IoDecrementKeepAliveCount

__int64 __fastcall IoDecrementKeepAliveCount(__int64 a1, __int64 a2){
  UINT64 v2; 
  int v3; 
  unsigned int v4; 
  unsigned __int8 v5; 
  unsigned __int64 v6; 
  __int64 v7; 
  __int64 *v8; 
  int v10; 
  __int64 v11; 
  v10 = 0;
  v11 = 0i64;
  IopAdjustFileObjectKeepAliveCount(a1, a2, 0, &v10, &v11);
  v4 = v3;
  if( v3 >= 0 && !v10 )
  {
    KeAcquireSpinLockRaiseToDpc(&qword_140C45BF0, v2);
    v6 = v5;
    v7 = v11;
    *(_QWORD *)(v11 + 48) = *(_QWORD *)&KUSER_SHARED_DATA.SystemTime.LowPart + 50000000i64;
    --*(_DWORD *)(v7 + 32);
    if( *(_BYTE *)(v7 + 16) )
    {
      if( qword_140C45C20 )
        KeAlertThread(qword_140C45C20, 0);
    }
    else
    {
      v8 = (__int64 *)qword_140C45BE8;
      if( *(PVOID **)qword_140C45BE8 != &qword_140C45BE0 )
        __fastfail(3u);
      *(_QWORD *)v7 = &qword_140C45BE0;
      *(_QWORD *)(v7 + 8) = v8;
      *v8 = v7;
      qword_140C45BE8 = v7;
      *(_BYTE *)(v7 + 16) = 1;
      if( !byte_140C45C18 )
      {
        byte_140C45C18 = 1;
        ExQueueWorkItem(&IopKeepAliveTracker, DelayedWorkQueue);
      }
    }
    KxReleaseSpinLock(&qword_140C45BF0);
    __writecr8(v6);
  }
  return v4;
}

Referenced by:

No references.