ExpGetKernelDataProtection
__int64 __fastcall ExpGetKernelDataProtection(__int64 a1, _OWORD *a2){
INT64 *v4;
INT64 *v5;
INT64 v6;
int v8;
INT64 a1a;
if( !a2 )
return 3221225485i64;
v4 = (INT64 *)(a1 + 47024);
ExAcquirePushLockSharedEx(a1 + 47024, 0i64);
v5 = *(INT64 **)(a1 + 47016);
if( v5 )
{
a1a = *v5;
v8 = sub_14061BF48(&a1a);
if( v8 >= 0 )
{
v6 = a1a;
*a2 = *(_OWORD *)a1a;
a2[1] = *(_OWORD *)(v6 + 16);
a2[2] = *(_OWORD *)(v6 + 32);
}
}
else
{
v8 = -1073741275;
}
if( _InterlockedCompareExchange64(v4, 0i64, 17i64) != 17 )
ExfReleasePushLockShared(v4);
KeAbPostRelease(v4);
return(unsigned int)v8;
}Referenced by:
ExpGetLicenseTamperState
sub_14094D610