MiDeleteFinalPageTables
__int64 __fastcall MiDeleteFinalPageTables(ULONG_PTR BugCheckParameter2){
__int64 v1;
__int64 v3;
_MMPFN *PfnDb;
_ETHREAD *CurrentThread;
int i;
unsigned __int64 v7;
INT64 v8;
bool v9;
__int64 result;
__int128 v11[3];
KAPC_STATE ApcState;
v1 = *(_QWORD *)(BugCheckParameter2 + 40) >> 12;
memset(&ApcState, 0, sizeof(ApcState));
v3 = 48 * v1;
memset(v11, 0, sizeof(v11));
PfnDb = MmGetPfnDb();
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
KiStackAttachProcess((_KPROCESS *)BugCheckParameter2, 0i64, &ApcState);
for( i = 0; i < 2; ++i )
{
if( i )
{
v7 = qword_140C4DB88;
if( !qword_140C4DB88 )
continue;
}
else
{
v7 = (unsigned __int64)&UKUSER_SHARED_DATA;
}
if( MI_READ_PTE_LOCK_FREE((INT64)MmGetPml4eBase() + 8 * ((v7 >> 39) & 0x1FF)) )
{
--*((_WORD *)CurrentThread + 243);
ExAcquirePushLockExclusiveEx(BugCheckParameter2 + 1224, 0i64);
*((_BYTE *)CurrentThread + 1304) |= 1u;
MiDeleteVirtualAddresses(v7, v7, 0, v11);
UNLOCK_ADDRESS_SPACE((__int64)CurrentThread, BugCheckParameter2);
}
}
MiDeleteVadBitmap((_EPROCESS *)BugCheckParameter2);
if( (*(_QWORD *)((char *)PfnDb + v3 + 24) & 0x3FFFFFFFFFFFFFFFi64) != 2 )
KeBugCheckEx(
0x1Au,
0x3453ui64,
BugCheckParameter2,
v3 / 48,
*(_QWORD *)((char *)PfnDb + v3 + 24) & 0x3FFFFFFFFFFFFFFFi64);
MiDeleteProcessShadow();
KiUnstackDetachProcess(&ApcState, 0i64);
_interlockedbittestandset((volatile signed __int32 *)(BugCheckParameter2 + 632), 0xAu);
MiUnlinkProcessFromSession(BugCheckParameter2);
KeFlushProcessTb(*(_QWORD *)(BugCheckParameter2 + 40));
v9 = (unsigned int)MiDeleteTopLevelPage(v8, *(_QWORD *)(BugCheckParameter2 + 40) >> 12) == 3;
result = *((_QWORD *)&v11[0] + 1);
if( v9 )
return *((_QWORD *)&v11[0] + 1) + 1i64;
return result;
}Referenced by:
MmDeleteProcessAddressSpace