PspSetupReservedUserMappings

NTSTATUS __stdcall PspSetupReservedUserMappings(
        ULONG_PTR TargetProcess,
        _KAPC_STATE *ApcState,
        PSP_CREATE_PROCESS_CONTEXT *CreateContext){
  int v5; 
  int VirtualMemory; 
  unsigned __int64 v8; 
  __int64 v9; 
  UINT64 AllocationType; 
  UINT64 Protect; 
  UINT64 RegionSize; 
  VOID *BaseAddress; 

  BaseAddress = 0i64;
  RegionSize = 0i64;
  v5 = *(_DWORD *)(*((_QWORD *)CreateContext + 26) + 8i64) & 0x60;
  if( !v5 && !*((_QWORD *)CreateContext + 32) )
    return 0;
  VirtualMemory = 0;
  KiStackAttachProcess(*(PVOID *)&TargetProcess, 0i64, ApcState);
  if( !v5 )
    goto LABEL_10;
  BaseAddress = (VOID *)4;
  if( v5 == 32 )
  {
    RegionSize = 1048320i64;
  }
  else if( v5 == 64 )
  {
    RegionSize = 16776960i64;
  }
  LODWORD(Protect) = 4;
  LODWORD(AllocationType) = 0x2000;
  VirtualMemory = ZwAllocateVirtualMemory(
                    (VOID *)0xFFFFFFFFFFFFFFFFi64,
                    &BaseAddress,
                    0i64,
                    &RegionSize,
                    AllocationType,
                    Protect);
  if( VirtualMemory >= 0 )
  {
LABEL_10:
    v8 = 0i64;
    if( *((_QWORD *)CreateContext + 32) )
    {
      v9 = 0i64;
      do
      {
        LODWORD(Protect) = 4;
        LODWORD(AllocationType) = 0x2000;
        VirtualMemory = ZwAllocateVirtualMemory(
                          (VOID *)0xFFFFFFFFFFFFFFFFi64,
                          (VOID **)(v9 + *((_QWORD *)CreateContext + 35)),
                          0i64,
                          (UINT64 *)(v9 + *((_QWORD *)CreateContext + 35) + 8),
                          AllocationType,
                          Protect);
        if( VirtualMemory < 0 )
          break;
        ++v8;
        v9 += 16i64;
      }
      while( v8 < *((_QWORD *)CreateContext + 32) );
    }
  }
  KiUnstackDetachProcess(ApcState, 0i64);
  return VirtualMemory;
}

Referenced by:

PspAllocateProcess