CmpCallbackFillObjectContext
VOID __stdcall CmpCallbackFillObjectContext(REG_NOTIFY_CLASS Type, VOID *Argument, LARGE_INTEGER *Cookie){
_DWORD *v5;
__int64 v6;
_QWORD *v7;
_DWORD *v8;
__int64 v9;
_QWORD *v10;
_DWORD *v11;
__int64 v12;
_QWORD *v13;
_DWORD *v14;
__int64 v15;
_QWORD *v16;
_DWORD *v17;
__int64 v18;
_QWORD *v19;
_DWORD *v20;
_QWORD *v21;
_ETHREAD *v22;
_QWORD *v23;
LONGLONG v24;
_DWORD *v25;
_QWORD *v26;
_ETHREAD *v27;
LONGLONG v28;
_ETHREAD *v29;
_QWORD *v30;
LONGLONG v31;
_ETHREAD *CurrentThread;
_QWORD *v33;
LONGLONG QuadPart;
_ETHREAD *v35;
LONGLONG v36;
_ETHREAD *v37;
_QWORD *v38;
LONGLONG v39;
_ETHREAD *v40;
_QWORD *v41;
LONGLONG v42;
switch( Type )
{
case RegNtPostOpenKeyEx:
LABEL_15:
v9 = 0i64;
LABEL_14:
*((_QWORD *)Argument + 5) = v9;
return;
case RegNtPreOpenKeyEx:
LABEL_16:
v11 = (_DWORD *)*((_QWORD *)Argument + 1);
v12 = 0i64;
if( v11 )
{
if( *v11 == 1803104306 )
{
v13 = v11 + 18;
if( (_QWORD *)*v13 != v13 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
v33 = (_QWORD *)*v13;
if( (_QWORD *)*v13 != v13 )
{
QuadPart = Cookie->QuadPart;
while( v33[4] != QuadPart )
{
if( v33[4] >= QuadPart )
{
v33 = (_QWORD *)*v33;
if( v33 != v13 )
continue;
}
goto LABEL_61;
}
v12 = v33[7];
}
LABEL_61:
ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
}
}
}
*((_QWORD *)Argument + 11) = v12;
break;
case RegNtPostQueryValueKey:
LABEL_11:
v8 = *(_DWORD **)Argument;
v9 = 0i64;
if( *(_QWORD *)Argument )
{
if( *v8 == 1803104306 )
{
v10 = v8 + 18;
if( (_QWORD *)*v10 != v10 )
{
v29 = (_ETHREAD *)KeGetCurrentThread();
--v29->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
v30 = (_QWORD *)*v10;
if( (_QWORD *)*v10 != v10 )
{
v31 = Cookie->QuadPart;
while( v30[4] != v31 )
{
if( v30[4] >= v31 )
{
v30 = (_QWORD *)*v30;
if( v30 != v10 )
continue;
}
goto LABEL_56;
}
v9 = v30[7];
}
LABEL_56:
ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
}
}
}
goto LABEL_14;
case RegNtQueryValueKey:
v14 = *(_DWORD **)Argument;
v15 = 0i64;
if( *(_QWORD *)Argument )
{
if( *v14 == 1803104306 )
{
v16 = v14 + 18;
if( (_QWORD *)*v16 != v16 )
{
v37 = (_ETHREAD *)KeGetCurrentThread();
--v37->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
v38 = (_QWORD *)*v16;
if( (_QWORD *)*v16 != v16 )
{
v39 = Cookie->QuadPart;
while( v38[4] != v39 )
{
if( v38[4] >= v39 )
{
v38 = (_QWORD *)*v38;
if( v38 != v16 )
continue;
}
goto LABEL_76;
}
v15 = v38[7];
}
LABEL_76:
ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
}
}
}
*((_QWORD *)Argument + 7) = v15;
break;
case RegNtPostQueryKey:
goto LABEL_11;
default:
switch( Type )
{
case RegNtDeleteKey:
case RegNtPreFlushKey:
*((_QWORD *)Argument + 2) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
return;
case RegNtSetValueKey:
*((_QWORD *)Argument + 6) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
return;
case RegNtDeleteValueKey:
case RegNtRenameKey:
case RegNtPreUnLoadKey:
*((_QWORD *)Argument + 3) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
return;
case RegNtSetInformationKey:
case RegNtPreQueryKeySecurity:
case RegNtPreQueryKeyName:
*((_QWORD *)Argument + 5) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
return;
case RegNtEnumerateKey:
v25 = *(_DWORD **)Argument;
v6 = 0i64;
if( !*(_QWORD *)Argument )
goto LABEL_10;
if( *v25 != 1803104306 )
goto LABEL_10;
v26 = v25 + 18;
if( (_QWORD *)*v26 == v26 )
goto LABEL_10;
v27 = (_ETHREAD *)KeGetCurrentThread();
--v27->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
v23 = (_QWORD *)*v26;
if( (_QWORD *)*v26 == v26 )
goto LABEL_69;
v28 = Cookie->QuadPart;
while( v23[4] != v28 )
{
if( v23[4] >= v28 )
{
v23 = (_QWORD *)*v23;
if( v23 != v26 )
continue;
}
goto LABEL_69;
}
goto LABEL_68;
case RegNtEnumerateValueKey:
v20 = *(_DWORD **)Argument;
v6 = 0i64;
if( !*(_QWORD *)Argument )
goto LABEL_10;
if( *v20 != 1803104306 )
goto LABEL_10;
v21 = v20 + 18;
if( (_QWORD *)*v21 == v21 )
goto LABEL_10;
v22 = (_ETHREAD *)KeGetCurrentThread();
--v22->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
v23 = (_QWORD *)*v21;
if( (_QWORD *)*v21 == v21 )
goto LABEL_69;
v24 = Cookie->QuadPart;
while( v23[4] != v24 )
{
if( v23[4] >= v24 )
{
v23 = (_QWORD *)*v23;
if( v23 != v21 )
continue;
}
goto LABEL_69;
}
goto LABEL_68;
case RegNtQueryKey:
v5 = *(_DWORD **)Argument;
v6 = 0i64;
if( !*(_QWORD *)Argument )
goto LABEL_10;
if( *v5 != 1803104306 )
goto LABEL_10;
v7 = v5 + 18;
if( (_QWORD *)*v7 == v7 )
goto LABEL_10;
v35 = (_ETHREAD *)KeGetCurrentThread();
--v35->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
v23 = (_QWORD *)*v7;
if( (_QWORD *)*v7 == v7 )
goto LABEL_69;
v36 = Cookie->QuadPart;
while( v23[4] != v36 )
{
if( v23[4] >= v36 )
{
v23 = (_QWORD *)*v23;
if( v23 != v7 )
continue;
}
goto LABEL_69;
}
LABEL_68:
v6 = v23[7];
LABEL_69:
ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
LABEL_10:
*((_QWORD *)Argument + 6) = v6;
return;
case RegNtQueryMultipleValueKey:
*((_QWORD *)Argument + 7) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
return;
case RegNtKeyHandleClose:
v17 = *(_DWORD **)Argument;
v18 = 0i64;
if( !*(_QWORD *)Argument )
goto LABEL_27;
if( *v17 != 1803104306 )
goto LABEL_27;
v19 = v17 + 18;
if( (_QWORD *)*v19 == v19 )
goto LABEL_27;
v40 = (_ETHREAD *)KeGetCurrentThread();
--v40->Tcb.KernelApcDisable;
ExAcquirePushLockSharedEx((_EX_PUSH_LOCK *)&CmpDummyThreadEvent + 254, 0i64);
v41 = (_QWORD *)*v19;
if( (_QWORD *)*v19 == v19 )
goto LABEL_81;
v42 = Cookie->QuadPart;
break;
case RegNtPostDeleteKey:
case RegNtPostSetValueKey:
case RegNtPostDeleteValueKey:
case RegNtPostSetInformationKey:
case RegNtPostRenameKey:
case RegNtPostEnumerateKey:
case RegNtPostEnumerateValueKey:
case RegNtPostQueryKey:
case RegNtPostQueryValueKey:
case RegNtPostQueryMultipleValueKey:
case RegNtPostFlushKey:
case RegNtPostLoadKey:
case RegNtPostUnLoadKey:
case RegNtPostQueryKeySecurity:
case RegNtPostSetKeySecurity:
case RegNtPostRestoreKey:
case RegNtPostSaveKey:
case RegNtPostReplaceKey:
case RegNtPostQueryKeyName:
goto LABEL_11;
case RegNtPostKeyHandleClose:
case RegNtPostCreateKeyEx:
goto LABEL_15;
case RegNtPreCreateKeyEx:
goto LABEL_16;
case RegNtPreLoadKey:
*((_QWORD *)Argument + 9) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
return;
case RegNtPreSetKeySecurity:
case RegNtPreRestoreKey:
case RegNtPreSaveKey:
case RegNtPreReplaceKey:
*((_QWORD *)Argument + 4) = CmpGetCallbackObjectContext(*(VOID **)Argument, Cookie);
return;
default:
return;
}
while( v41[4] != v42 )
{
if( v41[4] >= v42 )
{
v41 = (_QWORD *)*v41;
if( v41 != v19 )
continue;
}
goto LABEL_81;
}
v18 = v41[7];
LABEL_81:
ExReleasePushLockEx((ULONG_PTR)&CmpDummyThreadEvent + 2032, 0);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
LABEL_27:
*((_QWORD *)Argument + 2) = v18;
return;
}
}Referenced by:
CmpCallCallBacksEx