MmScrubMemory

INT64 __stdcall MmScrubMemory(PVOID StopHandle, UINT64 *OutputPagesScrubbed){
  _QWORD *v2; 
  _QWORD *v3; 
  INT64 result; 
  unsigned int v5; 
  __int64 v6; 
  INT64 v7; 
  __int64 v8; 
  int v9; 
  UINT64 *v10; 
  _QWORD *v11; 
  unsigned int v12; 
  _ETHREAD *CurrentThread; 
  _QWORD *v14; 
  int *v15; 
  PADAPTER_OBJECT DmaAdapter; 
  __int64 v17; 
  *v2 = 0i64;
  v3 = v2;
  DmaAdapter = 0i64;
  LODWORD(result) = ObReferenceObjectByHandle(
                      OutputPagesScrubbed,
                      1u,
                      (POBJECT_TYPE)ExEventObjectType,
                      *((_BYTE *)KeGetCurrentThread() + 562),
                      (PVOID *)&DmaAdapter,
                      0i64);
  if( (int)result >= 0 )
  {
    v5 = (unsigned __int16)KeNumberNodes;
    LODWORD(v6) = MiAllocatePool((struct _SLIST_ENTRY *)0x40);
    v8 = v6;
    if( v6 )
    {
      *(_DWORD *)v6 = v5;
      KeInitializeGate((_KGATE *)(v6 + 8), v7);
      *(_QWORD *)(v8 + 32) = DmaAdapter;
      v11 = (_QWORD *)(v8 + 64);
      *(_QWORD *)(v8 + 48) = &MiSystemPartition;
      v12 = 0;
      CurrentThread = (_ETHREAD *)KeGetCurrentThread();
      *(_QWORD *)(v8 + 40) = 0i64;
      *(_QWORD *)(v8 + 56) = CurrentThread;
      if( v5 )
      {
        v14 = (_QWORD *)(v8 + 104);
        do
        {
          *v11 = v8;
          *((_DWORD *)v14 - 8) = v12;
          *(v14 - 3) = 0i64;
          *(v14 - 1) = MiScrubMemoryWorker;
          *v14 = v11;
          ExQueueWorkItemToPartition(v14 - 3);
          ++v12;
          v11 += 28;
          v14 += 28;
        }
        while( v12 < v5 );
      }
      v17 = 0i64;
      v9 = MiScrubProcesses((_MI_PARTITION *)v8, (KEVENT *)&v17, v10);
      KeWaitForGate((PVOID)(v8 + 8), 0);
      if( v9 >= 0 )
      {
        v15 = (int *)v11 + 3;
        while( 1 )
        {
          v15 -= 56;
          if( *v15 < 0 )
            break;
          if( !--v12 )
            goto LABEL_13;
        }
        v9 = *v15;
      }
LABEL_13:
      *v3 = v17 + *(_QWORD *)(v8 + 40);
      ExFreePoolWithTag((PVOID)v8, 0);
      if( *(_DWORD *)(&DmaAdapter->Size + 1) || (*((_DWORD *)KeGetCurrentThread() + 324) & 1) != 0 )
        v9 = -1073741248;
      else
        _InterlockedIncrement(&dword_140C4E518);
    }
    else
    {
      v9 = -1073741670;
    }
    HalPutDmaAdapter(DmaAdapter);
    return(unsigned int)v9;
  }
  return result;
}

Referenced by:

NtSetSystemInformation