SmKmCleanup
VOID __fastcall SmKmCleanup(INT64 a1){
struct _PRIVILEGE_SET **v2;
__int64 v3;
struct _PRIVILEGE_SET *v4;
volatile INT64 *p_Attributes;
__int64 v6;
_ETHREAD *CurrentThread;
__int64 v8;
v2 = (struct _PRIVILEGE_SET **)a1;
v3 = 32i64;
do
{
v4 = *v2;
if( *v2 )
{
p_Attributes = (volatile INT64 *)&v4->Privilege[0].Attributes;
v6 = 32i64;
do
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquirePushLockExclusiveEx((UINT64)p_Attributes, 0i64);
v8 = *((_QWORD *)p_Attributes - 2);
if( v8 )
{
(*(void(__fastcall **)(INT64, _QWORD, __int64))(a1 + 256))(a1, *((_QWORD *)p_Attributes - 2), 7i64);
ExWaitForRundownProtectionRelease((EX_RUNDOWN_REF *)p_Attributes - 1);
}
else
{
*((_QWORD *)p_Attributes - 2) = -1i64;
}
if( (_InterlockedExchangeAdd64(p_Attributes, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(p_Attributes);
KeAbPostRelease((PVOID)p_Attributes);
KeLeaveCriticalRegion();
if( v8 )
(*(void(__fastcall **)(INT64, __int64, __int64))(a1 + 256))(a1, v8, 1i64);
p_Attributes += 5;
--v6;
}
while( v6 );
CmSiFreeMemory(v4);
}
++v2;
--v3;
}
while( v3 );
}Referenced by:
No references.