MiDeleteImageHotPatchState
VOID __fastcall MiDeleteImageHotPatchState(UINT64 a1){
_ETHREAD *CurrentThread;
_QWORD *ProcessHotPatchContext;
unsigned __int64 v4;
void *v5;
volatile INT64 *v6;
unsigned __int64 v7;
int v8;
int v9;
unsigned __int64 v10;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
ProcessHotPatchContext = MiGetProcessHotPatchContext(*((_QWORD *)CurrentThread + 23), 0i64);
v4 = (unsigned __int64)ProcessHotPatchContext;
if( ProcessHotPatchContext )
{
v5 = 0i64;
--*((_WORD *)CurrentThread + 243);
v6 = ProcessHotPatchContext + 2;
ExAcquirePushLockExclusiveEx((UINT64)(ProcessHotPatchContext + 2), 0i64);
v7 = *(_QWORD *)v4;
if( (*(_BYTE *)(v4 + 8) & 1) != 0 )
{
if( v7 )
v7 ^= v4;
else
v7 = 0i64;
}
v8 = *(_BYTE *)(v4 + 8) & 1;
if( v7 )
{
do
{
v9 = MiHotPatchImageTreeCompare(a1, v7);
if( v9 >= 0 )
{
if( v9 <= 0 )
break;
v10 = *(_QWORD *)(v7 + 8);
}
else
{
v10 = *(_QWORD *)v7;
}
if( v8 && v10 )
v7 ^= v10;
else
v7 = v10;
}
while( v7 );
v6 = (volatile INT64 *)(v4 + 16);
if( v7 )
{
RtlRbRemoveNode((unsigned __int64 *)v4, v7);
*(_DWORD *)(v7 + 92) |= 2u;
v5 = (void *)v7;
if( (*(_DWORD *)(v7 + 92) & 1) != 0 )
v5 = 0i64;
}
}
if( (_InterlockedExchangeAdd64(v6, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
ExfTryToWakePushLock(v6);
KeAbPostRelease((PVOID)v6);
KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
if( v5 )
MiDeleteHotPatchEntry(v5);
}
}Referenced by:
MiFinishVadDeletion
MiHotPatchImage