MiDeleteFinalPageTables

__int64 __fastcall MiDeleteFinalPageTables(ULONG_PTR BugCheckParameter2){
  __int64 v1; 
  __int64 v3; 
  _MMPFN *PfnDb; 
  _ETHREAD *CurrentThread; 
  int i; 
  unsigned __int64 v7; 
  INT64 v8; 
  bool v9; 
  __int64 result; 
  __int128 v11[3]; 
  KAPC_STATE ApcState; 
  v1 = *(_QWORD *)(BugCheckParameter2 + 40) >> 12;
  memset(&ApcState, 0, sizeof(ApcState));
  v3 = 48 * v1;
  memset(v11, 0, sizeof(v11));
  PfnDb = MmGetPfnDb();
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  KiStackAttachProcess((_KPROCESS *)BugCheckParameter2, 0i64, &ApcState);
  for( i = 0; i < 2; ++i )
  {
    if( i )
    {
      v7 = qword_140C4DB88;
      if( !qword_140C4DB88 )
        continue;
    }
    else
    {
      v7 = (unsigned __int64)&UKUSER_SHARED_DATA;
    }
    if( MI_READ_PTE_LOCK_FREE((INT64)MmGetPml4eBase() + 8 * ((v7 >> 39) & 0x1FF)) )
    {
      --*((_WORD *)CurrentThread + 243);
      ExAcquirePushLockExclusiveEx(BugCheckParameter2 + 1224, 0i64);
      *((_BYTE *)CurrentThread + 1304) |= 1u;
      MiDeleteVirtualAddresses(v7, v7, 0, v11);
      UNLOCK_ADDRESS_SPACE((__int64)CurrentThread, BugCheckParameter2);
    }
  }
  MiDeleteVadBitmap((_EPROCESS *)BugCheckParameter2);
  if( (*(_QWORD *)((char *)PfnDb + v3 + 24) & 0x3FFFFFFFFFFFFFFFi64) != 2 )
    KeBugCheckEx(
      0x1Au,
      0x3453ui64,
      BugCheckParameter2,
      v3 / 48,
      *(_QWORD *)((char *)PfnDb + v3 + 24) & 0x3FFFFFFFFFFFFFFFi64);
  MiDeleteProcessShadow();
  KiUnstackDetachProcess(&ApcState, 0i64);
  _interlockedbittestandset((volatile signed __int32 *)(BugCheckParameter2 + 632), 0xAu);
  MiUnlinkProcessFromSession(BugCheckParameter2);
  KeFlushProcessTb(*(_QWORD *)(BugCheckParameter2 + 40));
  v9 = (unsigned int)MiDeleteTopLevelPage(v8, *(_QWORD *)(BugCheckParameter2 + 40) >> 12) == 3;
  result = *((_QWORD *)&v11[0] + 1);
  if( v9 )
    return *((_QWORD *)&v11[0] + 1) + 1i64;
  return result;
}

Referenced by:

MmDeleteProcessAddressSpace