MiDereferenceSessionFinal

PVOID __fastcall MiDereferenceSessionFinal(PVOID MemoryMap){
  UINT64 v1; 
  _ETHREAD *CurrentThread; 
  INT64 v3; 
  unsigned __int64 v4; 
  _MI_PARTITION *v5; 
  _MI_PARTITION *v6; 
  void *v7; 
  void *v8; 
  UINT64 v9; 
  void(__fastcall *v10)(_QWORD); 
  _ETHREAD *v11; 
  INT64 v12; 
  INT64 v13; 
  INT64 v14; 
  INT64 v15; 
  int v16; 
  INT64 v17; 
  PVOID result; 
  void *v19; 
  __int128 v20; 
  __int128 v21; 
  __int128 v22; 
  int InstanceId; 
  v20 = 0i64;
  v21 = 0i64;
  v22 = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  v3 = *((_QWORD *)CurrentThread + 23);
  v4 = *(_QWORD *)(v3 + 1368);
  LODWORD(v5) = MiPartitionIdToPointer(*(_WORD *)(v4 + 430), v1);
  v6 = v5;
  MiMarkSessionDeletePending(v4);
  if( *(_QWORD *)(v4 + 80) )
  {
    KeSetEvent(*(PRKEVENT *)(v4 + 72), 1);
    ObCloseHandle(*(PVOID *)(v4 + 80), 0);
  }
  v10 = *(void(__fastcall **)(_QWORD))(v4 + 680);
  if( (unsigned __int64)v10 > 1 )
    v10(0i64);
  MiSessionUnloadAllImages(v8, v7, v9);
  MiUnlinkSessionWorkingSet(v4);
  InstanceId = *(_DWORD *)(v4 + 8);
  v11 = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)v11 + 242);
  ExpWnfDeleteScopeById(WnfDataScopeSession, &InstanceId, 4ui64);
  KeLeaveCriticalRegion();
  MiFreeSessionSpaceMap();
  v16 = *(_DWORD *)(v4 + 4);
  if( (v16 & 1) != 0 )
  {
    ExCleanupSessionHeapManager(v13, v12, v14, v15);
    *(_DWORD *)(v4 + 4) |= 0x100u;
    MiCheckSessionPoolAllocations();
    v16 = *(_DWORD *)(v4 + 4);
  }
  if( (v16 & 0x180) == 128 )
    ExCleanupSessionHeapManager(v13, v12, v14, v15);
  --*((_WORD *)CurrentThread + 243);
  ExAcquirePushLockExclusiveEx((UINT64)&P2, 0i64);
  *(_DWORD *)(v4 + 4) |= 0x20u;
  if( (_InterlockedExchangeAdd64((volatile signed __int64 *)&P2, 0xFFFFFFFFFFFFFFFFui64) & 6) == 2 )
    ExfTryToWakePushLock((volatile INT64 *)&P2);
  KeAbPostRelease(&P2);
  KiLeaveGuardedRegionUnsafe((__int64)CurrentThread);
  if( *(_QWORD *)(v3 + 1184) )
  {
    MiSessionUnlinkProcess(v17, v3);
    *(_QWORD *)(v3 + 1184) = 0i64;
  }
  MiDeleteSessionAddressSpace(v4, (__int64)&v20);
  MiDetachProcessFromSession(0i64);
  MiReturnCommit(v6, *((_QWORD *)&v21 + 1) - *((_QWORD *)&v20 + 1));
  MiReturnResident((INT64)v6, v20);
  result = (PVOID)MiReturnResident((INT64)v6, *(_QWORD *)(v4 + 368));
  v19 = *(void **)(v4 + 1048);
  if( v19 )
    LODWORD(result) = ObfDereferenceObjectWithTag(v19, 0x73536D4Dui64);
  *(_QWORD *)(v4 + 1048) = 0i64;
  return result;
}

Referenced by:

MiDereferenceSession