PspCreateSecureThread

NTSTATUS __stdcall PspCreateSecureThread(PVOID Base){
  __int64 v1; 
  __int64 v2; 
  UINT64 v4; 
  _MDL *PoolWithTag; 
  INT64 v6; 
  int v7; 
  INT64 v8; 
  _KAPC_STATE ApcState; 

  v2 = v1;
  memset(&ApcState, 0, sizeof(ApcState));
  KiStackAttachProcess(*((PVOID *)Base + 68), 0i64, &ApcState);
  LODWORD(v4) = MmSizeOfMdl(Base, 2200);
  PoolWithTag = (_MDL *)ExAllocatePoolWithTag(0x200ui64, v4, 1699967824i64);
  PoolWithTag->Next = 0i64;
  PoolWithTag->Size = 8 * (((unsigned __int16)(((unsigned __int16)Base & 0xFFF) + 6295) >> 12) + 6);
  PoolWithTag->MdlFlags = 0;
  PoolWithTag->StartVa = (void *)((unsigned __int64)Base & 0xFFFFFFFFFFFFF000ui64);
  PoolWithTag->ByteOffset = (unsigned __int16)Base & 0xFFF;
  PoolWithTag->ByteCount = 2200;
  MmProbeAndLockPages(PoolWithTag, 0, IoModifyAccess);
  v7 = KeSecureThread((__int64)Base, (__int64)PoolWithTag, *((_QWORD *)Base + 144), *((_QWORD *)Base + 154), v2);
  if( v7 < 0 )
  {
    MmUnlockPages((INT64)PoolWithTag, v6, v8);
    ExFreePoolWithTag(PoolWithTag, 0x65537350u);
  }
  KiUnstackDetachProcess(&ApcState, 0i64);
  return v7;
}

Referenced by:

PspInsertThread