ObShutdownSystem

VOID __stdcall ObShutdownSystem(UINT64 Phase){
  WCHAR v1; 
  PADAPTER_OBJECT v2; 
  _QWORD *v3; 
  void *v4; 
  WCHAR v5; 
  WCHAR v6; 
  struct _DMA_ADAPTER *v7; 
  struct _DMA_ADAPTER *v8; 
  unsigned int v9; 
  unsigned int v10; 
  __int64 v11; 
  unsigned __int16 *v12; 
  unsigned __int16 *v13; 
  unsigned __int16 *v14; 
  struct _DMA_ADAPTER *v15; 
  struct _DMA_ADAPTER *v16; 
  struct _DMA_ADAPTER *v17; 
  _OBJECT_TYPE *v18; 
  char v19; 
  __int64 v20; 
  _ETHREAD *CurrentThread; 
  unsigned __int16 *v22; 
  struct _DMA_ADAPTER **v23; 
  int v24; 
  unsigned __int16 *v25; 
  _OBJECT_TYPE *v26; 
  struct _UNICODE_STRING DestinationString; 
  int v28; 
  int v29; 
  int v30; 
  PVOID Object; 
  if( (_DWORD)Phase )
  {
    if( (_DWORD)Phase == 1 )
    {
      v30 = 0;
      ExEnumHandleTable(
        *((unsigned int **)PsInitialSystemProcess + 174),
        (__int64(__fastcall *)(unsigned int *, __int64 *, __int64, __int64))ObpShutdownCloseHandleProcedure,
        (__int64)&v30,
        0i64);
    }
    else
    {
      v2 = ObpTypeObjectType;
      Object = 0i64;
      DestinationString = 0i64;
      v3 = *(_QWORD **)&ObpTypeObjectType->Version;
      while( v3 != (_QWORD *)v2 )
      {
        v4 = v3 + 10;
        v3 = (_QWORD *)*v3;
        Object = v4;
        ObMakeTemporaryObject(v4);
      }
      RtlInitUnicodeString(&DestinationString, L"DosDevices", v1);
      if( ObReferenceObjectByName(
             (unsigned __int64)&DestinationString,
             64,
             0i64,
             0,
             (__int64)ObpSymbolicLinkObjectType,
             0,
             0i64,
             (PADAPTER_OBJECT *)&Object) >= 0 )
      {
        ObMakeTemporaryObject(Object);
        HalPutDmaAdapter((PADAPTER_OBJECT)Object);
      }
      RtlInitUnicodeString(&DestinationString, L"Global", v5);
      if( ObReferenceObjectByName(
             (unsigned __int64)&DestinationString,
             64,
             0i64,
             0,
             (__int64)ObpSymbolicLinkObjectType,
             0,
             0i64,
             (PADAPTER_OBJECT *)&Object) >= 0 )
      {
        ObMakeTemporaryObject(Object);
        HalPutDmaAdapter((PADAPTER_OBJECT)Object);
      }
      RtlInitUnicodeString(&DestinationString, L"GLOBALROOT", v6);
      if( ObReferenceObjectByName(
             (unsigned __int64)&DestinationString,
             64,
             0i64,
             0,
             (__int64)ObpSymbolicLinkObjectType,
             0,
             0i64,
             (PADAPTER_OBJECT *)&Object) >= 0 )
      {
        ObMakeTemporaryObject(Object);
        HalPutDmaAdapter((PADAPTER_OBJECT)Object);
      }
      HalPutDmaAdapter((PADAPTER_OBJECT)ObpRootDirectoryObject);
      HalPutDmaAdapter((PADAPTER_OBJECT)ObpDirectoryObjectType);
      HalPutDmaAdapter((PADAPTER_OBJECT)ObpSymbolicLinkObjectType);
      HalPutDmaAdapter(ObpTypeDirectoryObject);
      HalPutDmaAdapter(ObpTypeObjectType);
    }
  }
  else
  {
    v7 = (struct _DMA_ADAPTER *)ObpRootDirectoryObject;
    v28 = 1;
    v8 = 0i64;
    v9 = 1;
    v10 = 1;
    if( ObpRootDirectoryObject )
    {
LABEL_15:
      while( 2 )
      {
        v11 = 0i64;
LABEL_16:
        v29 = v11;
        if( (unsigned int)v11 < 0x25 )
        {
          v12 = &v7->Version + 4 * v11;
          v13 = *(unsigned __int16 **)v12;
          v14 = v12;
          v25 = v12;
          while( 1 )
          {
            if( !v13 )
            {
              v11 = (unsigned int)(v29 + 1);
              goto LABEL_16;
            }
            v15 = (struct _DMA_ADAPTER *)*((_QWORD *)v13 + 1);
            v16 = v8;
            v17 = v8;
            v18 = (_OBJECT_TYPE *)ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ LOBYTE(v15[-2].DmaOperations) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)v15 - 48) >> 8)];
            v19 = BYTE2(v15[-2].DmaOperations);
            v26 = v18;
            if( (v19 & 2) != 0 )
            {
              v20 = (__int64)&v15[-3] - *((unsigned __int8 *)ObpInfoMaskToOffset + (v19 & 3));
              v18 = (_OBJECT_TYPE *)ObTypeIndexTable[(unsigned __int8)ObHeaderCookie ^ LOBYTE(v15[-2].DmaOperations) ^ (unsigned __int64)(unsigned __int8)((unsigned __int16)((_WORD)v15 - 48) >> 8)];
            }
            else
            {
              v20 = 0i64;
            }
            if( v8 )
            {
              if( v15 == v8 && (v8 = 0i64, v10 > v9) )
              {
                v10 = v9;
                v14 = v12;
                v28 = v9;
              }
              else
              {
                v8 = 0i64;
                v14 = v13;
                if( v15 != v17 )
                  v8 = v16;
              }
            }
            else if( v18 == (_OBJECT_TYPE *)ObpTypeObjectType )
            {
              v14 = v13;
            }
            else
            {
              if( v18 == ObpDirectoryObjectType )
              {
                ++v9;
                v7 = (struct _DMA_ADAPTER *)*((_QWORD *)v13 + 1);
                goto LABEL_15;
              }
              CurrentThread = (_ETHREAD *)KeGetCurrentThread();
              --*((_WORD *)CurrentThread + 242);
              ExAcquirePushLockExclusiveEx((UINT64)&v15[-2], 0i64);
              BYTE3(v15[-2].DmaOperations) &= ~0x10u;
              ExReleasePushLockEx((UINT64)&v15[-2], 0i64);
              KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
              v22 = *(unsigned __int16 **)v14;
              if( v15[-3].DmaOperations )
              {
                v10 = v28;
                v14 = *(unsigned __int16 **)v14;
              }
              else
              {
                *(_QWORD *)v14 = *(_QWORD *)v22;
                ExFreePoolWithTag(v22, 0);
                if( (v26->TypeInfo.ObjectTypeFlags & 8) == 0 )
                {
                  LOBYTE(v24) = 0;
                  v26->TypeInfo.SecurityProcedure(
                    v15,
                    DeleteSecurityDescriptor,
                    0i64,
                    0i64,
                    0i64,
                    (void **)&v15[-1].DmaOperations,
                    v26->TypeInfo.PoolType,
                    0i64,
                    v24);
                }
                if( v26 == ObpSymbolicLinkObjectType )
                {
                  v10 = v9;
                  v28 = v9;
                  ObpDeleteSymbolicLinkName((__int64)v15);
                  v14 = v25;
                }
                else
                {
                  v10 = v28;
                }
                ExFreePoolWithTag(*(PVOID *)(v20 + 16), 0);
                *(_QWORD *)(v20 + 16) = 0i64;
                *(_DWORD *)(v20 + 8) = 0;
                *(_QWORD *)v20 = 0i64;
                HalPutDmaAdapter(v15);
                HalPutDmaAdapter(v7);
              }
              v12 = v25;
            }
            v13 = *(unsigned __int16 **)v14;
          }
        }
        --v9;
        if( (BYTE2(v7[-2].DmaOperations) & 2) != 0 )
          v23 = (struct _DMA_ADAPTER **)((char *)&v7[-3]
                                       - *((unsigned __int8 *)ObpInfoMaskToOffset + (BYTE2(v7[-2].DmaOperations) & 3)));
        else
          v23 = 0i64;
        v8 = v7;
        v7 = *v23;
        if( *v23 )
          continue;
        break;
      }
    }
  }
}

Referenced by:

PoBroadcastSystemState
PopGracefulShutdown