KiFilterFiberContext

BOOL __stdcall KiFilterFiberContext(INT64 a1){
  NTSTATUS v2; 
  unsigned __int64 v3; 
  unsigned __int128 v4; 
  unsigned __int64 v5; 
  unsigned __int64 v6; 
  unsigned __int128 v7; 
  __int64 v8; 
  unsigned __int64 v9; 
  unsigned __int128 v10; 
  unsigned __int64 v11; 
  NTSTATUS v12; 
  UINT32 v13; 
  char v14; 
  unsigned __int64 v15; 
  unsigned __int128 v16; 
  int v17; 
  unsigned __int64 v18; 
  unsigned __int128 v19; 
  NTSTATUS v20; 
  char v21; 
  NTSTATUS v22; 
  int v23; 
  NTSTATUS v24; 
  char v25; 
  int v26; 
  __int64 *v27; 
  __int64 v28; 
  int Parameter[4]; 
  INT64 v31; 
  int v32; 
  char v33; 
  int v34[4]; 
  INT64 v35; 
  int v36; 
  char v37; 
  int v38[4]; 
  __int64 v39; 
  int v40; 
  char v41; 
  __int64 v42; 
  __int64 v43; 
  _OBJECT_ATTRIBUTES ObjectAttributes; 
  PCALLBACK_OBJECT CallbackObject; 
  __int64 v46; 
  __int64 v47; 
  __int64 v48; 

  v2 = KdDisableDebugger();
  KeKeepData();
  _disable();
  if( !(_BYTE)KdDebuggerNotPresent )
  {
    while( 1 )
      ;
  }
  _enable();
  v3 = __rdtsc();
  v4 = (__ROR8__(v3, 3) ^ v3) * (unsigned __int128)0x7010008004002001ui64;
  v46 = *((_QWORD *)&v4 + 1);
  v5 = ((unsigned __int64)v4 ^ *((_QWORD *)&v4 + 1)) % 0xA;
  if( !Src && !a1 && !__32 )
  {
    if( PsIntegrityCheckEnabled )
    {
      ObjectAttributes.Length = 48;
      ObjectAttributes.ObjectName = (_UNICODE_STRING *)L"TV";
      ObjectAttributes.RootDirectory = 0i64;
      ObjectAttributes.Attributes = 64;
      *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
      if( ExCreateCallback(&CallbackObject, &ObjectAttributes, 0, 0) >= 0 )
      {
        ExNotifyCallback(CallbackObject, sub_1403DCCA0, &__29);
        HalPutDmaAdapter((PADAPTER_OBJECT)CallbackObject);
        if( __29 )
          __32 = 1;
        ExInitializeNPagedLookasideList((PNPAGED_LOOKASIDE_LIST)&Lookaside, 0i64, 0i64, 0x200u, 2800, 0x746E494Bu, 0);
      }
    }
  }
  v6 = __rdtsc();
  v7 = (__ROR8__(v6, 3) ^ v6) * (unsigned __int128)0x7010008004002001ui64;
  v47 = *((_QWORD *)&v7 + 1);
  v8 = v7;
  *(_QWORD *)&v7 = __rdtsc();
  v9 = v8 ^ *((_QWORD *)&v7 + 1);
  Parameter[2] = (v5 < 6) + 1;
  v31 = a1;
  v32 = 1;
  v33 = 0;
  v10 = (__ROR8__(v7, 3) ^ (unsigned __int64)v7) * (unsigned __int128)0x7010008004002001ui64;
  v48 = *((_QWORD *)&v10 + 1);
  v11 = ((unsigned __int64)v10 ^ *((_QWORD *)&v10 + 1)) % 6;
  Parameter[1] = v11;
  Parameter[0] = v9 % 0xD;
  v12 = KeExpandKernelStackAndCallout(sub_140A379E0, Parameter, 49152);
  v14 = v33;
  if( v12 < 0 )
    v14 = 0;
  v33 = v14;
  if( v14 )
  {
    if( v5 < 6 )
    {
      v15 = __rdtsc();
      v16 = (__ROR8__(v15, 3) ^ v15) * (unsigned __int128)0x7010008004002001ui64;
      v42 = *((_QWORD *)&v16 + 1);
      v17 = ((unsigned __int64)v16 ^ *((_QWORD *)&v16 + 1)) % 0xD;
      do
      {
        v18 = __rdtsc();
        v19 = (__ROR8__(v18, 3) ^ v18) * (unsigned __int128)0x7010008004002001ui64;
        v43 = *((_QWORD *)&v19 + 1);
      }
      while( (_DWORD)v11 && ((unsigned __int64)v19 ^ *((_QWORD *)&v19 + 1)) % 6 == (_DWORD)v11 );
      v34[0] = v17;
      v34[1] = ((unsigned __int64)v19 ^ *((_QWORD *)&v19 + 1)) % 6;
      v34[2] = (v5 < 6) + 1;
      v35 = a1;
      v36 = 0;
      v37 = 0;
      v20 = KeExpandKernelStackAndCallout(sub_140A379E0, v34, 49152);
      v21 = v37;
      if( v20 < 0 )
        v21 = 0;
      v37 = v21;
      v14 = v21;
    }
    if( v14 )
    {
      if( !Src && !a1 && (KiSwInterruptPresent() >= 0 || __32) )
      {
        v38[0] = 0;
        v38[1] = 7;
        v38[2] = 1;
        v39 = 0i64;
        v22 = KiSwInterruptPresent();
        v41 = 0;
        v23 = 8;
        if( v22 >= 0 )
          v23 = 0;
        v40 = v23;
        v24 = KeExpandKernelStackAndCallout(sub_140A379E0, v38, 49152);
        v25 = v41;
        if( v24 < 0 )
          v25 = 0;
        v41 = v25;
        v14 = v25;
      }
      if( v14 && !a1 )
      {
        if( qword_140D57650 )
          ExFreePoolWithTag(qword_140D57650, v13);
        v26 = 24;
        v27 = &__2a;
        v28 = 3i64;
        do
        {
          *v27 = 0i64;
          v26 -= 8;
          ++v27;
          --v28;
        }
        while( v28 );
        for( ; v26; --v26 )
        {
          *(_BYTE *)v27 = 0;
          v27 = (__int64 *)((char *)v27 + 1);
        }
        __20 = 0;
        __2b = 0;
        __2c = 0i64;
        dword_140C12E80 = 0;
        qword_140D57080 = 0i64;
      }
    }
  }
  _disable();
  if( !(_BYTE)KdDebuggerNotPresent )
  {
    while( 1 )
      ;
  }
  _enable();
  _disable();
  if( !(_BYTE)KdDebuggerNotPresent )
  {
    while( 1 )
      ;
  }
  _enable();
  if( v2 >= 0 )
    KdEnableDebugger();
  return v14 != 0;
}

Referenced by:

No references.