__int64 __fastcall MmGetSessionCreateTime(__int64 a1){ __int64 v1; v1 = *(_QWORD *)(a1 + 1368); if( !v1 || (*(_DWORD *)(a1 + 2172) & 0x1000) != 0 ) return 0i64; else return *(_QWORD *)(v1 + 1056); }