PnpAsynchronousCall
NTSTATUS __stdcall PnpAsynchronousCall(
PDEVICE_OBJECT TargetDevice,
PIO_STACK_LOCATION TopStackLocation,
PIO_COMPLETION_ROUTINE CompletionRoutine,
PVOID CompletionContext){
__int64 v8;
_DEVICE_OBJECT *v9;
IRP *Irp;
IRP *v11;
__int64 v12;
__int128 v13;
_ETHREAD *CurrentThread;
__int128 v15;
__int64 v16;
__int128 v17;
__int128 v18;
__int64 v19;
NTSTATUS v20;
LODWORD(v8) = IoGetAttachedDeviceReferenceWithTag(TargetDevice, 0x69706E50u);
v9 = (_DEVICE_OBJECT *)v8;
Irp = IoAllocateIrp(*(_BYTE *)(v8 + 76), 0);
v11 = Irp;
if( Irp )
{
IovUtilWatermarkIrp(Irp, 1ui64);
if( TargetDevice )
v12 = *(_QWORD *)(*((_QWORD *)TargetDevice + 39) + 40i64);
else
v12 = 0i64;
if( v12 )
*(_QWORD *)(v12 + 72) = v11;
*((_QWORD *)v11 + 7) = 0i64;
v13 = *(_OWORD *)TopStackLocation;
*((_DWORD *)v11 + 12) = -1073741637;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
*((_QWORD *)v11 + 9) = 0i64;
*((_QWORD *)v11 + 10) = 0i64;
v15 = *((_OWORD *)TopStackLocation + 1);
*((_QWORD *)v11 + 19) = CurrentThread;
v16 = *((_QWORD *)v11 + 23);
*((_BYTE *)v11 + 64) = 0;
*(_OWORD *)(v16 - 72) = v13;
v17 = *((_OWORD *)TopStackLocation + 2);
*(_OWORD *)(v16 - 56) = v15;
v18 = *((_OWORD *)TopStackLocation + 3);
*(_OWORD *)(v16 - 40) = v17;
*(_QWORD *)&v17 = *((_QWORD *)TopStackLocation + 8);
*(_OWORD *)(v16 - 24) = v18;
*(_QWORD *)(v16 - 8) = v17;
v19 = *((_QWORD *)v11 + 23);
*(_QWORD *)(v19 - 16) = CompletionRoutine;
*(_QWORD *)(v19 - 8) = CompletionContext;
*(_BYTE *)(v19 - 69) = -32;
v20 = IofCallDriver(v9, v11);
}
else
{
v20 = -1073741670;
}
ObfDereferenceObjectWithTag(v9, 0x69706E50ui64);
return v20;
}Referenced by:
PiIrpQueryRemoveDevice
PnpSendIrp