ExpKeyedEventInitialization
NTSTATUS __stdcall ExpKeyedEventInitialization(){
NTSTATUS result;
unsigned int v1;
VOID **PoolWithTag;
UINT64 v3;
_ACL *v4;
int Acl;
_ACL *v6;
unsigned int v7;
VOID **v8;
UINT64 v9;
_ACL *v10;
UINT64 v11;
int v12;
PVOID *Object;
PVOID *Objecta;
void *AccessMask;
INT64 AccessMaska;
_UNICODE_STRING DestinationString;
_OBJECT_ATTRIBUTES ObjectAttributes;
__int128 SecurityDescriptor[2];
__int64 v20;
_OBJECT_TYPE_INITIALIZER ObjectTypeInitializer;
VOID *KeyedEventHandle;
PVOID v23;
DestinationString = 0i64;
memset(&ObjectTypeInitializer, 0i64, sizeof(ObjectTypeInitializer));
*(&ObjectAttributes.Length + 1) = 0;
*(&ObjectAttributes.Attributes + 1) = 0;
KeyedEventHandle = 0i64;
memset(SecurityDescriptor, 0, sizeof(SecurityDescriptor));
v20 = 0i64;
RtlInitUnicodeString(&DestinationString, L"KeyedEvent");
ObjectTypeInitializer.InvalidAttributes = 0;
ObjectTypeInitializer.DefaultPagedPoolCharge = 0;
ObjectTypeInitializer.DefaultNonPagedPoolCharge = 0;
ObjectTypeInitializer._bf_0 |= 4u;
ObjectTypeInitializer.PoolType = PagedPool;
ObjectTypeInitializer.ValidAccessMask = 983043;
ObjectTypeInitializer.GenericMapping.GenericAll = 983043;
ObjectTypeInitializer.Length = 120;
ObjectTypeInitializer.GenericMapping.GenericRead = 131073;
ObjectTypeInitializer.GenericMapping.GenericWrite = 131074;
ObjectTypeInitializer.GenericMapping.GenericExecute = 0x20000;
result = ObCreateObjectType(&DestinationString, &ObjectTypeInitializer, 0i64, &ExpKeyedEventObjectType);
if( result < 0 )
return result;
result = RtlCreateSecurityDescriptor(SecurityDescriptor, 1ui64);
if( result < 0 )
return result;
v1 = 4
* (*((unsigned __int8 *)SeLocalSystemSid + 1)
+ *((unsigned __int8 *)SeAliasAdminsSid + 1)
+ *((unsigned __int8 *)SeWorldSid + 1))
+ 68;
PoolWithTag = ExAllocatePoolWithTag(1ui64, v1, 1818452292i64);
v4 = (_ACL *)PoolWithTag;
if( !PoolWithTag )
return -1073741670;
Acl = RtlCreateAcl((PACL)PoolWithTag, (_ACL)v1, 2ui64, v3);
v6 = v4;
if( Acl < 0
|| (Acl = RtlAddAccessAllowedAce(v4, 2ui64, 131075, SeWorldSid), v6 = v4, Acl < 0)
|| (Acl = RtlAddAccessAllowedAce(v4, 2ui64, 983043, SeAliasAdminsSid), v6 = v4, Acl < 0) )
{
LABEL_20:
ExFreePoolWithTag(v6, 0);
return Acl;
}
Acl = RtlAddAccessAllowedAce(v4, 2ui64, 983043, SeLocalSystemSid);
if( Acl < 0 || (Acl = RtlSetDaclSecurityDescriptor(SecurityDescriptor, 1u, v4, 0), Acl < 0) )
{
LABEL_19:
v6 = v4;
goto LABEL_20;
}
v7 = 4 * *((unsigned __int8 *)SeLowMandatorySid + 1) + 28;
v8 = ExAllocatePoolWithTag(1ui64, v7, 1818452292i64);
v10 = (_ACL *)v8;
if( !v8 )
{
Acl = -1073741670;
goto LABEL_19;
}
v12 = RtlCreateAcl((PACL)v8, (_ACL)v7, 2ui64, v9);
if( v12 < 0
|| (LODWORD(AccessMask) = 1,
v12 = RtlAddMandatoryAce(v10, v11, 0i64, (UINT64)SeLowMandatorySid, Object, AccessMask),
v12 < 0)
|| (v12 = RtlSetSaclSecurityDescriptor(SecurityDescriptor, 1u, v10, 0), v12 < 0) )
{
ExFreePoolWithTag(v4, 0);
ExFreePoolWithTag(v10, 0);
}
else
{
RtlInitUnicodeString(&DestinationString, L"\\KernelObjects\\CritSecOutOfMemoryEvent");
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.SecurityQualityOfService = 0i64;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.Length = 48;
ObjectAttributes.SecurityDescriptor = SecurityDescriptor;
ObjectAttributes.Attributes = 16;
v12 = ZwCreateKeyedEvent(
&KeyedEventHandle,
983043,
&ObjectAttributes,
0i64,
Objecta,
AccessMaska,
*(INT64 *)&DestinationString.Length,
(INT64)DestinationString.Buffer);
ExFreePoolWithTag(v4, 0);
ExFreePoolWithTag(v10, 0);
if( v12 >= 0 )
{
v23 = 0i64;
v12 = ObReferenceObjectByHandle(KeyedEventHandle, 0xF0003ui64, ExpKeyedEventObjectType, 0, &v23, 0i64);
*(&WheapDeferredInternalLogsEventLock + 72) = v23;
ZwClose((_HANDLE)KeyedEventHandle);
}
}
return v12;
}Referenced by:
ExpInitSystemPhase1