PspRundownSingleProcess
char __fastcall PspRundownSingleProcess(ULONG_PTR BugCheckParameter1, char a2){
char v2;
_ETHREAD *CurrentThread;
volatile INT64 *v5;
_HANDLE_TABLE *v6;
__int64 v7;
__int64 v8;
_QWORD *v9;
_QWORD *v10;
_QWORD *v11;
__int64 v12;
unsigned __int64 v13;
_QWORD *v14;
_QWORD *v15;
_QWORD *v16;
__int64 v17;
unsigned __int64 v18;
struct _DMA_ADAPTER *v19;
void *v20;
void *v21;
_KAPC_STATE ApcState;
v2 = a2;
memset(&ApcState, 0, sizeof(ApcState));
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
if( a2 )
goto LABEL_10;
--*((_WORD *)CurrentThread + 242);
v5 = (volatile INT64 *)(BugCheckParameter1 + 1080);
ExAcquirePushLockExclusiveEx(BugCheckParameter1 + 1080, 0i64);
if( !*(_DWORD *)(BugCheckParameter1 + 1520) )
{
_m_prefetchw((const void *)(BugCheckParameter1 + 1124));
if( (_InterlockedOr((volatile signed __int32 *)(BugCheckParameter1 + 1124), 0x2000008u) & 0x2000000) == 0 )
v2 = 1;
}
if( (_InterlockedExchangeAdd64(v5, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(v5);
KeAbPostRelease((PVOID)v5);
KeLeaveCriticalRegionThread((__int64)CurrentThread);
if( v2 )
{
LABEL_10:
ExWaitForRundownProtectionRelease((EX_RUNDOWN_REF *)(BugCheckParameter1 + 1112));
ExRundownCompleted((EX_RUNDOWN_REF *)(BugCheckParameter1 + 1112));
if( *(_QWORD *)(BugCheckParameter1 + 1296) && (*(_DWORD *)(BugCheckParameter1 + 1120) & 1) == 0 )
{
RtlInterlockedSetClearBits((UINT64 *)(BugCheckParameter1 + 1120), 8ui64);
PspSendProcessNotificationToJobChain(BugCheckParameter1, v7, *(_QWORD *)(BugCheckParameter1 + 1088));
}
if( *(_QWORD *)(BugCheckParameter1 + 992) )
KeRundownSecureProcess(BugCheckParameter1);
if( (*(_DWORD *)(BugCheckParameter1 + 1124) & 0x40000) != 0 )
{
KiStackAttachProcess((_KPROCESS *)BugCheckParameter1, 0i64, &ApcState);
if( *(_QWORD *)(BugCheckParameter1 + 1392) )
ObKillProcess(BugCheckParameter1);
MmCleanProcessAddressSpace(BugCheckParameter1, v8);
KiUnstackDetachProcess(&ApcState, 0i64);
}
if( *(_QWORD *)(BugCheckParameter1 + 2248) )
{
--*((_WORD *)CurrentThread + 242);
ExAcquirePushLockExclusiveEx(BugCheckParameter1 + 2264, 0i64);
ExFreePoolWithTag(*(PVOID *)(*(_QWORD *)(BugCheckParameter1 + 2248) + 8i64), 0);
ExFreePoolWithTag(*(PVOID *)(BugCheckParameter1 + 2248), 0);
*(_QWORD *)(BugCheckParameter1 + 2248) = 0i64;
if( (_InterlockedExchangeAdd64((volatile signed __int64 *)(BugCheckParameter1 + 2264), 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock((volatile INT64 *)(BugCheckParameter1 + 2264));
KeAbPostRelease((PVOID)(BugCheckParameter1 + 2264));
KeLeaveCriticalRegionThread((__int64)CurrentThread);
}
v9 = *(_QWORD **)(BugCheckParameter1 + 2560);
if( v9 )
{
while( 1 )
{
while( 1 )
{
while( *v9 )
{
v10 = v9;
v9 = (_QWORD *)*v9;
*v10 = 0i64;
}
if( !v9[1] )
break;
v11 = v9;
v9 = (_QWORD *)v9[1];
v11[1] = 0i64;
}
v12 = v9[2];
SC_ENV::Free(v9);
v13 = v12 & 0xFFFFFFFFFFFFFFFCui64;
if( !v13 )
break;
v9 = (_QWORD *)v13;
}
}
*(_QWORD *)(BugCheckParameter1 + 2560) = 0i64;
v14 = *(_QWORD **)(BugCheckParameter1 + 2576);
if( v14 )
{
while( 1 )
{
while( 1 )
{
while( *v14 )
{
v15 = v14;
v14 = (_QWORD *)*v14;
*v15 = 0i64;
}
if( !v14[1] )
break;
v16 = v14;
v14 = (_QWORD *)v14[1];
v16[1] = 0i64;
}
v17 = v14[2];
SC_ENV::Free(v14);
v18 = v17 & 0xFFFFFFFFFFFFFFFCui64;
if( !v18 )
break;
v14 = (_QWORD *)v18;
}
}
*(_QWORD *)(BugCheckParameter1 + 2576) = 0i64;
if( *(_QWORD *)(BugCheckParameter1 + 2600) )
{
ExFreePoolWithTag(*(PVOID *)(BugCheckParameter1 + 2600), 0);
*(_QWORD *)(BugCheckParameter1 + 2600) = 0i64;
}
v19 = *(struct _DMA_ADAPTER **)(BugCheckParameter1 + 1304);
if( v19 )
{
*(_QWORD *)(BugCheckParameter1 + 1304) = 0i64;
HalPutDmaAdapter(v19);
}
v20 = *(void **)(BugCheckParameter1 + 1440);
if( v20 )
{
ObfDereferenceObjectWithTag(v20, 0x72437350ui64);
*(_QWORD *)(BugCheckParameter1 + 1440) = 0i64;
}
if( (*(_DWORD *)(BugCheckParameter1 + 1124) & 0x40000) != 0 )
KeSetProcess((_KPROCESS *)BugCheckParameter1);
if( *(_QWORD *)(BugCheckParameter1 + 1296) )
{
PspRemoveProcessFromJobChain(BugCheckParameter1, 0i64, 4, 0);
PspNotifyEmptyJobsInJobChain(BugCheckParameter1);
}
v21 = *(void **)(BugCheckParameter1 + 1088);
if( v21 )
PspClearProcessThreadCidRefs(CurrentThread, v21, (PVOID)BugCheckParameter1);
}
else
{
v6 = (_HANDLE_TABLE *)ObReferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)BugCheckParameter1);
if( v6 )
{
ExSweepHandleTable((_EPROCESS *)BugCheckParameter1, v6, 1);
ExReleaseRundownProtection((PEX_RUNDOWN_REF)(BugCheckParameter1 + 1112));
}
}
return v2;
}Referenced by:
NtCreateUserProcess
PsCreateMinimalProcess
PsTerminateMinimalProcess
PspAllocateProcess
PspCreateProcess
PspExitThread
PspProcessRundownWorker
PspProcessRundownWorkerSingle
PspTerminateAllThreads
PspTerminateProcess