MiQueryAddressSpan

unsigned __int64 __fastcall MiQueryAddressSpan(__int64 a1, unsigned __int64 a2, unsigned __int64 a3, ULONG_PTR a4){
  int v4; 
  unsigned __int64 v7; 
  unsigned __int64 v8; 
  unsigned __int64 v9; 
  INT64 v11; 
  unsigned __int8 v12; 
  int v13; 
  int v14; 
  unsigned __int64 v15; 
  int v17; 
  int v18; 
  int v19; 
  __int64 v20[3]; 
  __int16 v21; 
  __int16 v22; 
  int v23; 
  int v24; 
  v4 = 0;
  v7 = *(unsigned int *)(a4 + 28) | ((unsigned __int64)*(unsigned __int8 *)(a4 + 33) << 32);
  v23 = 0;
  v8 = a3;
  v18 = 0;
  v9 = ((v7 << 12) | 0xFFF) + 1;
  v20[0] = 0i64;
  v17 = 0;
  v24 = 0;
  v19 = 0;
  v21 = 0;
  v22 = 0;
  if( a3 > v9 || !a3 )
    v8 = v9;
  v11 = *((_QWORD *)KeGetCurrentThread() + 23) + 1664i64;
  v12 = MiLockWorkingSetShared(v11);
  *(_DWORD *)(a1 + 32) = MiQueryAddressState(a2, v8 - 1, v12, a4, 0i64, &v23, &v24, &v21, v20, &v17);
  if( v23 )
  {
    v13 = MmProtectToValue[v23];
    *(_DWORD *)(a1 + 36) = v13;
    v14 = v24 | v13;
  }
  else
  {
    v14 = 0;
  }
  *(_DWORD *)(a1 + 36) = v14;
  v15 = v20[0];
  *(_WORD *)(a1 + 20) = v21;
  while( v15 < v8 )
  {
    if( (unsigned int)MiQueryAddressState(v15, v8 - 1, v12, a4, a1, &v18, &v19, &v22, v20, &v17) != *(_DWORD *)(a1 + 32)
      || v18 != v23
      || v22 != v21
      || v19 != v24 )
    {
      break;
    }
    v15 = v20[0];
    if( (++v4 & 0x1F) == 0 && MiWorkingSetIsContended(v11) || KeShouldYieldProcessor() )
    {
      MiUnlockWorkingSetShared(v11, v12);
      MiLockWorkingSetShared(v11);
    }
  }
  MiUnlockWorkingSetShared(v11, v12);
  return v15;
}

Referenced by:

MmQueryVirtualMemory