IoRevokeHandlesForProcess
NTSTATUS __stdcall IoRevokeHandlesForProcess(_UNICODE_STRING *TargetDevicePath, _EPROCESS *Process){
unsigned int *v5;
int v6;
DEVICE_OBJECT *DevicePDO;
DEVICE_OBJECT *v8;
UINT64 v9;
PVOID Object[2];
_OBJECT_ATTRIBUTES ObjectAttributes;
_DWORD result[4];
int v13;
int v14;
void *v15;
__int128 v16;
__int128 v17;
_EJOB *Silo;
PVOID Handle;
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
if( !PsIsProcessAppContainer(Process) )
return 0;
v5 = (unsigned int *)ObReferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)Process);
if( !v5 )
return -1073741811;
memset((INT64)result, 0i64);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Length = 48;
v16 = 0i64;
ObjectAttributes.Attributes = 576;
ObjectAttributes.ObjectName = TargetDevicePath;
LOWORD(v16) = 40;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
result[0] = 14155784;
v14 = 1;
v17 = 0i64;
Silo = (_EJOB *)1;
Silo = PsGetCurrentSilo();
LODWORD(v9) = 0;
v6 = ObOpenObjectByNameEx(&ObjectAttributes, (_OBJECT_TYPE *)IoFileObjectType, 0, 0i64, v9, result, Silo, &Handle);
if( v14 == -1096154543 )
{
v6 = v13;
if( v13 >= 0 )
{
Object[0] = v15;
Object[1] = Process;
ExEnumHandleTable(
v5,
(__int64(__fastcall *)(unsigned int *, __int64 *, __int64, __int64))IopCheckHandleForRevocation,
(__int64)Object,
0i64);
DevicePDO = IopGetDevicePDO((DEVICE_OBJECT *)Object[0]);
v8 = DevicePDO;
if( DevicePDO )
{
PnpDisableUserModeNotifications((__int64)DevicePDO, (__int64)Process);
ObfDereferenceObjectWithTag(v8, 0x746C6644ui64);
}
ObfDereferenceObjectWithTag(Object[0], 0x746C6644ui64);
}
}
ObDereferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)Process);
return v6;
}Referenced by:
NtSetInformationProcess