MmFreeLoaderBlock
VOID __stdcall MmFreeLoaderBlock(_LOADER_PARAMETER_BLOCK *LoaderBlock){
_LIST_ENTRY *p_MemoryDescriptorListHead;
unsigned int v2;
__int64 v3;
_LIST_ENTRY *Flink;
_LIST_ENTRY *v5;
__int64 v6;
int v7;
_QWORD *Pool;
VOID *v9;
signed __int64 v10;
_MMSUPPORT_INSTANCE *v11;
char v12;
UINT64 v13;
_LIST_ENTRY *v14;
_MMPTE *PteBase;
INT64 v16;
_LIST_ENTRY **v17;
_LIST_ENTRY **v18;
_LIST_ENTRY *v19;
_LIST_ENTRY **v20;
unsigned int v21;
int v22;
_QWORD *v23;
_LIST_ENTRY **p_Blink;
UINT64 v25;
__int64 v26;
_LIST_ENTRY **v27;
unsigned __int64 v28;
_MMPTE *v29;
__int64 v30;
UINT64 v31;
__int64 v32;
_LIST_ENTRY *v33;
_MMPFN *v34;
unsigned __int64 v35;
__int64 *v36;
__int64 v37;
char *v38;
UINT64 v39;
UINT64 v40;
INT64 v41;
char WsleContents;
INT64 v43;
UINT64 v44;
char v45;
UINT64 v46;
int v47;
INT64 v48;
INT64 v49;
char v50;
unsigned int v51;
INT64 v52;
UINT64 v53;
INT64 v54;
VOID *Va;
__int64 *v56;
_MMPFN *v57;
_MMSUPPORT_INSTANCE *AnyMultiplexedVm;
_QWORD *v59;
__int64 v60;
_LIST_ENTRY *Blink;
_LIST_ENTRY *v62;
_MI_TB_FLUSH_LIST TbFlushList[48];
memset(TbFlushList, 0i64, 0xB8u);
p_MemoryDescriptorListHead = &KeLoaderBlock_0->MemoryDescriptorListHead;
v54 = 0i64;
v2 = 0;
v52 = 0i64;
v3 = 0i64;
v62 = p_MemoryDescriptorListHead;
Flink = KeLoaderBlock_0->MemoryDescriptorListHead.Flink;
if( p_MemoryDescriptorListHead->Flink != p_MemoryDescriptorListHead )
{
do
{
v5 = Flink[2].Flink;
v6 = v3;
if( v5 )
{
v7 = (int)Flink[1].Flink;
v3 += (__int64)v5;
if( v7 != 19 )
v3 = v6;
if( v7 == 7 || v7 == 21 || v7 == 14 )
++v2;
}
Flink = Flink->Flink;
}
while( Flink != p_MemoryDescriptorListHead );
v51 = v2;
if( v3 )
{
Pool = MiAllocatePool(64i64, 8 * v3 + 8, 0x624D6D4Dui64);
v59 = Pool;
v10 = (signed __int64)Pool;
if( Pool )
{
*Pool = v3;
*(_QWORD *)&TbFlushList[6] = 0i64;
v56 = Pool + 1;
TbFlushList[2] = 20;
AnyMultiplexedVm = MiGetAnyMultiplexedVm(MiWorkingSetTypeSystemViews, v9);
v11 = AnyMultiplexedVm;
MiLockWorkingSetShared();
v14 = p_MemoryDescriptorListHead->Flink;
v50 = v12;
if( p_MemoryDescriptorListHead->Flink != p_MemoryDescriptorListHead )
{
PteBase = MmGetPteBase();
v16 = (INT64)AnyMultiplexedVm;
do
{
if( LODWORD(v14[1].Flink) == 19 && v14[2].Flink )
{
Va = 0i64;
v31 = 0i64;
Blink = v14[1].Blink;
v32 = (__int64)Blink;
v60 = (_QWORD)PteBase << 25;
MiPteInShadowRange((UINT64)&v53);
v33 = (_LIST_ENTRY *)Va;
v34 = &MmGetPfnDb()[v32];
v57 = v34;
do
{
v35 = v34->PteLong | 0x8000000000000000ui64;
v36 = v56;
v37 = (__int64)((v35 << 25) - v60) >> 16;
*v56 = v37;
v56 = v36 + 1;
Va = (VOID *)v37;
v38 = (char *)MmGetPteBase() + ((v35 >> 9) & 0x7FFFFFFFF8i64);
if( (char *)v31 != v38 )
{
if( v31 )
{
MiFlushTbList(TbFlushList);
MiFreeRegistryPageRange(v54, v52);
MiUnlockPageTableInternal(v16, v31);
}
v31 = (UINT64)v38;
MiLockPageTableInternal(v16, (UINT64)v38, 0i64);
}
LODWORD(v39) = MI_READ_PTE_LOCK_FREE(v35);
v53 = v39;
v40 = v39;
MiMarkPfnTradable((INT64)v34, 0i64);
WsleContents = MiGetWsleContents(v41, v37);
MiWriteWsle(v43, v37, WsleContents & 0xF0 | 0xA);
LODWORD(v44) = MiMakeTransitionPte((v40 >> 12) & 0xFFFFFFFFFi64, 4);
v53 = v44;
v45 = v44;
v46 = v44;
LOBYTE(v47) = MiPteInShadowRange(v35);
if( v47 && (KeGetCurrentThread()->ApcState.Process->Flags3 & 0x1000) != 0 && (v45 & 1) != 0 )
v46 |= 0x8000000000000000ui64;
*(_QWORD *)v35 = v46;
if( TbFlushList[3] )
{
v48 = v54;
v49 = v52 + 1;
}
else
{
v49 = 1i64;
v48 = (INT64)Blink + (_QWORD)v33;
v54 = (INT64)Blink + (_QWORD)v33;
}
v52 = v49;
MiInsertTbFlushEntry(TbFlushList, Va, 1ui64, 0i64);
v33 = (_LIST_ENTRY *)((char *)v33 + 1);
v34 = ++v57;
}
while( v33 < v14[2].Flink );
p_MemoryDescriptorListHead = v62;
MiFlushTbList(TbFlushList);
MiFreeRegistryPageRange(v48, v49);
MiUnlockPageTableInternal(v16, v31);
PteBase = MmGetPteBase();
}
v14 = v14->Flink;
}
while( v14 != p_MemoryDescriptorListHead );
v10 = (signed __int64)v59;
v11 = AnyMultiplexedVm;
v2 = v51;
v12 = v50;
}
LOBYTE(v13) = v12;
MiUnlockWorkingSetShared(v11, v13);
if( _InterlockedCompareExchange64((_QWORD *)&stru_140C4DB30 + 540, v10, 0i64) )
{
*(&stru_140C4DB30 + 540) = v10;
MmFreeBootRegistry();
}
}
}
}
v17 = (_LIST_ENTRY **)MiAllocatePool(64i64, 16i64 * v2, 0x624D6D4Dui64);
v18 = v17;
if( v17 )
{
v19 = p_MemoryDescriptorListHead->Flink;
v20 = v17;
if( p_MemoryDescriptorListHead->Flink != p_MemoryDescriptorListHead )
{
do
{
v21 = (unsigned int)v19[1].Flink;
if( v21 <= 0x15 )
{
v22 = 2113664;
if( _bittest(&v22, v21) )
{
if( v19[2].Flink )
{
*v20 = v19[1].Blink;
v20[1] = v19[2].Flink;
v20 += 2;
}
}
}
v19 = v19->Flink;
}
while( v19 != p_MemoryDescriptorListHead );
if( v20 != v18 )
{
v23 = v20 - 2;
if( v23 >= v18 )
{
p_Blink = &MmGetPfnDb()->ListEntry.Blink;
do
{
v25 = 6i64 * *v23;
v26 = v23[1];
v27 = &MmGetPfnDb()[v25 / 6].ListEntry.Blink;
v28 = (unsigned __int64)*v27 | 0x8000000000000000ui64;
while( --v26 )
{
v27 += 6;
v28 += 8i64;
if( ((unsigned __int64)*v27 | 0x8000000000000000ui64) != v28 )
{
v29 = (_MMPTE *)((unsigned __int64)p_Blink[v25] | 0x8000000000000000ui64);
v30 = (__int64)(v28 - (_QWORD)v29) >> 3;
MiDeleteBootRange(v29, v30, v25 * 8);
v23[1] -= v30;
*v23 += v30;
v23 += 2;
if( v30 )
goto LABEL_31;
break;
}
}
MiDeleteBootRange((_MMPTE *)((unsigned __int64)p_Blink[6 * *v23] | 0x8000000000000000ui64), v23[1], v25 * 8);
LABEL_31:
v23 -= 2;
}
while( v23 >= v18 );
}
}
}
ExFreePoolWithTag(v18, 0);
}
}Referenced by:
KeInitSystem