MiTrimAllSystemPagableMemory
NTSTATUS __stdcall MiTrimAllSystemPagableMemory(UINT64 MemoryType, UINT64 PurgeTransition){
unsigned int *v2;
__int64 p_Vm;
_MMSUPPORT_INSTANCE *v4;
int v5;
__int64 v6;
unsigned int v7;
NTSTATUS v9;
_ETHREAD *CurrentThread;
int v11;
INT64 v12;
INT64 v13;
__int16 v14;
char v15;
_MMSUPPORT_INSTANCE *v16;
_MI_PARTITION *v17;
int v18;
v18 = PurgeTransition;
v2 = (unsigned int *)((char *)&stru_140C4DB30 + 4216);
p_Vm = 1i64;
v4 = (_MMSUPPORT_INSTANCE *)((char *)&stru_140C4DB30 + 4624);
v5 = MemoryType;
v6 = 3i64;
if( !(_DWORD)MemoryType )
{
v7 = 0;
PurgeTransition = (UINT64)&stru_140C4DB30 + 4216;
MemoryType = (UINT64)&stru_140C4DB30 + 4624;
do
{
p_Vm = MemoryType;
if( MemoryType && *(_DWORD *)PurgeTransition != *(_DWORD *)(MemoryType + 4) )
break;
++v7;
MemoryType += 320i64;
PurgeTransition += 4i64;
}
while( v7 < 3 );
if( v7 == 6 )
return 0;
}
if( KeGetCurrentIrql() > 1u )
return 0;
v9 = 0;
CurrentThread = 0i64;
v11 = 0;
if( _InterlockedIncrement((_DWORD *)&stru_140C4DB30 + 1046) <= 1 )
{
KeAreInterruptsEnabled(MemoryType, (_BYTE *)PurgeTransition);
if( v15 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v11 = 1;
--CurrentThread->Tcb.SpecialApcDisable;
if( !v5 )
{
do
{
p_Vm = (__int64)v4;
if( v4 && *v2 != v4->PageFaultCount )
{
v9 = 1;
MiEmptyTargetedWorkingSet(v4, v12, v14);
*v2 = v4->PageFaultCount;
}
v4 = (_MMSUPPORT_INSTANCE *)((char *)v4 + 320);
++v2;
--v6;
}
while( v6 );
goto LABEL_22;
}
if( v5 == 1 )
{
p_Vm = (__int64)&CurrentThread->Tcb.ApcState.Process->Vm;
v16 = (_MMSUPPORT_INSTANCE *)p_Vm;
}
else
{
if( (CurrentThread->Tcb.ApcState.Process->Flags & 0x10000) == 0 )
{
LABEL_22:
if( v18 == 1 && v9 == 1 )
{
if( v5 == 1 )
v17 = *(_MI_PARTITION **)(*(&stru_140C4DB30 + 267) + 8i64 * *(unsigned __int16 *)(p_Vm + 174));
else
v17 = &Irp;
MiPurgePartitionStandby(v17, 8ui64);
}
goto LABEL_28;
}
p_Vm = (__int64)MiGetSessionVm(v13, v12, v14);
v16 = (_MMSUPPORT_INSTANCE *)p_Vm;
}
MiEmptyTargetedWorkingSet(v16, v12, v14);
v9 = 1;
goto LABEL_22;
}
}
LABEL_28:
_InterlockedAdd((_DWORD *)&stru_140C4DB30 + 1046, 0xFFFFFFFF);
if( v11 == 1 )
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
return v9;
}Referenced by:
MmTrimAllSystemPagableMemory
MmVerifierTrimMemory