ObShutdownSystem
VOID __stdcall ObShutdownSystem(UINT64 Phase){
WCHAR v1;
PADAPTER_OBJECT v2;
_QWORD *v3;
void *v4;
WCHAR v5;
WCHAR v6;
struct _DMA_ADAPTER *v7;
struct _DMA_ADAPTER *v8;
unsigned int v9;
unsigned int v10;
__int64 v11;
unsigned __int16 *v12;
unsigned __int16 *v13;
unsigned __int16 *v14;
struct _DMA_ADAPTER *v15;
struct _DMA_ADAPTER *v16;
struct _DMA_ADAPTER *v17;
_OBJECT_TYPE *v18;
char v19;
__int64 v20;
_ETHREAD *CurrentThread;
unsigned __int16 *v22;
struct _DMA_ADAPTER **v23;
int v24;
unsigned __int16 *v25;
_OBJECT_TYPE *v26;
struct _UNICODE_STRING DestinationString;
int v28;
int v29;
int v30;
PVOID Object;
if( (_DWORD)Phase )
{
if( (_DWORD)Phase == 1 )
{
v30 = 0;
ExEnumHandleTable(
*((unsigned int **)PsInitialSystemProcess + 174),
(__int64(__fastcall *)(unsigned int *, __int64 *, __int64, __int64))ObpShutdownCloseHandleProcedure,
(__int64)&v30,
0i64);
}
else
{
v2 = ObpTypeObjectType;
Object = 0i64;
DestinationString = 0i64;
v3 = *(_QWORD **)&ObpTypeObjectType->Version;
while( v3 != (_QWORD *)v2 )
{
v4 = v3 + 10;
v3 = (_QWORD *)*v3;
Object = v4;
ObMakeTemporaryObject(v4);
}
RtlInitUnicodeString(&DestinationString, L"DosDevices", v1);
if( ObReferenceObjectByName(
(unsigned __int64)&DestinationString,
64,
0i64,
0,
(__int64)ObpSymbolicLinkObjectType,
0,
0i64,
(PADAPTER_OBJECT *)&Object) >= 0 )
{
ObMakeTemporaryObject(Object);
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
}
RtlInitUnicodeString(&DestinationString, L"Global", v5);
if( ObReferenceObjectByName(
(unsigned __int64)&DestinationString,
64,
0i64,
0,
(__int64)ObpSymbolicLinkObjectType,
0,
0i64,
(PADAPTER_OBJECT *)&Object) >= 0 )
{
ObMakeTemporaryObject(Object);
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
}
RtlInitUnicodeString(&DestinationString, L"GLOBALROOT", v6);
if( ObReferenceObjectByName(
(unsigned __int64)&DestinationString,
64,
0i64,
0,
(__int64)ObpSymbolicLinkObjectType,
0,
0i64,
(PADAPTER_OBJECT *)&Object) >= 0 )
{
ObMakeTemporaryObject(Object);
HalPutDmaAdapter((PADAPTER_OBJECT)Object);
}
HalPutDmaAdapter((PADAPTER_OBJECT)ObpRootDirectoryObject);
HalPutDmaAdapter((PADAPTER_OBJECT)ObpDirectoryObjectType);
HalPutDmaAdapter((PADAPTER_OBJECT)ObpSymbolicLinkObjectType);
HalPutDmaAdapter(ObpTypeDirectoryObject);
HalPutDmaAdapter(ObpTypeObjectType);
}
}
else
{
v7 = (struct _DMA_ADAPTER *)ObpRootDirectoryObject;
v28 = 1;
v8 = 0i64;
v9 = 1;
v10 = 1;
if( ObpRootDirectoryObject )
{
LABEL_15:
while( 2 )
{
v11 = 0i64;
LABEL_16:
v29 = v11;
if( (unsigned int)v11 < 0x25 )
{
v12 = &v7->Version + 4 * v11;
v13 = *(unsigned __int16 **)v12;
v14 = v12;
v25 = v12;
while( 1 )
{
if( !v13 )
{
v11 = (unsigned int)(v29 + 1);
goto LABEL_16;
}
v15 = (struct _DMA_ADAPTER *)*((_QWORD *)v13 + 1);
v16 = v8;
v17 = v8;
v18 = (_OBJECT_TYPE *)ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ LOBYTE(v15[-2].DmaOperations) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)v15 - 48) >> 8)];
v19 = BYTE2(v15[-2].DmaOperations);
v26 = v18;
if( (v19 & 2) != 0 )
{
v20 = (__int64)&v15[-3] - *((unsigned __int8 *)ObpInfoMaskToOffset + (v19 & 3));
v18 = (_OBJECT_TYPE *)ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ LOBYTE(v15[-2].DmaOperations) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)v15 - 48) >> 8)];
}
else
{
v20 = 0i64;
}
if( v8 )
{
if( v15 == v8 && (v8 = 0i64, v10 > v9) )
{
v10 = v9;
v14 = v12;
v28 = v9;
}
else
{
v8 = 0i64;
v14 = v13;
if( v15 != v17 )
v8 = v16;
}
}
else if( v18 == (_OBJECT_TYPE *)ObpTypeObjectType )
{
v14 = v13;
}
else
{
if( v18 == ObpDirectoryObjectType )
{
++v9;
v7 = (struct _DMA_ADAPTER *)*((_QWORD *)v13 + 1);
goto LABEL_15;
}
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquirePushLockExclusiveEx((UINT64)&v15[-2], 0i64);
BYTE3(v15[-2].DmaOperations) &= ~0x10u;
ExReleasePushLockEx((UINT64)&v15[-2], 0i64);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
v22 = *(unsigned __int16 **)v14;
if( v15[-3].DmaOperations )
{
v10 = v28;
v14 = *(unsigned __int16 **)v14;
}
else
{
*(_QWORD *)v14 = *(_QWORD *)v22;
ExFreePoolWithTag(v22, 0);
if( (v26->TypeInfo.ObjectTypeFlags & 8) == 0 )
{
LOBYTE(v24) = 0;
v26->TypeInfo.SecurityProcedure(
v15,
DeleteSecurityDescriptor,
0i64,
0i64,
0i64,
(void **)&v15[-1].DmaOperations,
v26->TypeInfo.PoolType,
0i64,
v24);
}
if( v26 == ObpSymbolicLinkObjectType )
{
v10 = v9;
v28 = v9;
ObpDeleteSymbolicLinkName((__int64)v15);
v14 = v25;
}
else
{
v10 = v28;
}
ExFreePoolWithTag(*(PVOID *)(v20 + 16), 0);
*(_QWORD *)(v20 + 16) = 0i64;
*(_DWORD *)(v20 + 8) = 0;
*(_QWORD *)v20 = 0i64;
HalPutDmaAdapter(v15);
HalPutDmaAdapter(v7);
}
v12 = v25;
}
v13 = *(unsigned __int16 **)v14;
}
}
--v9;
if( (BYTE2(v7[-2].DmaOperations) & 2) != 0 )
v23 = (struct _DMA_ADAPTER **)((char *)&v7[-3]
- *((unsigned __int8 *)ObpInfoMaskToOffset + (BYTE2(v7[-2].DmaOperations) & 3)));
else
v23 = 0i64;
v8 = v7;
v7 = *v23;
if( *v23 )
continue;
break;
}
}
}
}Referenced by:
PoBroadcastSystemState
PopGracefulShutdown