyThreadEvent + 610);
    __writecr8(v9);
    if( v10 )
    {
      v12 = Memory;
      HalpMmAllocCtxFree(v11, *((VOID **)Memory + 25));
      HalpMmAllocCtxFree(v13, v12);
      --*(&CmpDummyThreadEvent + 1222);
    }
    else if( !Memory )
    {
      return -1073741823;
    }
    return v2;
  }
}

Referenced by:

No references.