ViIrpCheckKernelAddressForIrp
void __fastcall ViIrpCheckKernelAddressForIrp(ULONG_PTR BugCheckParameter2, ULONG_PTR BugCheckParameter3, __int64 a3){
_EPROCESS *v5;
UINT64 v6;
if( BugCheckParameter3 - 1 <= 0x7FFFFFFEFFFDi64 )
{
v5 = (_EPROCESS *)*((_QWORD *)KeGetCurrentThread() + 23);
if( v5 != (_EPROCESS *)PsInitialSystemProcess
&& v5 != PsIdleProcess
&& (!a3 || (unsigned int)VfTargetDriversIsEnabled(*(VOID **)(a3 + 176))) )
{
VerifierBugCheckIfAppropriate(0xC4ui64, 0xE2ui64, BugCheckParameter2, BugCheckParameter3, 0i64, v6);
}
}
}Referenced by:
VfBeforeCallDriver