KiUnstackDetachProcess
VOID __stdcall KiUnstackDetachProcess(KAPC_STATE *ApcState, UINT64 Force){
INT64 v2;
INT64 v3;
INT64 v4;
INT64 v5;
INT64 v6;
INT64 v7;
_EPROCESS *Process;
char v9;
_ETHREAD *CurrentThread;
_EPROCESS *v11;
int v12;
unsigned __int8 CurrentIrql;
struct _KPRCB *CurrentPrcb;
_QWORD *v15;
INT64 v16;
VOID *v17;
INT64 *v18;
INT64 v19;
__int64 v20;
struct _KPRCB *v21;
__int64 v22;
int v23;
INT64 v24;
INT64 v25;
INT64 v26;
INT64 v27;
INT64 v28;
UINT64 SpinCount;
int v30;
UINT64 v31;
v30 = Force;
Process = ApcState->Process;
v9 = Force;
if( Process != (_EPROCESS *)1 )
{
if( Process )
{
KiDetachProcess(ApcState, Force);
}
else
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
v27 = v3;
v26 = v2;
v25 = v4;
v24 = v6;
v11 = (_EPROCESS *)*((_QWORD *)CurrentThread + 23);
v12 = Force & 2;
if( (Force & 2) != 0 )
{
CurrentIrql = 15;
}
else
{
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
CurrentPrcb = KeGetCurrentPrcb();
LODWORD(SpinCount) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)CurrentThread + 16, 0i64) )
{
do
KeYieldProcessorEx(&SpinCount);
while( *((_QWORD *)CurrentThread + 8) );
v20 = *((_QWORD *)CurrentPrcb + 4247);
if( v20 && *((_BYTE *)CurrentPrcb + 32) <= 1u )
++*(_DWORD *)(v20 + 24);
}
}
if( *((_BYTE *)CurrentThread + 193) )
{
do
{
if( CurrentIrql || *((_WORD *)CurrentThread + 243) )
break;
KiReleaseThreadLockSafe((INT64)CurrentThread);
__writecr8(0i64);
CurrentIrql = KeGetCurrentIrql();
__writecr8(2ui64);
v21 = KeGetCurrentPrcb();
LODWORD(v31) = 0;
while( _interlockedbittestandset64((volatile signed __int32 *)CurrentThread + 16, 0i64) )
{
do
KeYieldProcessorEx(&v31);
while( *((_QWORD *)CurrentThread + 8) );
v22 = *((_QWORD *)v21 + 4247);
if( v22 && *((_BYTE *)v21 + 32) <= 1u )
{
v23 = *(_DWORD *)(v22 + 24) + 1;
*(_DWORD *)(v22 + 24) = v23;
}
}
}
while( *((_BYTE *)CurrentThread + 193) );
v9 = v30;
}
if( !*((_BYTE *)CurrentThread + 586)
|| (*((_BYTE *)CurrentThread + 192) & 1) != 0
|| (v15 = (_QWORD *)((char *)CurrentThread + 152), (_QWORD *)*v15 != v15)
|| *((_ETHREAD **)CurrentThread + 21) != (_ETHREAD *)((char *)CurrentThread + 168) )
{
KeBugCheck(6ui64);
}
*((_DWORD *)CurrentThread + 29) |= 0x800u;
KiMoveApcState((_KAPC_STATE *)((char *)CurrentThread + 600), (_KAPC_STATE *)((char *)CurrentThread + 152));
*((_QWORD *)CurrentThread + 79) = 0i64;
*((_BYTE *)CurrentThread + 586) = 0;
if( !v12 )
KiReleaseThreadLockSafe((INT64)CurrentThread);
KiSwapProcess(*((_EPROCESS **)CurrentThread + 23), v11);
*((_DWORD *)CurrentThread + 29) &= ~0x800u;
if( !v12 )
__writecr8(CurrentIrql);
if( (v9 & 1) == 0 )
KiDecrementProcessStackCount((_KPROCESS *)v11);
if( (_QWORD *)*v15 != v15 )
{
LOBYTE(v17) = 1;
*((_BYTE *)CurrentThread + 193) = 1;
HalRequestSoftwareInterrupt(v17, v16, v18, v19, v7, v24, v5, v25, v26, v27, v28);
}
}
}
}Referenced by:
AlpcViewDestroyProcedure
AlpcpExposeViewAttributeInSenderContext
AlpcpForceUnlinkSecureView
AlpcpPrepareViewForDelivery
AlpcpRestoreWriteAccess
CmCallbackGetKeyObjectID
CmCallbackGetKeyObjectIDEx
CmEnumerateValueKey
CmEtwRunDown
CmLoadKey
CmReconcileAndValidateAllHives
CmRmFinalizeRecovery
CmpAddRemoveContainerToCLFSLog
CmpCleanUpKCBCacheTable
CmpCleanupLightWeightTransaction
CmpDelayCloseWorker
CmpDetachFromRegistryProcess
CmpEtwDumpKcb
CmpFinishSystemHivesLoad
CmpFlushBackupHive
CmpForceFlushWorker
CmpHandlePageFileOpenNotification
CmpInitHiveFromFile
CmpInitializeRegistryProcess
CmpMountPreloadedHives
CmpPublishEventForPcaResolver
CmpRmUnDoPhase
CmpSearchKeyControlBlockTreeEx
DbgkQueueUserExceptionReport
DbgkSendSystemDllMessages
DbgkUserReportWorkRoutine
DbgkpMarkProcessPeb
DbgkpPostFakeProcessCreateMessages
EmpCacheBiosDate
EmpMapPhysicalAddress
EtwQueryProcessTelemetryInfo
EtwTraceAppStateChange
EtwpAddRegEntryToGroup
EtwpCovSampEnumerateProcess
EtwpProcessEnumCallback
EtwpPsProvProcessEnumCallback
EtwpRealtimeInjectEtwBuffer
EtwpTiQueryVad
EtwpTrackGuidEntryRegistrations
EtwpUMGLEnabled
EtwpUpdateProcessTracingCallback
EtwpWriteProcessEvent
ExSweepHandleTable
ExpDebuggerWorker
ExpSvmServicePageFault
ExpWnfWriteStateData
IoRaiseHardError
IoRemoveIoCompletion
IopIsNotNativeDriverImage
IopRaiseHardError
KeForceDetachProcess
KeSecureProcess
KiTpReadImageData
KiTpWriteMemory
MiAllocateChildVads
MiAllocateVirtualMemory
MiCloneProcessAddressSpace
MiCombineIdenticalPages
MiCopyLargeVad
MiCopyPagesIntoEnclave
MiDeleteFinalPageTables
MiDeleteInsertedCloneVads
MiEmptyAccessLogs
MiFindNextEnclaveBoundary
MiFlushAllPages
MiGetWorkingSetInfoEx
MiGetWorkingSetInfoList
MiHotPatchAllProcesses
MiInSwapSharedWorkingSetWorker
MiInSwapStoreWorker
MiInsertChildVads
MiLoadDataIntoVsmEnclave
MiLockDownWorkingSet
MiLogHotPatchRundown
MiMapImageForEnclaveUse
MiMapImageInSystemSpace
MiMapViewOfSection
MiQueryMemoryPhysicalContiguity
MiQueryProcessActivePatches
MiScrubProcesses
MiUnmapImageForEnclaveUse
MiUnmapImageInSystemSpace
MiUnmapViewOfSection
MiWaitForInPageComplete
MmAssignProcessToJob
MmCopyVirtualMemory
MmCreatePeb
MmCreateShadowMapping
MmCreateTeb
MmDeleteShadowMapping
MmDeleteTeb
MmDetachSession
MmEnforceWorkingSetLimit
MmEnumerateAddressSpaceAndReferenceImages
MmFlushVirtualMemory
MmFreeVirtualMemory
MmInitializeHandBuiltProcess2
MmInitializeProcessAddressSpace
MmIsFileMapped
MmNewProcessInitialized
MmPrefetchVirtualMemory
MmProbeAndLockProcessPages
MmProcessWorkingSetControl
MmSecureVirtualMemoryAgainstWrites
MmSetCommitReleaseEligibility
MmUpdateOldWorkingSetPages
NtCompressKey
NtCreateEnclave
NtEnumerateValueKey
NtFlushKey
NtQueryMultipleValueKey
NtRenameKey
NtRestoreKey
NtRollbackRegistryTransaction
NtSaveKeyEx
NtSaveMergedKeys
NtThawRegistry
ObCloseHandleTableEntry
ObSetHandleAttributes
ObpDecrementHandleCount
ObpIncrementHandleCountEx
PfSnAsyncPrefetchWorker
PfSnPopulateReadList
PoEnergyContextStart
PsDispatchIumService
PsMapSystemDlls
PsQueryProcessCommandLine
PsQueryProcessExceptionFlags
PsStartSiloMonitor
PsUnregisterSiloMonitor
PspAllocatePartition
PspAllocateThread
PspApplyWorkingSetLimitsToProcess
PspChangeProcessExecutionState
PspCreateSecureThread
PspDeleteUserStack
PspInitPhase3
PspIsProcessReadyForRemoteThread
PspIumGetPhysicalPage
PspProcessDynamicEHContinuationTargets
PspRundownSingleProcess
PspSetupReservedUserMappings
PspSetupUserProcessAddressSpace
PspSetupUserShadowStack
PspSetupUserStack
PspShutdownCsrProcess
PspTrySetProcessPebThrottlingFlags
PspWow64InitThread
PspWow64ReadOrWriteThreadCpuArea
PspWow64SetupUserStack
PspWritePebAffinityInfo
PspWriteTebIdealProcessor
PspWriteTebImpersonationInfo
SMKM_STORE::SmStCleanup
SMKM_STORE::SmStDirectRead
SMKM_STORE::SmStPrioritizeRegionsStore
SMKM_STORE::SmStSwapStore
SMKM_STORE::SmStTrimWsStore
SepAdtLogAuditRecord
SepCleanupLUIDDeviceMapDirectory
SepRmCallLsa
SmFirstTimeInit
SmProcessStoreMemoryPriorityRequest
VmpPrefetchWorker