MmRemoveImportOptimizationForDriverVerifier
INT64 __fastcall MmRemoveImportOptimizationForDriverVerifier(INT64 a1){
int v2;
int v3;
_SECTION *v4;
_OWORD *v5;
__int64 v6;
__int64 v7;
unsigned __int16 **v8;
__int64 v9;
_OWORD *v10;
unsigned int v11;
__int64 v12;
UINT8 *v13;
unsigned int v14;
UINT8 *v15;
unsigned __int8 CurrentIrql;
ULONG_PTR Context;
__int64 v19;
INT64 v20;
PVOID P[2];
__int64 result[8];
memset((INT64)result, 0i64);
v2 = 0;
Context = 0i64;
v19 = 0i64;
*(_OWORD *)P = 0i64;
MiInitializeDriverPatchState(a1, (INT64)result);
v20 = a1;
if( MmHasImageBeenImportOptimized() )
{
if( (MiFlags & 0x10000) != 0 )
{
v3 = -1073740641;
}
else
{
if( (unsigned int)KeIsNmiCallbackRegistered() )
goto LABEL_6;
v4 = *(_SECTION **)(a1 + 112);
v5 = 0i64;
if( v4 )
{
v6 = *(_QWORD *)(*((_QWORD *)MiSectionControlArea(v4) + 12) + 32i64);
if( v6 )
v5 = *(_OWORD **)(v6 + 96);
}
else
{
v5 = *(_OWORD **)(a1 + 296);
}
v7 = *(_DWORD *)(a1 + 64) >> 12;
if( !v5 )
{
LABEL_6:
v3 = -1073741637;
}
else
{
v3 = MiLockAndMapEntireDriver(a1, result, (MDL **)P);
if( v3 >= 0 )
{
HIDWORD(v19) = 8 * v7 + 56;
if( (_DWORD)v7 )
{
v8 = (unsigned __int16 **)v5 + 7;
v9 = (unsigned int)v7;
do
{
if( *v8 )
v2 += ((*v8)[1] >> 1) + ((*v8)[2] >> 1) + (**v8 >> 2);
++v8;
--v9;
}
while( v9 );
}
LODWORD(v10) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
P[1] = v10;
if( v10 )
{
v11 = 0;
*v10 = *v5;
v10[1] = v5[1];
v10[2] = v5[2];
*((_QWORD *)P[1] + 2) = 0i64;
*((_QWORD *)P[1] + 3) = 0i64;
*((_QWORD *)P[1] + 6) = (char *)P[1] + (unsigned int)(8 * v7 + 56);
if( (_DWORD)v7 )
{
v12 = 56i64;
do
{
v13 = *(UINT8 **)((char *)v5 + v12);
if( v13 )
{
v14 = *((unsigned __int16 *)v13 + 1) + 12 + *((unsigned __int16 *)v13 + 2) + *(unsigned __int16 *)v13;
v15 = (UINT8 *)(*((_QWORD *)P[1] + 6) + v11);
*(_QWORD *)((char *)P[1] + v12) = v15;
memmove(v15, v13, v14);
v11 += v14;
}
v12 += 8i64;
--v7;
}
while( v7 );
}
CurrentIrql = KeGetCurrentIrql();
__writecr8(0xCui64);
HIDWORD(Context) = KeQueryActiveProcessorCountEx(0xFFFFu);
LODWORD(Context) = HIDWORD(Context);
v3 = (unsigned int)KeIpiGenericCall((PKIPI_BROADCAST_WORKER)MmRemoveImportOptimizationWorker, &Context);
__writecr8(CurrentIrql);
}
else
{
v3 = -1073741670;
}
}
}
}
}
else
{
v3 = 0;
}
MiUnlockEntireDriver((UINT64 *)result, (INT64)P[0]);
if( P[1] )
ExFreePoolWithTag(P[1], 0);
return(unsigned int)v3;
}Referenced by:
VfDriverEnableVerifier