MmGetSystemRoutineAddress

NTSTATUS __stdcall MmGetSystemRoutineAddress(UNICODE_STRING *SystemRoutineName){
  UNICODE_STRING *i; 
  INT8 v3; 
  INT64 v4; 
  INT8 v5; 
  INT64 v6; 
  INT64 v8; 
  struct _STRING DestinationString; 
  DestinationString = 0i64;
  for( i = SystemRoutineName; RtlUnicodeStringToAnsiString(&DestinationString, i, 1u) < 0; i = SystemRoutineName )
    KeDelayExecutionThread(0, 0, (PLARGE_INTEGER)&MiShortTime);
  LODWORD(v4) = RtlFindExportedRoutineByName((PVOID)PsNtosImageBase, DestinationString.Buffer, v3);
  v6 = v4;
  if( !v4 )
  {
    LODWORD(v8) = RtlFindExportedRoutineByName(PsHalImageBase, DestinationString.Buffer, v5);
    v6 = v8;
  }
  RtlFreeAnsiString((_UNICODE_STRING *)&DestinationString);
  if( v6 && (int)MiMarkKernelCfgTarget(v6) < 0 )
    return 0;
  else
    return v6;
}

Referenced by:

HalpCmciLoadThresholdConfiguration