IoDecrementKeepAliveCount
__int64 __fastcall IoDecrementKeepAliveCount(__int64 a1, __int64 a2){
UINT64 v2;
int v3;
unsigned int v4;
unsigned __int8 v5;
unsigned __int64 v6;
__int64 v7;
__int64 *v8;
int v10;
__int64 v11;
v10 = 0;
v11 = 0i64;
IopAdjustFileObjectKeepAliveCount(a1, a2, 0, &v10, &v11);
v4 = v3;
if( v3 >= 0 && !v10 )
{
KeAcquireSpinLockRaiseToDpc(&qword_140C45BF0, v2);
v6 = v5;
v7 = v11;
*(_QWORD *)(v11 + 48) = *(_QWORD *)&KUSER_SHARED_DATA.SystemTime.LowPart + 50000000i64;
--*(_DWORD *)(v7 + 32);
if( *(_BYTE *)(v7 + 16) )
{
if( qword_140C45C20 )
KeAlertThread(qword_140C45C20, 0);
}
else
{
v8 = (__int64 *)qword_140C45BE8;
if( *(PVOID **)qword_140C45BE8 != &qword_140C45BE0 )
__fastfail(3u);
*(_QWORD *)v7 = &qword_140C45BE0;
*(_QWORD *)(v7 + 8) = v8;
*v8 = v7;
qword_140C45BE8 = v7;
*(_BYTE *)(v7 + 16) = 1;
if( !byte_140C45C18 )
{
byte_140C45C18 = 1;
ExQueueWorkItem(&IopKeepAliveTracker, DelayedWorkQueue);
}
}
KxReleaseSpinLock(&qword_140C45BF0);
__writecr8(v6);
}
return v4;
}Referenced by:
No references.