PnpAsynchronousCall

NTSTATUS __stdcall PnpAsynchronousCall(
        PDEVICE_OBJECT TargetDevice,
        PIO_STACK_LOCATION TopStackLocation,
        PIO_COMPLETION_ROUTINE CompletionRoutine,
        PVOID CompletionContext){
  __int64 v8; 
  _DEVICE_OBJECT *v9; 
  IRP *Irp; 
  IRP *v11; 
  __int64 v12; 
  __int128 v13; 
  _ETHREAD *CurrentThread; 
  __int128 v15; 
  __int64 v16; 
  __int128 v17; 
  __int128 v18; 
  __int64 v19; 
  NTSTATUS v20; 
  LODWORD(v8) = IoGetAttachedDeviceReferenceWithTag(TargetDevice, 0x69706E50u);
  v9 = (_DEVICE_OBJECT *)v8;
  Irp = IoAllocateIrp(*(_BYTE *)(v8 + 76), 0);
  v11 = Irp;
  if( Irp )
  {
    IovUtilWatermarkIrp(Irp, 1ui64);
    if( TargetDevice )
      v12 = *(_QWORD *)(*((_QWORD *)TargetDevice + 39) + 40i64);
    else
      v12 = 0i64;
    if( v12 )
      *(_QWORD *)(v12 + 72) = v11;
    *((_QWORD *)v11 + 7) = 0i64;
    v13 = *(_OWORD *)TopStackLocation;
    *((_DWORD *)v11 + 12) = -1073741637;
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    *((_QWORD *)v11 + 9) = 0i64;
    *((_QWORD *)v11 + 10) = 0i64;
    v15 = *((_OWORD *)TopStackLocation + 1);
    *((_QWORD *)v11 + 19) = CurrentThread;
    v16 = *((_QWORD *)v11 + 23);
    *((_BYTE *)v11 + 64) = 0;
    *(_OWORD *)(v16 - 72) = v13;
    v17 = *((_OWORD *)TopStackLocation + 2);
    *(_OWORD *)(v16 - 56) = v15;
    v18 = *((_OWORD *)TopStackLocation + 3);
    *(_OWORD *)(v16 - 40) = v17;
    *(_QWORD *)&v17 = *((_QWORD *)TopStackLocation + 8);
    *(_OWORD *)(v16 - 24) = v18;
    *(_QWORD *)(v16 - 8) = v17;
    v19 = *((_QWORD *)v11 + 23);
    *(_QWORD *)(v19 - 16) = CompletionRoutine;
    *(_QWORD *)(v19 - 8) = CompletionContext;
    *(_BYTE *)(v19 - 69) = -32;
    v20 = IofCallDriver(v9, v11);
  }
  else
  {
    v20 = -1073741670;
  }
  ObfDereferenceObjectWithTag(v9, 0x69706E50ui64);
  return v20;
}

Referenced by:

PiIrpQueryRemoveDevice
PnpSendIrp