PpIrpAllocateDeviceUsageNotification
IRP *__fastcall PpIrpAllocateDeviceUsageNotification(INT64 a1){
INT64 v1;
IRP *result;
__int64 v4;
v1 = a1 + 40;
KeInitializeEvent((_KEVENT *)(a1 + 40), NotificationEvent, 0);
result = IoAllocateIrp(*(_BYTE *)(*(_QWORD *)a1 + 76i64), 0);
if( result )
{
*((_QWORD *)result + 24) = *(_QWORD *)(a1 + 16);
*((_QWORD *)result + 19) = KeGetCurrentThread();
*((_QWORD *)result + 9) = a1 + 24;
v4 = *((_QWORD *)result + 23);
*((_BYTE *)result + 64) = 0;
*((_QWORD *)result + 10) = v1;
*((_DWORD *)result + 4) = 4;
*((_QWORD *)result + 11) = 0i64;
*(_WORD *)(v4 - 72) = 5659;
*(_QWORD *)(v4 - 24) = *(_QWORD *)(a1 + 16);
*((_DWORD *)result + 12) = -1073741637;
*((_QWORD *)result + 3) = 0i64;
*(_BYTE *)(v4 - 64) = *(_BYTE *)(a1 + 12);
*(_DWORD *)(v4 - 56) = *(_DWORD *)(a1 + 8);
}
return result;
}Referenced by:
PiPagePathSetState
PipSendGuestAssignedNotification