MiTrimAllSystemPagableMemory
UINT64 __stdcall MiTrimAllSystemPagableMemory(UINT64 MemoryType, UINT64 PurgeTransition){
__int64 *v2;
__int64 SessionVm;
INT64 *v4;
int v5;
__int64 v6;
unsigned int v7;
unsigned int v9;
_ETHREAD *CurrentThread;
int v11;
char v12;
INT64 v13;
_MI_PARTITION *v14;
int v15;
v15 = PurgeTransition;
v2 = qword_140C4EBA8;
SessionVm = 1i64;
v4 = &qword_140C4ED40;
v5 = MemoryType;
v6 = 3i64;
if( !(_DWORD)MemoryType )
{
v7 = 0;
PurgeTransition = (UINT64)qword_140C4EBA8;
MemoryType = (UINT64)&qword_140C4ED40;
do
{
SessionVm = MemoryType;
if( MemoryType && *(_DWORD *)PurgeTransition != *(_DWORD *)(MemoryType + 4) )
break;
++v7;
MemoryType += 320i64;
PurgeTransition += 4i64;
}
while( v7 < 3 );
if( v7 == 6 )
return 0i64;
}
if( KeGetCurrentIrql() > 1u )
return 0i64;
v9 = 0;
CurrentThread = 0i64;
v11 = 0;
if( _InterlockedIncrement(&dword_140C4EB88) <= 1 )
{
KeAreInterruptsEnabled(MemoryType, (_BYTE *)PurgeTransition);
if( v12 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v11 = 1;
--*((_WORD *)CurrentThread + 243);
if( !v5 )
{
do
{
SessionVm = (__int64)v4;
if( v4 && *(_DWORD *)v2 != *((_DWORD *)v4 + 1) )
{
v9 = 1;
MiEmptyTargetedWorkingSet((INT64)v4);
*(_DWORD *)v2 = *((_DWORD *)v4 + 1);
}
v4 += 40;
v2 = (__int64 *)((char *)v2 + 4);
--v6;
}
while( v6 );
goto LABEL_22;
}
if( v5 == 1 )
{
SessionVm = *((_QWORD *)CurrentThread + 23) + 1664i64;
v13 = SessionVm;
}
else
{
if( (*(_DWORD *)(*((_QWORD *)CurrentThread + 23) + 1124i64) & 0x10000) == 0 )
{
LABEL_22:
if( v15 == 1 && v9 == 1 )
{
if( v5 == 1 )
v14 = *(_MI_PARTITION **)(qword_140C4E388 + 8i64 * *(unsigned __int16 *)(SessionVm + 174));
else
v14 = (_MI_PARTITION *)&MiSystemPartition;
MiPurgePartitionStandby(v14, 8ui64);
}
goto LABEL_28;
}
SessionVm = MiGetSessionVm();
v13 = SessionVm;
}
MiEmptyTargetedWorkingSet(v13);
v9 = 1;
goto LABEL_22;
}
}
LABEL_28:
_InterlockedAdd(&dword_140C4EB88, 0xFFFFFFFF);
if( v11 == 1 )
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
return v9;
}Referenced by:
MmTrimAllSystemPagableMemory
MmVerifierTrimMemory