KiMcheckFastForward
NTSTATUS __stdcall KiMcheckFastForward(PVOID BugCheckParameter4){
char v1;
char v2;
char *v3;
unsigned int v4;
int v5;
UINT64 v6;
int v7;
unsigned __int64 v8;
struct _KPRCB *CurrentPrcb;
unsigned __int64 v10;
int v11;
__int64 v12;
unsigned __int64 v13;
__int64 v14;
__int64 v15;
unsigned __int64 v16;
unsigned __int64 v17;
v2 = v1;
v3 = (char *)BugCheckParameter4;
v4 = 0;
if( (*((_BYTE *)BugCheckParameter4 + 368) & 1) == 0 )
{
LOBYTE(v5) = KiRspInIstStack(3ui64, *((_QWORD *)BugCheckParameter4 + 48));
if( v5 )
_InterlockedAdd(&KiMcheckRecursive, 1u);
LOBYTE(v7) = KiRspInIstStack(2ui64, v6);
if( v7 )
{
v4 |= 2u;
_InterlockedAdd(&dword_140C2AD64, 1u);
}
v8 = *((_QWORD *)v3 + 45);
if( v8 >= (unsigned __int64)&KiMcheckExitMceTailMceBegin && v8 < (unsigned __int64)&KiMcheckExitMceTailMceEnd )
{
v4 |= 4u;
_InterlockedAdd(&dword_140C2AD68, 1u);
}
if( v8 >= (unsigned __int64)&KiMcheckExitMceTailNmiBegin && v8 < (unsigned __int64)KiMcheckExitMceTailNmiEnd )
{
v4 |= 4u;
_InterlockedAdd(&dword_140C2AD68, 1u);
}
if( KiKvaShadow )
{
if( v8 >= (unsigned __int64)&KiKernelIstMceExitMceTailMceBegin
&& v8 < (unsigned __int64)&KiKernelIstMceExitMceTailMceEnd )
{
v4 |= 4u;
_InterlockedAdd(&dword_140C2AD6C, 1u);
}
if( KiKvaShadow
&& v8 >= (unsigned __int64)&KiKernelIstMceExitMceTailNmiBegin
&& v8 < (unsigned __int64)KiKernelIstMceExitMceTailNmiEnd )
{
v4 |= 4u;
_InterlockedAdd(&dword_140C2AD6C, 1u);
}
}
}
CurrentPrcb = KeGetCurrentPrcb();
LODWORD(v10) = v4 & 1;
if( v2 || (v4 & 1) != 0 )
{
_InterlockedAdd(&dword_140C2AD78, 1u);
if( (v4 & 1) != 0 )
_InterlockedAdd(&dword_140C2AD80, 1u);
v11 = 1;
}
else
{
_InterlockedAdd(&dword_140C2AD7C, 1u);
v11 = 0;
}
v12 = 0i64;
if( KiKvaShadow )
{
v13 = CurrentPrcb[-1].PrcbPad141[473];
if( !v2 )
{
v12 = *(_QWORD *)(v13 + 44);
goto LABEL_29;
}
v12 = *(_QWORD *)(v13 + 52);
}
if( !v2 )
{
LABEL_29:
v14 = 36048i64;
if( v11 )
goto LABEL_31;
goto LABEL_30;
}
if( (v4 & 1) != 0 )
KeBugCheckEx(0x111u, (PVOID)v4, *((PVOID *)v3 + 48), *((PVOID *)v3 + 45), v3);
LABEL_30:
v14 = 35968i64;
LABEL_31:
if( (v4 & 4) != 0 )
{
_InterlockedAdd(&dword_140C2AD84, 1u);
v15 = *(_QWORD *)(&CurrentPrcb->CpuType + v14);
if( KiKvaShadow )
{
*(_QWORD *)(v12 + 16) = v15;
*(_QWORD *)(v12 + 24) = CurrentPrcb->HalReserved[(unsigned __int64)v14 / 8];
if( (CurrentPrcb->HalReserved[(unsigned __int64)v14 / 8] & 3) != 0
&& CurrentPrcb->CurrentThread->Tcb.Process->Pcb.AddressPolicy != 1 )
{
_InterlockedAdd(&dword_140C2AD88, 1u);
_interlockedbittestandreset((volatile signed __int32 *)&CurrentPrcb->ShadowFlags, 0);
v16 = __readcr4();
if( (v16 & 0x20080) != 0 )
{
__writecr4(v16 ^ 0x80);
__writecr4(v16);
}
else
{
v17 = __readcr3();
__writecr3(v17);
}
}
}
else
{
*((_QWORD *)v3 + 13) = v15;
}
*(_OWORD *)(v3 + 360) = *(_OWORD *)((char *)&CurrentPrcb->_MxCsr + v14);
*(_OWORD *)(v3 + 376) = *(_OWORD *)((char *)&CurrentPrcb->NextThread + v14);
*((_QWORD *)v3 + 49) = *(_QWORD *)(&CurrentPrcb->NestingLevel + v14);
*((_QWORD *)v3 + 6) = *(unsigned __int64 *)((char *)&CurrentPrcb->RspBase + v14);
*((_QWORD *)v3 + 7) = *(unsigned __int64 *)((char *)&CurrentPrcb->PrcbLock + v14);
v10 = *(unsigned __int64 *)((char *)&CurrentPrcb->PriorityState + v14);
*((_QWORD *)v3 + 8) = v10;
_InterlockedAdd(&dword_140C2AD74, 1u);
*(_WORD *)((char *)&CurrentPrcb->CurrentThread + v14) = 0;
}
if( !v2 )
{
_InterlockedAdd(&dword_140C2AD70, 1u);
*(_OWORD *)((char *)&CurrentPrcb->_MxCsr + v14) = *(_OWORD *)(v3 + 360);
*(_OWORD *)((char *)&CurrentPrcb->NextThread + v14) = *(_OWORD *)(v3 + 376);
*(_QWORD *)(&CurrentPrcb->NestingLevel + v14) = *((_QWORD *)v3 + 49);
*(unsigned __int64 *)((char *)&CurrentPrcb->RspBase + v14) = *((_QWORD *)v3 + 6);
*(unsigned __int64 *)((char *)&CurrentPrcb->PrcbLock + v14) = *((_QWORD *)v3 + 7);
*(char **)((char *)&CurrentPrcb->PriorityState + v14) = (char *)*((_QWORD *)v3 + 8);
v10 = *((_QWORD *)v3 + 13);
*(_QWORD *)(&CurrentPrcb->CpuType + v14) = v10;
if( KiKvaShadow )
{
*(_QWORD *)(&CurrentPrcb->CpuType + v14) = *(_QWORD *)(v12 + 16);
v10 = *(_QWORD *)(v12 + 24);
CurrentPrcb->HalReserved[(unsigned __int64)v14 / 8] = v10;
}
}
return v10;
}Referenced by:
KiMcheckAbort
KiNmiInterruptStart