PiSwProcessParentRemoveIrp

VOID __stdcall PiSwProcessParentRemoveIrp(DEVICE_OBJECT *ParentDeviceObject){
  DEVICE_OBJECT *v1; 
  UNICODE_STRING *v2; 
  _ETHREAD *CurrentThread; 
  __int64 *v4; 
  __int64 *v5; 
  WCHAR *Buffer; 
  INT64 SwDevice; 
  __int64 v8; 
  v1 = ParentDeviceObject;
  if( ParentDeviceObject )
    ParentDeviceObject = *(DEVICE_OBJECT **)(*((_QWORD *)ParentDeviceObject + 39) + 40i64);
  v2 = (UNICODE_STRING *)(((unsigned __int64)ParentDeviceObject + 40) & -(__int64)(ParentDeviceObject != 0i64));
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  ExAcquireResourceExclusiveLite((ERESOURCE *)PiSwLockObj, 1u);
  v4 = (__int64 *)PiSwGlobalPdoAssociationList;
  while( v4 != &PiSwGlobalPdoAssociationList )
  {
    v5 = v4;
    v4 = (__int64 *)*v4;
    if( (DEVICE_OBJECT *)v5[2] == v1 )
    {
      v8 = v5[3];
      if( (*(_DWORD *)(*(_QWORD *)(v8 + 64) + 8i64) & 0x20) == 0 )
        PiSwProcessRemove((DEVICE_OBJECT *)v8, 0);
      PiSwDestroyDeviceObject((DEVICE_OBJECT *)v8);
    }
  }
  if( v2 )
  {
    Buffer = v2->Buffer;
    if( Buffer )
    {
      SwDevice = PiSwFindSwDevice(Buffer);
      if( !SwDevice || (*(_DWORD *)(SwDevice + 4) & 1) == 0 && !*(_DWORD *)(SwDevice + 180) )
        PiSwCloseDescendants(v2);
    }
  }
  ExReleaseResourceLite((PERESOURCE)PiSwLockObj);
  KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
}

Referenced by:

IopRemoveDevice