MiSnapDriverRange

__int64 __fastcall MiSnapDriverRange(__int64 a1, unsigned int a2, char a3, __int64 a4, char **a5, char **a6){
  unsigned int v6; 
  void *v10; 
  IMAGE_NT_HEADERS *v11; 
  unsigned __int64 v12; 
  unsigned __int64 SectionAlignment; 
  unsigned int NumberOfSections; 
  unsigned __int64 v15; 
  __int64 SizeOfOptionalHeader; 
  char *PteAddress; 
  char *v18; 
  __int64 *v19; 
  unsigned int v20; 
  int v21; 
  unsigned int v22; 
  BOOL v23; 
  bool v24; 
  __int64 v25; 
  MMPTE *v26; 
  unsigned __int64 v27; 
  __int16 v28; 
  PVOID v29; 
  unsigned int v30; 
  char *v31; 
  unsigned __int64 v33; 
  unsigned int v34; 
  unsigned int v35; 
  unsigned __int64 v36; 
  void *v38; 
  IMAGE_NT_HEADERS *v40; 
  __int64 v41; 
  __int64 v42; 
  int v43; 
  __int128 v44; 
  __int64 v45; 
  int v46; 
  v6 = 0;
  v42 = 0i64;
  *a5 = 0i64;
  v44 = 0i64;
  *a6 = 0i64;
  v10 = *(void **)(a1 + 48);
  v45 = 0i64;
  v38 = v10;
  v11 = RtlImageNtHeader(v10);
  v40 = v11;
  v12 = a4 - (_QWORD)v10;
  SectionAlignment = v11->OptionalHeader.SectionAlignment;
  NumberOfSections = v11->FileHeader.NumberOfSections;
  v15 = (unsigned int)SectionAlignment;
  v36 = a4 - (_QWORD)v10;
  if( SectionAlignment > 0x1000 )
    v15 = 4096i64;
  v35 = v11->FileHeader.NumberOfSections;
  if( a2 > NumberOfSections )
    return 0i64;
  SizeOfOptionalHeader = v11->FileHeader.SizeOfOptionalHeader;
  v41 = SizeOfOptionalHeader;
  PteAddress = 0i64;
  v46 = 0x40000000;
  v18 = 0i64;
  DWORD1(v44) = SizeOfOptionalHeader + 40 * NumberOfSections + (_DWORD)v11 + 24 - (_DWORD)v10;
  v43 = DWORD1(v44);
  while( 1 )
  {
    if( a2 )
      v19 = (__int64 *)((char *)&v11->OptionalHeader + 40 * a2 + SizeOfOptionalHeader - 40);
    else
      v19 = &v42;
    v20 = *((_DWORD *)v19 + 4);
    if( v20 < *((_DWORD *)v19 + 2) )
      v20 = *((_DWORD *)v19 + 2);
    v34 = v20;
    if( !a4 )
      break;
    v33 = *((unsigned int *)v19 + 3);
    if( v12 < v33 || v12 >= v20 + (unsigned int)v33 )
      goto LABEL_18;
    if( (a3 & 0x40) != 0 && (*((_DWORD *)v19 + 9) & 0x2000000) != 0 )
      return 0i64;
LABEL_24:
    v25 = *((unsigned int *)v19 + 3);
    if( !PteAddress )
      PteAddress = (char *)MiGetPteAddress((PVOID)(((unsigned __int64)v10 + v25 + 4095) & 0xFFFFFFFFFFFFF000ui64));
    v26 = MiGetPteAddress((PVOID)(-(__int64)v15 & ((unsigned __int64)v10 + v15 + v20 + v25 - 1)));
    v18 = (char *)v26;
    if( (v28 & 0xFFF) == 0 || (a3 & 0xC) == 0 || v15 >= 0x1000 )
      v18 = (char *)v26 - 8;
    if( v27 > 0x1000 )
      goto LABEL_18;
LABEL_19:
    if( ++a2 > NumberOfSections )
    {
      if( PteAddress )
      {
        v30 = *((_DWORD *)v19 + 4);
        if( v30 < *((_DWORD *)v19 + 2) )
          v30 = *((_DWORD *)v19 + 2);
        v31 = (char *)MiGetPteAddress((PVOID)(((-(__int64)v15 & ((unsigned __int64)v10
                                                               + v15
                                                               + v30
                                                               + *((unsigned int *)v19 + 3)
                                                               - 1))
                                             + 4095) & 0xFFFFFFFFFFFFF000ui64))
            - 8;
        if( PteAddress <= v31 )
        {
          *a5 = PteAddress;
          *a6 = v31;
        }
      }
      return 0i64;
    }
    v11 = v40;
    SizeOfOptionalHeader = v41;
  }
  if( (a3 & 8) != 0 )
  {
    v21 = (*((_DWORD *)v19 + 9) & 0xE0000000) != 0;
    goto LABEL_23;
  }
  if( (a3 & 1) != 0 )
  {
    v21 = MmImageSectionPagable(v19, (INT64 *)v11);
    goto LABEL_22;
  }
  if( (a3 & 4) != 0 )
  {
    v22 = *((_DWORD *)v19 + 9) & 0xE0000000;
    v23 = MmImageSectionPagable(v19, (INT64 *)v11);
    v24 = v22 != 0;
    v10 = v38;
    v21 = v24 && !v23;
LABEL_22:
    NumberOfSections = v35;
    v20 = v34;
    v12 = v36;
    goto LABEL_23;
  }
  if( (a3 & 0x10) != 0 )
  {
    v21 = *((_DWORD *)v19 + 9) & 0x20000000;
    goto LABEL_23;
  }
  if( (a3 & 0x20) != 0 )
  {
    if( *(_BYTE *)v19 != 80
      || *((_BYTE *)v19 + 1) != 65
      || *((_BYTE *)v19 + 2) != 71
      || *((_BYTE *)v19 + 3) != 69
      || *((_BYTE *)v19 + 4) != 75
      || *((_BYTE *)v19 + 5) != 68 )
    {
      goto LABEL_18;
    }
    goto LABEL_24;
  }
  if( !*(_DWORD *)v19 && v19 != &v42 )
    return 0i64;
  v21 = *((_DWORD *)v19 + 9) & 0x2000000;
  if( (*(_DWORD *)(a1 + 104) & 0x4000000) != 0 && *(_DWORD *)v19 == 1414090313 )
    v21 = 0;
  if( v21 )
  {
    v29 = *(PVOID *)(a1 + 48);
    if( (v29 == (PVOID)PsNtosImageBase || v29 == PsHalImageBase) && MiIsKernelHalPadSection((INT64)v19) )
      v21 = 0;
LABEL_23:
    if( !v21 )
      goto LABEL_18;
    goto LABEL_24;
  }
LABEL_18:
  if( !PteAddress )
    goto LABEL_19;
  if( PteAddress > v18 )
  {
    PteAddress = 0i64;
    goto LABEL_19;
  }
  *a5 = PteAddress;
  *a6 = v18;
  if( a2 + 1 <= NumberOfSections )
    return a2 + 1;
  return v6;
}

Referenced by:

MiBackSingleImageWithPagefile
MiCheckForDiscardableLongJumpTable
MiDisablePagingOfDriver
MiEnablePagingOfDriver
MiFreeDriverInitialization
MiHandleDriverNonPagedSections
MiMarkKernelImageCfgBits
MmDiscardDriverSection