ViXdvDriverLoadImage

UINT8 __stdcall ViXdvDriverLoadImage(_KLDR_DATA_TABLE_ENTRY *DataTableEntry){
  char *DllBase; 
  UINT8 v2; 
  _IMAGE_EXPORT_DIRECTORY *v3; 
  _IMAGE_EXPORT_DIRECTORY *v4; 
  UINT8 v5; 
  char *v6; 
  UINT8 v7; 
  __int64 v8; 
  UINT8 *v9; 
  int v10; 
  int v11; 
  int v12; 
  UINT64 *FuncAddress; 
  INT8 *v14; 
  int v15; 
  UINT64 *v16; 
  int v17; 
  void(__fastcall *v18)(__int64(__fastcall **)(PCONTEXT)); 
  int v19; 
  int v20; 
  int v21; 
  UINT64 *v22; 
  UINT64 v24; 

  DllBase = (char *)DataTableEntry->DllBase;
  v2 = 1;
  v3 = (_IMAGE_EXPORT_DIRECTORY *)RtlImageDirectoryEntryToData(DllBase, 1u, 0, &v24);
  v4 = v3;
  if( !v3 || !v3->NumberOfNames )
    return 0;
  v5 = 0;
  v6 = &DllBase[v3->AddressOfNames];
  v7 = 0;
  v8 = 0i64;
  do
  {
    v9 = (UINT8 *)&DllBase[*(unsigned int *)&v6[4 * v8]];
    strcmp((UINT8 *)"DifLoadPlugins", v9);
    if( !v10 )
    {
      if( VfIsRuleClassEnabled(0x23ui64) )
      {
        ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
        if( !ViXdvSetRequestedAPIsforDIF() )
          VfDifAPIThunkContextHead = 0i64;
      }
      goto LABEL_30;
    }
    strcmp((UINT8 *)"DifUpdatePluginState", v9);
    if( !v11 )
    {
      if( VfIsRuleClassEnabled(0x23ui64) )
        PFnViUpdateDIFPlugins = (__int64)ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
      goto LABEL_30;
    }
    strcmp((UINT8 *)"GetXdvDDIWrappers", v9);
    if( !v12 )
    {
      FuncAddress = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
      v5 = ViXdvBindXdvDDIWrappers(FuncAddress);
      if( v5 == 1 )
        goto LABEL_30;
      v14 = "Error on Verifier Extention DDI bound process\n";
LABEL_29:
      VfUtilDbgPrint(v14);
      goto LABEL_30;
    }
    strcmp((UINT8 *)"GetXdvDriverEntryWrappers", v9);
    if( !v15 )
    {
      v16 = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
      v7 = ViXdvBindXdvDriverEntryWrappers(v16);
      if( v7 == 1 )
        goto LABEL_30;
      v14 = "Error on Verifier Extention entry point bound process\n";
      goto LABEL_29;
    }
    strcmp((UINT8 *)"SetXdvKernelUtilities", v9);
    if( !v17 )
    {
      v18 = (void(__fastcall *)(__int64(__fastcall **)(PCONTEXT)))ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
      if( ViXdvSetXdvKernelUtilities(v18) )
        goto LABEL_30;
      v14 = "Error on providing kernel utilities to  XDV.\n";
      goto LABEL_29;
    }
    strcmp((UINT8 *)"XdvHibernationNotification", v9);
    if( !v19 )
    {
      ViFnExtensionHiberFunc = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
      goto LABEL_30;
    }
    strcmp((UINT8 *)"XdvNotifyExtensions", v9);
    if( !v20 )
    {
      ViFnXdvNotifyExtensions = (__int64)ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
      goto LABEL_30;
    }
    strcmp((UINT8 *)"XdvQueryDispatchTable", v9);
    if( !v21 )
    {
      v22 = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
      ViFnXdvQueryDispatchTable = (__int64(__fastcall *)(_QWORD, _QWORD))v22;
      if( v22 )
      {
        ViXdvTipUtils = ((__int64(__fastcall *)(__int64))v22)(4i64);
        if( ViXdvTipUtils )
          goto LABEL_30;
        v14 = "Error on getting TiP utilities from XDV.\n";
      }
      else
      {
        v14 = (INT8 *)"Error on getting XdvQueryDispatchTable utility from XDV.\n";
      }
      goto LABEL_29;
    }
LABEL_30:
    v8 = (unsigned int)(v8 + 1);
  }
  while( (unsigned int)v8 < v4->NumberOfNames );
  if( !v5 || !v7 )
    return 0;
  return v2;
}

Referenced by:

ViLogAndLoadXdv