MiModifiedPageWriter

VOID __stdcall MiModifiedPageWriter(PVOID StartContext){
  _ETHREAD *CurrentThread; 
  char *v3; 
  _DWORD *v4; 
  _DWORD *v5; 
  _DWORD *v6; 
  int v7; 
  UINT64 v8; 
  UINT8 v9; 
  char *v10; 
  __int64 *v11; 
  int v12; 
  unsigned __int64 v13; 
  unsigned __int64 v14; 
  unsigned __int64 v15; 
  int v16; 
  int v17; 
  int v18; 
  __int64 v19; 
  _QWORD *v20; 
  unsigned int v21; 
  unsigned int v22; 
  __int64 v23; 
  char v24; 
  unsigned int v25; 
  __int64 i; 
  _QWORD *v27; 
  UINT64 v28; 
  UINT8 v29; 
  UINT8 v30; 
  unsigned int v31; 
  unsigned int v32; 
  unsigned __int64 v33; 
  char *v34; 
  __int64 v35; 
  __int64 v36; 
  KIRQL v37; 
  char v38; 
  unsigned __int64 v39; 
  unsigned int v40; 
  char *v41; 
  __int64 v42; 
  __int64 v43; 
  unsigned int j; 
  _QWORD *v45; 
  signed __int32 v46[8]; 
  KPROCESSOR_MODE WaitMode[8]; 
  int v48; 
  unsigned __int64 v49; 
  _ETHREAD *v50; 
  PVOID Object[3]; 
  struct _KWAIT_BLOCK WaitBlockArray; 
  PVOID v53[6]; 
  struct _KWAIT_BLOCK v54; 
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  *((_QWORD *)StartContext + 118) = CurrentThread;
  v50 = CurrentThread;
  *((_DWORD *)CurrentThread + 325) |= 2u;
  v48 = KeSetActualBasePriorityThread((__int64)CurrentThread, 18);
  v3 = (char *)StartContext + 104;
  v53[2] = (char *)StartContext + 920;
  Object[0] = (char *)StartContext + 104;
  v53[0] = (char *)StartContext + 104;
  v4 = (char *)StartContext + 880;
  Object[1] = (char *)StartContext + 736;
  v5 = (char *)StartContext + 696;
  v53[1] = (char *)StartContext + 880;
  v6 = (char *)StartContext + 1008;
  v53[3] = (char *)StartContext + 696;
  v53[4] = (char *)StartContext + 1008;
LABEL_2:
  *((_QWORD *)StartContext + 105) = 0i64;
  *((_DWORD *)StartContext + 212) = 0;
  *((_BYTE *)StartContext + 674) = 0;
  MiStoreCheckCompleteWriteBatch((INT64)StartContext);
  KeWaitForMultipleObjects((_BYTE *)2, Object, WaitAny, WrPageOut, 0, 0, 0i64, &WaitBlockArray);
  *((_BYTE *)StartContext + 674) = 1;
  if( v7 )
  {
    while( 1 )
    {
      if( *((_DWORD *)v3 + 1) )
        goto LABEL_68;
      if( !*((_QWORD *)StartContext + 950) )
        goto LABEL_2;
      --*((_WORD *)CurrentThread + 243);
      MiStoreCheckCompleteWriteBatch((INT64)StartContext);
      v11 = (__int64 *)((char *)StartContext + 904);
      if( (__int64 *)*v11 == v11 )
      {
        *((_BYTE *)StartContext + 673) = 1;
        KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
        KeWaitForMultipleObjects((_BYTE *)5, v53, WaitAny, WrPageOut, 0, 0, 0i64, &v54);
        if( !v12 )
          goto LABEL_68;
        --*((_WORD *)CurrentThread + 243);
        *((_BYTE *)StartContext + 673) = 0;
      }
      if( v5[1] )
      {
        KeResetEvent(v5, v8, v9, (UINT8)v10, *(IRP **)WaitMode);
        if( *((_DWORD *)StartContext + 173) )
          IoBoostThreadIoPriority((KSPIN_LOCK *)CurrentThread, 2, 0);
      }
      if( v4[1] )
      {
        KeResetEvent(v4, v8, v9, (UINT8)v10, *(IRP **)WaitMode);
        _InterlockedOr(v46, 0);
        v22 = *((_DWORD *)StartContext + 1734);
        if( v22 )
        {
          v10 = (char *)StartContext + 6944;
          v23 = v22;
          do
          {
            v24 = *(_BYTE *)(*(_QWORD *)v10 + 206i64);
            if( (v24 & 1) != 0 )
            {
              v25 = 0;
              *(_BYTE *)(*(_QWORD *)v10 + 206i64) = v24 & 0xFE;
              for( i = *(_QWORD *)v10; v25 < *(_DWORD *)(*(_QWORD *)v10 + 72i64); ++v25 )
              {
                v27 = *(_QWORD **)(*(_QWORD *)(i + 64) + 8i64 * v25);
                if( v27 && *v27 == 2575857425i64 )
                  MiMakePagefileWriterEntryAvailable(v27);
                i = *(_QWORD *)v10;
              }
            }
            v10 += 8;
            --v23;
          }
          while( v23 );
        }
      }
      if( v6[1] )
      {
        KeResetEvent(v6, v8, v9, (UINT8)v10, *(IRP **)WaitMode);
        MiStoreUpdateMemoryConditions((_MI_PARTITION *)StartContext);
      }
      v13 = 0i64;
      v14 = *((_QWORD *)StartContext + 344);
      v15 = *((_QWORD *)StartContext + 950);
      if( *((__int64 *)StartContext + 896) >= 0 )
        v13 = *((_QWORD *)StartContext + 896);
      v49 = *((_QWORD *)StartContext + 344);
      if( *((_QWORD *)StartContext + 104) < 0x800ui64 && (v15 > *((_QWORD *)StartContext + 866) >> 2 || v15 > v13 >> 2) )
      {
        v31 = *((_DWORD *)StartContext + 212);
        if( v31 >= 0x40 && *((_DWORD *)StartContext + 210) / v31 < (unsigned int)dword_140CFA18C >> 3 )
        {
          v32 = *((_DWORD *)StartContext + 1734);
          v33 = 3 * (v15 >> 2);
          if( v32 )
          {
            v34 = (char *)StartContext + 6944;
            v35 = v32;
            do
            {
              v36 = *(_QWORD *)v34;
              if( (*(_WORD *)(*(_QWORD *)v34 + 204i64) & 0x60) == 0 )
              {
                if( v14 > v33 )
                {
                  v37 = ExAcquireSpinLockExclusive((PEX_SPIN_LOCK)(v36 + 232));
                  v38 = *(_BYTE *)(v36 + 207);
                  v39 = v37;
                  if( (v38 & 1) == 0 )
                  {
                    *(_BYTE *)(v36 + 207) = v38 | 1;
                    MiInitializePagefileBitmapsCache(v36);
                    *(_DWORD *)(v36 + 124) = dword_140CFA18C;
                  }
                  ExReleaseSpinLockExclusiveFromDpcLevel((INT64 *)(v36 + 232));
                  __writecr8(v39);
                }
                MiFreeModifiedReservations((_MMPAGING_FILE *)v36, 0i64);
                v14 = v49;
              }
              v34 += 8;
              --v35;
            }
            while( v35 );
            CurrentThread = v50;
            v11 = (__int64 *)((char *)StartContext + 904);
            v5 = (char *)StartContext + 696;
            v6 = (char *)StartContext + 1008;
            v4 = (char *)StartContext + 880;
          }
          ++*((_DWORD *)StartContext + 214);
          if( v14 > v33 )
          {
            *((_QWORD *)StartContext + 108) = KiQueryUnbiasedInterruptTime(1u);
            _InterlockedOr(v46, 0);
            *((_WORD *)StartContext + 438) |= 1u;
            ++*((_DWORD *)StartContext + 213);
          }
          *((_DWORD *)StartContext + 212) = 0;
          *((_QWORD *)StartContext + 105) = 0i64;
        }
      }
      if( (__int64 *)*v11 == v11 )
        break;
      v16 = *((_DWORD *)StartContext + 288);
      if( (v16 & 1) != 0
        && (v16 & 0xFFFFFFFE) == 0
        && _InterlockedCompareExchange((volatile signed __int32 *)StartContext + 288, 0, 1) == 1 )
      {
        KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
        KeResetEvent((char *)StartContext + 736, v28, v29, v30, *(IRP **)WaitMode);
LABEL_45:
        v3 = (char *)StartContext + 104;
        goto LABEL_2;
      }
      if( (unsigned int)MiUseLowIoPriorityForModifiedPages((_MI_PARTITION *)StartContext) )
      {
        if( *((_QWORD *)StartContext + 950) < *((_QWORD *)StartContext + 91) )
        {
          KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
          goto LABEL_45;
        }
        *((_DWORD *)StartContext + 180) = 4;
        v17 = KeSetActualBasePriorityThread((__int64)CurrentThread, 4);
        v18 = 0;
      }
      else
      {
        if( *((_DWORD *)StartContext + 173) )
          IoBoostThreadIoPriority((KSPIN_LOCK *)CurrentThread, 2, 0);
        v17 = -1;
        v18 = 8;
      }
      v19 = *v11;
      v20 = *(_QWORD **)*v11;
      if( *(__int64 **)(*v11 + 8) != v11 || v20[1] != v19 )
        __fastfail(3u);
      *v11 = (__int64)v20;
      v20[1] = v11;
      v21 = *(_DWORD *)(v19 + 40) & 0xFFFFFFE3;
      *(_QWORD *)v19 = 97i64;
      *(_DWORD *)(v19 + 40) = v18 | v21;
      KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
      *(_QWORD *)(v19 + 200) = v19 + 208;
      MiGatherPagefilePages(v19);
      v5 = (char *)StartContext + 696;
      v3 = (char *)StartContext + 104;
      if( v17 == -1 )
      {
        v6 = (char *)StartContext + 1008;
      }
      else
      {
        if( KeQueryPriorityThread((_KTHREAD *)CurrentThread) != 18 )
          KeSetActualBasePriorityThread((__int64)CurrentThread, v17);
        *((_DWORD *)StartContext + 180) = 18;
        v5 = (char *)StartContext + 696;
        v6 = (char *)StartContext + 1008;
LABEL_29:
        v3 = (char *)StartContext + 104;
      }
    }
    KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
    goto LABEL_29;
  }
LABEL_68:
  if( *((_DWORD *)StartContext + 173) )
    IoBoostThreadIoPriority((KSPIN_LOCK *)CurrentThread, 2, 0);
  ExWaitForRundownProtectionRelease((EX_RUNDOWN_REF *)StartContext + 119);
  v40 = *((_DWORD *)StartContext + 1734);
  if( v40 )
  {
    v41 = (char *)StartContext + 6944;
    v42 = v40;
    do
    {
      if( *(_QWORD *)v41 )
      {
        --*((_WORD *)CurrentThread + 243);
        v43 = *(_QWORD *)v41;
        for( j = 0; j < *(_DWORD *)(*(_QWORD *)v41 + 72i64); ++j )
        {
          v45 = *(_QWORD **)(*(_QWORD *)(v43 + 64) + 8i64 * j);
          if( v45 )
          {
            while( *v45 == 97i64 )
            {
              *((_BYTE *)StartContext + 673) = 1;
              KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
              KeWaitForSingleObject((char *)StartContext + 920, WrPageOut, 0, 0, 0i64);
              --*((_WORD *)CurrentThread + 243);
            }
          }
          v43 = *(_QWORD *)v41;
        }
        KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
      }
      v41 += 8;
      --v42;
    }
    while( v42 );
  }
  KeSetActualBasePriorityThread((__int64)CurrentThread, v48);
  KeSetEvent((PRKEVENT)((char *)StartContext + 760), 0);
}

Referenced by:

No references.