WbDispatchOperation
NTSTATUS __stdcall WbDispatchOperation(PVOID Src, SIZE_T a2){
UINT64 v2;
char *v4;
NTSTATUS WarbirdProcess;
int *v6;
int v7;
_BOOL8 v8;
HANDLE ProcessId;
INT64 v10;
NTSTATUS v11;
int v13;
INT64 a1;
PVOID P;
v2 = (unsigned int)a2;
a1 = 0i64;
P = 0i64;
if( Src )
{
if( (unsigned int)a2 < 8 )
{
WarbirdProcess = -1073741811;
goto LABEL_18;
}
v4 = (char *)Src + (unsigned int)a2;
if( (unsigned __int64)v4 > 0x7FFFFFFF0000i64 || v4 < Src )
MEMORY[0x7FFFFFFF0000] = 0;
WarbirdProcess = WbAlloc((unsigned int)a2);
if( WarbirdProcess < 0 )
goto LABEL_18;
v6 = (int *)P;
memmove((UINT8 *)P, (UINT8 *)Src, v2);
v7 = *v6;
v13 = *v6;
}
else
{
v7 = 4;
v13 = 4;
}
v8 = v7 != 7;
ProcessId = PsGetProcessId(*((PEPROCESS *)KeGetCurrentThread() + 23));
WarbirdProcess = WbGetWarbirdProcess((INT64)ProcessId, v8, (INT64 **)&a1);
if( WarbirdProcess < 0 )
goto LABEL_18;
switch( v13 )
{
case 1:
v11 = WbDecryptEncryptionSegment(a1, (struct wil_details_FeatureReportingCache *)P, (unsigned int)v2);
goto LABEL_17;
case 2:
v11 = WbReEncryptEncryptionSegment(a1, (struct wil_details_FeatureReportingCache *)P, (unsigned int)v2);
goto LABEL_17;
case 3:
v11 = WbHeapExecuteCall((UINT64 *)a1, (INT64)P, (UINT8 *)Src, (unsigned int)v2);
goto LABEL_17;
case 4:
if( !P )
{
v11 = sub_14065EC80(a1, v10);
LABEL_17:
WarbirdProcess = v11;
goto LABEL_18;
}
break;
case 5:
case 6:
WarbirdProcess = Src != 0i64 ? -1073741822 : -1073741811;
goto LABEL_18;
case 7:
v11 = WbRemoveWarbirdProcess(*(_QWORD *)a1);
goto LABEL_17;
case 8:
v11 = WbProcessStartup(a1, P, (unsigned int)v2);
goto LABEL_17;
case 9:
v11 = WbProcessModuleUnload(a1, P, (unsigned int)v2);
goto LABEL_17;
}
WarbirdProcess = -1073741811;
LABEL_18:
sub_14065E8E4((volatile signed __int64 *)a1);
if( P )
ExFreePoolWithTag(P, 0x42524157u);
return WarbirdProcess;
}Referenced by:
ExpQuerySystemInformation