MmRemoveImportOptimizationForDriverVerifier

INT64 __fastcall MmRemoveImportOptimizationForDriverVerifier(INT64 a1){
  int v2; 
  int v3; 
  _SECTION *v4; 
  _OWORD *v5; 
  __int64 v6; 
  __int64 v7; 
  unsigned __int16 **v8; 
  __int64 v9; 
  _OWORD *v10; 
  unsigned int v11; 
  __int64 v12; 
  UINT8 *v13; 
  unsigned int v14; 
  UINT8 *v15; 
  unsigned __int8 CurrentIrql; 
  ULONG_PTR Context; 
  __int64 v19; 
  INT64 v20; 
  PVOID P[2]; 
  __int64 result[8]; 
  memset((INT64)result, 0i64);
  v2 = 0;
  Context = 0i64;
  v19 = 0i64;
  *(_OWORD *)P = 0i64;
  MiInitializeDriverPatchState(a1, (INT64)result);
  v20 = a1;
  if( MmHasImageBeenImportOptimized() )
  {
    if( (MiFlags & 0x10000) != 0 )
    {
      v3 = -1073740641;
    }
    else
    {
      if( (unsigned int)KeIsNmiCallbackRegistered() )
        goto LABEL_6;
      v4 = *(_SECTION **)(a1 + 112);
      v5 = 0i64;
      if( v4 )
      {
        v6 = *(_QWORD *)(*((_QWORD *)MiSectionControlArea(v4) + 12) + 32i64);
        if( v6 )
          v5 = *(_OWORD **)(v6 + 96);
      }
      else
      {
        v5 = *(_OWORD **)(a1 + 296);
      }
      v7 = *(_DWORD *)(a1 + 64) >> 12;
      if( !v5 )
      {
LABEL_6:
        v3 = -1073741637;
      }
      else
      {
        v3 = MiLockAndMapEntireDriver(a1, result, (MDL **)P);
        if( v3 >= 0 )
        {
          HIDWORD(v19) = 8 * v7 + 56;
          if( (_DWORD)v7 )
          {
            v8 = (unsigned __int16 **)v5 + 7;
            v9 = (unsigned int)v7;
            do
            {
              if( *v8 )
                v2 += ((*v8)[1] >> 1) + ((*v8)[2] >> 1) + (**v8 >> 2);
              ++v8;
              --v9;
            }
            while( v9 );
          }
          LODWORD(v10) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
          P[1] = v10;
          if( v10 )
          {
            v11 = 0;
            *v10 = *v5;
            v10[1] = v5[1];
            v10[2] = v5[2];
            *((_QWORD *)P[1] + 2) = 0i64;
            *((_QWORD *)P[1] + 3) = 0i64;
            *((_QWORD *)P[1] + 6) = (char *)P[1] + (unsigned int)(8 * v7 + 56);
            if( (_DWORD)v7 )
            {
              v12 = 56i64;
              do
              {
                v13 = *(UINT8 **)((char *)v5 + v12);
                if( v13 )
                {
                  v14 = *((unsigned __int16 *)v13 + 1) + 12 + *((unsigned __int16 *)v13 + 2) + *(unsigned __int16 *)v13;
                  v15 = (UINT8 *)(*((_QWORD *)P[1] + 6) + v11);
                  *(_QWORD *)((char *)P[1] + v12) = v15;
                  memmove(v15, v13, v14);
                  v11 += v14;
                }
                v12 += 8i64;
                --v7;
              }
              while( v7 );
            }
            CurrentIrql = KeGetCurrentIrql();
            __writecr8(0xCui64);
            HIDWORD(Context) = KeQueryActiveProcessorCountEx(0xFFFFu);
            LODWORD(Context) = HIDWORD(Context);
            v3 = (unsigned int)KeIpiGenericCall((PKIPI_BROADCAST_WORKER)MmRemoveImportOptimizationWorker, &Context);
            __writecr8(CurrentIrql);
          }
          else
          {
            v3 = -1073741670;
          }
        }
      }
    }
  }
  else
  {
    v3 = 0;
  }
  MiUnlockEntireDriver((UINT64 *)result, (INT64)P[0]);
  if( P[1] )
    ExFreePoolWithTag(P[1], 0);
  return(unsigned int)v3;
}

Referenced by:

VfDriverEnableVerifier