DbgkpLkmdLaunchSnapApc

INT64 __fastcall DbgkpLkmdLaunchSnapApc(INT64 a1, INT64 a2, INT64 a3, INT64 a4){
  char *PoolWithTag; 
  _KAPC *v9; 
  volatile signed __int32 *v11; 
  void *v12; 
  unsigned int v13; 
  union _LARGE_INTEGER Timeout; 
  PoolWithTag = (char *)ExAllocatePoolWithTag(NonPagedPoolNx, 0x90ui64, 0x704E534Bui64);
  v9 = (_KAPC *)PoolWithTag;
  if( !PoolWithTag )
    return 3221225495i64;
  *((_QWORD *)PoolWithTag + 13) = a2;
  v11 = (volatile signed __int32 *)(PoolWithTag + 88);
  *((_DWORD *)PoolWithTag + 22) = 0;
  v12 = PoolWithTag + 120;
  *((_QWORD *)PoolWithTag + 12) = a1;
  *((_QWORD *)PoolWithTag + 14) = a4;
  KeInitializeEvent((_KEVENT *)PoolWithTag + 5, NotificationEvent, 0);
  KeInitializeApc((INT64)v9, a3, 0i64, (INT64)DbgkpLkmdSnapThreadApc, 0i64, 0i64, 0, 0i64);
  if( KeInsertQueueApc(v9, v9, (PVOID)v11, 2i64) )
  {
    Timeout.QuadPart = -50000000i64;
    while( 1 )
    {
      v13 = KeWaitForSingleObject(v12, Executive, 0, 0, &Timeout);
      if( !v13 )
        break;
      if( v13 == 258 )
        *(_DWORD *)(a4 + 4) |= 0x8000u;
      if( !_InterlockedCompareExchange(v11, 1, 0) )
        return v13;
    }
    ExFreePoolWithTag(v9, 0x704E534Bu);
    return v13;
  }
  else
  {
    ExFreePoolWithTag(v9, 0x704E534Bu);
    *(_DWORD *)(a4 + 4) |= 0x4000u;
    return 3221225473i64;
  }
}

Referenced by:

DbgkpLkmdSnapThread