KeCheckForTimer

VOID __stdcall KeCheckForTimer(PVOID BlockStart, UINT64 BlockSize){
  char *BugCheckParameter4; 
  unsigned int v4; 
  _KPRCB **v5; 
  unsigned int v6; 
  __int64 v7; 
  _QWORD **v8; 
  volatile signed __int32 *v9; 
  unsigned __int8 CurrentIrql; 
  _QWORD *v11; 
  char *v12; 
  ULONG_PTR v13; 
  unsigned __int64 v14; 
  ULONG_PTR v15; 
  unsigned int ActiveProcessorCount; 
  _KPRCB **v17; 
  __int64 v18; 
  unsigned int v19; 
  UINT64 SpinCount; 
  if( (KeTimerCheckFlags & 1) != 0 )
  {
    BugCheckParameter4 = (char *)BlockStart + BlockSize;
    v4 = 0;
    ActiveProcessorCount = KeQueryActiveProcessorCountEx(0xFFFFu);
    if( ActiveProcessorCount )
    {
      v5 = &KiProcessorBlock;
      v17 = &KiProcessorBlock;
      do
      {
        v6 = 0;
        v7 = 0i64;
        v18 = 0i64;
        do
        {
          v19 = 0;
          v8 = (_QWORD **)((char *)*v5 + 0x2000 * (unsigned __int64)v6 + 15176);
          v9 = (volatile signed __int32 *)((char *)*v5 + v7 + 15168);
          do
          {
            CurrentIrql = KeGetCurrentIrql();
            __writecr8(2ui64);
            LODWORD(SpinCount) = 0;
            while( _interlockedbittestandset64(v9, 0i64) )
            {
              do
                KeYieldProcessorEx(&SpinCount);
              while( *(_QWORD *)v9 );
            }
            v11 = *v8;
            if( *v8 != v8 )
            {
              v12 = (char *)BlockStart - 64;
              do
              {
                v13 = (ULONG_PTR)(v11 - 4);
                v11 = (_QWORD *)*v11;
                if( v13 > (unsigned __int64)v12 && v13 < (unsigned __int64)BugCheckParameter4 )
                  KeBugCheckEx(0xC7u, 0i64, v13, (ULONG_PTR)BlockStart, (ULONG_PTR)BugCheckParameter4);
                v14 = KiWaitAlways ^ _byteswap_uint64(v13 ^ __ROL8__(*(_QWORD *)(v13 + 48) ^ KiWaitNever, KiWaitNever));
                if( v14 )
                {
                  if( v14 > (unsigned __int64)v12 && v14 < (unsigned __int64)BugCheckParameter4 )
                    KeBugCheckEx(0xC7u, 1ui64, v14, (ULONG_PTR)BlockStart, (ULONG_PTR)BugCheckParameter4);
                  v15 = *(_QWORD *)(v14 + 24);
                  if( v15 >= (unsigned __int64)BlockStart && v15 < (unsigned __int64)BugCheckParameter4 )
                    KeBugCheckEx(0xC7u, 2ui64, v15, (ULONG_PTR)BlockStart, (ULONG_PTR)BugCheckParameter4);
                }
              }
              while( v11 != v8 );
            }
            _InterlockedAnd64((volatile signed __int64 *)v9, 0i64);
            __writecr8(CurrentIrql);
            v8 += 4;
            v9 += 8;
            ++v19;
          }
          while( v19 < 0x100 );
          ++v6;
          v5 = v17;
          v7 = v18 + 0x2000;
          v18 += 0x2000i64;
        }
        while( v6 < 2 );
        v5 = v17 + 1;
        ++v4;
        ++v17;
      }
      while( v4 < ActiveProcessorCount );
    }
  }
}

Referenced by:

ExFreeHeapPool
ExpFreePoolChecks
VerifierKeInitializeTimerEx