PspRundownSingleProcess

char __fastcall PspRundownSingleProcess(ULONG_PTR BugCheckParameter1, char a2){
  char v2; 
  _ETHREAD *CurrentThread; 
  volatile INT64 *v5; 
  _HANDLE_TABLE *v6; 
  __int64 v7; 
  __int64 v8; 
  _QWORD *v9; 
  _QWORD *v10; 
  _QWORD *v11; 
  __int64 v12; 
  unsigned __int64 v13; 
  _QWORD *v14; 
  _QWORD *v15; 
  _QWORD *v16; 
  __int64 v17; 
  unsigned __int64 v18; 
  struct _DMA_ADAPTER *v19; 
  void *v20; 
  void *v21; 
  _KAPC_STATE ApcState; 
  v2 = a2;
  memset(&ApcState, 0, sizeof(ApcState));
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  if( a2 )
    goto LABEL_10;
  --*((_WORD *)CurrentThread + 242);
  v5 = (volatile INT64 *)(BugCheckParameter1 + 1080);
  ExAcquirePushLockExclusiveEx(BugCheckParameter1 + 1080, 0i64);
  if( !*(_DWORD *)(BugCheckParameter1 + 1520) )
  {
    _m_prefetchw((const void *)(BugCheckParameter1 + 1124));
    if( (_InterlockedOr((volatile signed __int32 *)(BugCheckParameter1 + 1124), 0x2000008u) & 0x2000000) == 0 )
      v2 = 1;
  }
  if( (_InterlockedExchangeAdd64(v5, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
    ExfTryToWakePushLock(v5);
  KeAbPostRelease((PVOID)v5);
  KeLeaveCriticalRegionThread((__int64)CurrentThread);
  if( v2 )
  {
LABEL_10:
    ExWaitForRundownProtectionRelease((EX_RUNDOWN_REF *)(BugCheckParameter1 + 1112));
    ExRundownCompleted((EX_RUNDOWN_REF *)(BugCheckParameter1 + 1112));
    if( *(_QWORD *)(BugCheckParameter1 + 1296) && (*(_DWORD *)(BugCheckParameter1 + 1120) & 1) == 0 )
    {
      RtlInterlockedSetClearBits((UINT64 *)(BugCheckParameter1 + 1120), 8ui64);
      PspSendProcessNotificationToJobChain(BugCheckParameter1, v7, *(_QWORD *)(BugCheckParameter1 + 1088));
    }
    if( *(_QWORD *)(BugCheckParameter1 + 992) )
      KeRundownSecureProcess(BugCheckParameter1);
    if( (*(_DWORD *)(BugCheckParameter1 + 1124) & 0x40000) != 0 )
    {
      KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
      if( *(_QWORD *)(BugCheckParameter1 + 1392) )
        ObKillProcess(BugCheckParameter1);
      MmCleanProcessAddressSpace(BugCheckParameter1, v8);
      KiUnstackDetachProcess(&ApcState, 0i64);
    }
    if( *(_QWORD *)(BugCheckParameter1 + 2248) )
    {
      --*((_WORD *)CurrentThread + 242);
      ExAcquirePushLockExclusiveEx(BugCheckParameter1 + 2264, 0i64);
      ExFreePoolWithTag(*(PVOID *)(*(_QWORD *)(BugCheckParameter1 + 2248) + 8i64), 0);
      ExFreePoolWithTag(*(PVOID *)(BugCheckParameter1 + 2248), 0);
      *(_QWORD *)(BugCheckParameter1 + 2248) = 0i64;
      if( (_InterlockedExchangeAdd64((volatile signed __int64 *)(BugCheckParameter1 + 2264), 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
        ExfTryToWakePushLock((volatile INT64 *)(BugCheckParameter1 + 2264));
      KeAbPostRelease((PVOID)(BugCheckParameter1 + 2264));
      KeLeaveCriticalRegionThread((__int64)CurrentThread);
    }
    v9 = *(_QWORD **)(BugCheckParameter1 + 2560);
    if( v9 )
    {
      while( 1 )
      {
        while( 1 )
        {
          while( *v9 )
          {
            v10 = v9;
            v9 = (_QWORD *)*v9;
            *v10 = 0i64;
          }
          if( !v9[1] )
            break;
          v11 = v9;
          v9 = (_QWORD *)v9[1];
          v11[1] = 0i64;
        }
        v12 = v9[2];
        SC_ENV::Free(v9);
        v13 = v12 & 0xFFFFFFFFFFFFFFFCui64;
        if( !v13 )
          break;
        v9 = (_QWORD *)v13;
      }
    }
    *(_QWORD *)(BugCheckParameter1 + 2560) = 0i64;
    v14 = *(_QWORD **)(BugCheckParameter1 + 2576);
    if( v14 )
    {
      while( 1 )
      {
        while( 1 )
        {
          while( *v14 )
          {
            v15 = v14;
            v14 = (_QWORD *)*v14;
            *v15 = 0i64;
          }
          if( !v14[1] )
            break;
          v16 = v14;
          v14 = (_QWORD *)v14[1];
          v16[1] = 0i64;
        }
        v17 = v14[2];
        SC_ENV::Free(v14);
        v18 = v17 & 0xFFFFFFFFFFFFFFFCui64;
        if( !v18 )
          break;
        v14 = (_QWORD *)v18;
      }
    }
    *(_QWORD *)(BugCheckParameter1 + 2576) = 0i64;
    if( *(_QWORD *)(BugCheckParameter1 + 2600) )
    {
      ExFreePoolWithTag(*(PVOID *)(BugCheckParameter1 + 2600), 0);
      *(_QWORD *)(BugCheckParameter1 + 2600) = 0i64;
    }
    v19 = *(struct _DMA_ADAPTER **)(BugCheckParameter1 + 1304);
    if( v19 )
    {
      *(_QWORD *)(BugCheckParameter1 + 1304) = 0i64;
      HalPutDmaAdapter(v19);
    }
    v20 = *(void **)(BugCheckParameter1 + 1440);
    if( v20 )
    {
      ObfDereferenceObjectWithTag(v20, 0x72437350ui64);
      *(_QWORD *)(BugCheckParameter1 + 1440) = 0i64;
    }
    if( (*(_DWORD *)(BugCheckParameter1 + 1124) & 0x40000) != 0 )
      KeSetProcess((_KPROCESS *)BugCheckParameter1);
    if( *(_QWORD *)(BugCheckParameter1 + 1296) )
    {
      PspRemoveProcessFromJobChain(BugCheckParameter1, 0i64, 4, 0);
      PspNotifyEmptyJobsInJobChain(BugCheckParameter1);
    }
    v21 = *(void **)(BugCheckParameter1 + 1088);
    if( v21 )
      PspClearProcessThreadCidRefs(CurrentThread, v21, (PVOID)BugCheckParameter1);
  }
  else
  {
    v6 = (_HANDLE_TABLE *)ObReferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)BugCheckParameter1);
    if( v6 )
    {
      ExSweepHandleTable((_EPROCESS *)BugCheckParameter1, v6, 1);
      ExReleaseRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112));
    }
  }
  return v2;
}

Referenced by:

NtCreateUserProcess
PsCreateMinimalProcess
PsTerminateMinimalProcess
PspAllocateProcess
PspCreateProcess
PspExitThread
PspProcessRundownWorker
PspProcessRundownWorkerSingle
PspTerminateAllThreads
PspTerminateProcess