IoRevokeHandlesForProcess

NTSTATUS __stdcall IoRevokeHandlesForProcess(_UNICODE_STRING *TargetDevicePath, _EPROCESS *Process){
  unsigned int *v5; 
  int v6; 
  DEVICE_OBJECT *DevicePDO; 
  DEVICE_OBJECT *v8; 
  UINT64 v9; 
  PVOID Object[2]; 
  _OBJECT_ATTRIBUTES ObjectAttributes; 
  _DWORD result[4]; 
  int v13; 
  int v14; 
  void *v15; 
  __int128 v16; 
  __int128 v17; 
  _EJOB *Silo; 
  PVOID Handle; 
  *(&ObjectAttributes.Length + 1) = 0;
  *(&ObjectAttributes.Attributes + 1) = 0;
  if( !PsIsProcessAppContainer(Process) )
    return 0;
  v5 = (unsigned int *)ObReferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)Process);
  if( !v5 )
    return -1073741811;
  memset((INT64)result, 0i64);
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.Length = 48;
  v16 = 0i64;
  ObjectAttributes.Attributes = 576;
  ObjectAttributes.ObjectName = TargetDevicePath;
  LOWORD(v16) = 40;
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  result[0] = 14155784;
  v14 = 1;
  v17 = 0i64;
  Silo = (_EJOB *)1;
  Silo = PsGetCurrentSilo();
  LODWORD(v9) = 0;
  v6 = ObOpenObjectByNameEx(&ObjectAttributes, (_OBJECT_TYPE *)IoFileObjectType, 0, 0i64, v9, result, Silo, &Handle);
  if( v14 == -1096154543 )
  {
    v6 = v13;
    if( v13 >= 0 )
    {
      Object[0] = v15;
      Object[1] = Process;
      ExEnumHandleTable(
        v5,
        (__int64(__fastcall *)(unsigned int *, __int64 *, __int64, __int64))IopCheckHandleForRevocation,
        (__int64)Object,
        0i64);
      DevicePDO = IopGetDevicePDO((DEVICE_OBJECT *)Object[0]);
      v8 = DevicePDO;
      if( DevicePDO )
      {
        PnpDisableUserModeNotifications((__int64)DevicePDO, (__int64)Process);
        ObfDereferenceObjectWithTag(v8, 0x746C6644ui64);
      }
      ObfDereferenceObjectWithTag(Object[0], 0x746C6644ui64);
    }
  }
  ObDereferenceProcessHandleTable((struct _EX_RUNDOWN_REF *)Process);
  return v6;
}

Referenced by:

NtSetInformationProcess