CmpCallbackFillObjectContext

VOID __stdcall CmpCallbackFillObjectContext(REG_NOTIFY_CLASS Type, VOID *Argument, LARGE_INTEGER *Cookie){
  _DWORD *v5; 
  __int64 v6; 
  _QWORD *v7; 
  _DWORD *v8; 
  __int64 v9; 
  _QWORD *v10; 
  _DWORD *v11; 
  __int64 v12; 
  _QWORD *v13; 
  _DWORD *v14; 
  __int64 v15; 
  _QWORD *v16; 
  _DWORD *v17; 
  __int64 v18; 
  _QWORD *v19; 
  _DWORD *v20; 
  _QWORD *v21; 
  _ETHREAD *v22; 
  _QWORD *v23; 
  LONGLONG v24; 
  _DWORD *v25; 
  _QWORD *v26; 
  _ETHREAD *v27; 
  LONGLONG v28; 
  _ETHREAD *v29; 
  _QWORD *v30; 
  LONGLONG v31; 
  _ETHREAD *CurrentThread; 
  _QWORD *v33; 
  LONGLONG QuadPart; 
  _ETHREAD *v35; 
  LONGLONG v36; 
  _ETHREAD *v37; 
  _QWORD *v38; 
  LONGLONG v39; 
  _ETHREAD *v40; 
  _QWORD *v41; 
  LONGLONG v42; 

  switch( Type )
  {
    case RegNtPostOpenKeyEx:
LABEL_15:
      v9 = 0i64;
LABEL_14:
      *((_QWORD *)Argument + 5) = v9;
      return;
    case RegNtPreOpenKeyEx:
LABEL_16:
      v11 = (_DWORD *)*((_QWORD *)Argument + 1);
      v12 = 0i64;
      if( v11 )
      {
        if( *v11 == 1803104306 )
        {
          v13 = v11 + 18;
          if( (_QWORD *)*v13 != v13 )
          {
            CurrentThread = (_ETHREAD *)KeGetCurrentThread();
            --CurrentThread->Tcb.KernelApcDisable;
            ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
            v33 = (_QWORD *)*v13;
            if( (_QWORD *)*v13 != v13 )
            {
              QuadPart = Cookie->QuadPart;
              while( v33[4] != QuadPart )
              {
                if( v33[4] >= QuadPart )
                {
                  v33 = (_QWORD *)*v33;
                  if( v33 != v13 )
                    continue;
                }
                goto LABEL_61;
              }
              v12 = v33[7];
            }
LABEL_61:
            ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
            KeLeaveCriticalRegionThread(KeGetCurrentThread());
          }
        }
      }
      *((_QWORD *)Argument + 11) = v12;
      break;
    case RegNtPostQueryValueKey:
LABEL_11:
      v8 = *(_DWORD **)Argument;
      v9 = 0i64;
      if( *(_QWORD *)Argument )
      {
        if( *v8 == 1803104306 )
        {
          v10 = v8 + 18;
          if( (_QWORD *)*v10 != v10 )
          {
            v29 = (_ETHREAD *)KeGetCurrentThread();
            --v29->Tcb.KernelApcDisable;
            ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
            v30 = (_QWORD *)*v10;
            if( (_QWORD *)*v10 != v10 )
            {
              v31 = Cookie->QuadPart;
              while( v30[4] != v31 )
              {
                if( v30[4] >= v31 )
                {
                  v30 = (_QWORD *)*v30;
                  if( v30 != v10 )
                    continue;
                }
                goto LABEL_56;
              }
              v9 = v30[7];
            }
LABEL_56:
            ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
            KeLeaveCriticalRegionThread(KeGetCurrentThread());
          }
        }
      }
      goto LABEL_14;
    case RegNtQueryValueKey:
      v14 = *(_DWORD **)Argument;
      v15 = 0i64;
      if( *(_QWORD *)Argument )
      {
        if( *v14 == 1803104306 )
        {
          v16 = v14 + 18;
          if( (_QWORD *)*v16 != v16 )
          {
            v37 = (_ETHREAD *)KeGetCurrentThread();
            --v37->Tcb.KernelApcDisable;
            ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
            v38 = (_QWORD *)*v16;
            if( (_QWORD *)*v16 != v16 )
            {
              v39 = Cookie->QuadPart;
              while( v38[4] != v39 )
              {
                if( v38[4] >= v39 )
                {
                  v38 = (_QWORD *)*v38;
                  if( v38 != v16 )
                    continue;
                }
                goto LABEL_76;
              }
              v15 = v38[7];
            }
LABEL_76:
            ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
            KeLeaveCriticalRegionThread(KeGetCurrentThread());
          }
        }
      }
      *((_QWORD *)Argument + 7) = v15;
      break;
    case RegNtPostQueryKey:
      goto LABEL_11;
    default:
      switch( Type )
      {
        case RegNtDeleteKey:
        case RegNtPreFlushKey:
          *((_QWORD *)Argument + 2) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
          return;
        case RegNtSetValueKey:
          *((_QWORD *)Argument + 6) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
          return;
        case RegNtDeleteValueKey:
        case RegNtRenameKey:
        case RegNtPreUnLoadKey:
          *((_QWORD *)Argument + 3) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
          return;
        case RegNtSetInformationKey:
        case RegNtPreQueryKeySecurity:
        case RegNtPreQueryKeyName:
          *((_QWORD *)Argument + 5) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
          return;
        case RegNtEnumerateKey:
          v25 = *(_DWORD **)Argument;
          v6 = 0i64;
          if( !*(_QWORD *)Argument )
            goto LABEL_10;
          if( *v25 != 1803104306 )
            goto LABEL_10;
          v26 = v25 + 18;
          if( (_QWORD *)*v26 == v26 )
            goto LABEL_10;
          v27 = (_ETHREAD *)KeGetCurrentThread();
          --v27->Tcb.KernelApcDisable;
          ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
          v23 = (_QWORD *)*v26;
          if( (_QWORD *)*v26 == v26 )
            goto LABEL_69;
          v28 = Cookie->QuadPart;
          while( v23[4] != v28 )
          {
            if( v23[4] >= v28 )
            {
              v23 = (_QWORD *)*v23;
              if( v23 != v26 )
                continue;
            }
            goto LABEL_69;
          }
          goto LABEL_68;
        case RegNtEnumerateValueKey:
          v20 = *(_DWORD **)Argument;
          v6 = 0i64;
          if( !*(_QWORD *)Argument )
            goto LABEL_10;
          if( *v20 != 1803104306 )
            goto LABEL_10;
          v21 = v20 + 18;
          if( (_QWORD *)*v21 == v21 )
            goto LABEL_10;
          v22 = (_ETHREAD *)KeGetCurrentThread();
          --v22->Tcb.KernelApcDisable;
          ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
          v23 = (_QWORD *)*v21;
          if( (_QWORD *)*v21 == v21 )
            goto LABEL_69;
          v24 = Cookie->QuadPart;
          while( v23[4] != v24 )
          {
            if( v23[4] >= v24 )
            {
              v23 = (_QWORD *)*v23;
              if( v23 != v21 )
                continue;
            }
            goto LABEL_69;
          }
          goto LABEL_68;
        case RegNtQueryKey:
          v5 = *(_DWORD **)Argument;
          v6 = 0i64;
          if( !*(_QWORD *)Argument )
            goto LABEL_10;
          if( *v5 != 1803104306 )
            goto LABEL_10;
          v7 = v5 + 18;
          if( (_QWORD *)*v7 == v7 )
            goto LABEL_10;
          v35 = (_ETHREAD *)KeGetCurrentThread();
          --v35->Tcb.KernelApcDisable;
          ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
          v23 = (_QWORD *)*v7;
          if( (_QWORD *)*v7 == v7 )
            goto LABEL_69;
          v36 = Cookie->QuadPart;
          while( v23[4] != v36 )
          {
            if( v23[4] >= v36 )
            {
              v23 = (_QWORD *)*v23;
              if( v23 != v7 )
                continue;
            }
            goto LABEL_69;
          }
LABEL_68:
          v6 = v23[7];
LABEL_69:
          ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
          KeLeaveCriticalRegionThread(KeGetCurrentThread());
LABEL_10:
          *((_QWORD *)Argument + 6) = v6;
          return;
        case RegNtQueryMultipleValueKey:
          *((_QWORD *)Argument + 7) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
          return;
        case RegNtKeyHandleClose:
          v17 = *(_DWORD **)Argument;
          v18 = 0i64;
          if( !*(_QWORD *)Argument )
            goto LABEL_27;
          if( *v17 != 1803104306 )
            goto LABEL_27;
          v19 = v17 + 18;
          if( (_QWORD *)*v19 == v19 )
            goto LABEL_27;
          v40 = (_ETHREAD *)KeGetCurrentThread();
          --v40->Tcb.KernelApcDisable;
          ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
          v41 = (_QWORD *)*v19;
          if( (_QWORD *)*v19 == v19 )
            goto LABEL_81;
          v42 = Cookie->QuadPart;
          break;
        case RegNtPostDeleteKey:
        case RegNtPostSetValueKey:
        case RegNtPostDeleteValueKey:
        case RegNtPostSetInformationKey:
        case RegNtPostRenameKey:
        case RegNtPostEnumerateKey:
        case RegNtPostEnumerateValueKey:
        case RegNtPostQueryKey:
        case RegNtPostQueryValueKey:
        case RegNtPostQueryMultipleValueKey:
        case RegNtPostFlushKey:
        case RegNtPostLoadKey:
        case RegNtPostUnLoadKey:
        case RegNtPostQueryKeySecurity:
        case RegNtPostSetKeySecurity:
        case RegNtPostRestoreKey:
        case RegNtPostSaveKey:
        case RegNtPostReplaceKey:
        case RegNtPostQueryKeyName:
          goto LABEL_11;
        case RegNtPostKeyHandleClose:
        case RegNtPostCreateKeyEx:
          goto LABEL_15;
        case RegNtPreCreateKeyEx:
          goto LABEL_16;
        case RegNtPreLoadKey:
          *((_QWORD *)Argument + 9) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
          return;
        case RegNtPreSetKeySecurity:
        case RegNtPreRestoreKey:
        case RegNtPreSaveKey:
        case RegNtPreReplaceKey:
          *((_QWORD *)Argument + 4) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
          return;
        default:
          return;
      }
      while( v41[4] != v42 )
      {
        if( v41[4] >= v42 )
        {
          v41 = (_QWORD *)*v41;
          if( v41 != v19 )
            continue;
        }
        goto LABEL_81;
      }
      v18 = v41[7];
LABEL_81:
      ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
      KeLeaveCriticalRegionThread(KeGetCurrentThread());
LABEL_27:
      *((_QWORD *)Argument + 2) = v18;
      return;
  }
}

Referenced by:

CmpCallCallBacksEx