RtlpAllocateAtom
VOID *__stdcall RtlpAllocateAtom(UINT64 NumberOfBytes, UINT64 Tag){
UINT64 v2;
ULONG v3;
_QWORD *PoolWithTag;
INT64 v5;
v2 = NumberOfBytes + 16;
v3 = Tag;
if( NumberOfBytes + 16 < NumberOfBytes )
return 0i64;
PoolWithTag = ExAllocatePoolWithTag(PagedPool, v2, (unsigned int)Tag);
if( PoolWithTag )
{
v5 = PsChargeSharedPoolQuota(*((_QWORD *)KeGetCurrentThread() + 23), v2, 0i64);
*PoolWithTag = v5;
if( v5 )
{
PoolWithTag[1] = v2;
PoolWithTag += 2;
}
else
{
ExFreePoolWithTag(PoolWithTag, v3);
return 0i64;
}
}
return PoolWithTag;
}Referenced by:
RtlCreateAtomTableEx
RtlpAllocateAtomTableEntry
RtlpLookupOrCreateLowBox