ViXdvDriverLoadImage
UINT8 __stdcall ViXdvDriverLoadImage(_KLDR_DATA_TABLE_ENTRY *DataTableEntry){
char *DllBase;
UINT8 v2;
_IMAGE_EXPORT_DIRECTORY *v3;
_IMAGE_EXPORT_DIRECTORY *v4;
UINT8 v5;
char *v6;
UINT8 v7;
__int64 v8;
UINT8 *v9;
int v10;
int v11;
int v12;
UINT64 *FuncAddress;
INT8 *v14;
int v15;
UINT64 *v16;
int v17;
void(__fastcall *v18)(__int64(__fastcall **)(PCONTEXT));
int v19;
int v20;
int v21;
UINT64 *v22;
UINT64 v24;
DllBase = (char *)DataTableEntry->DllBase;
v2 = 1;
v3 = (_IMAGE_EXPORT_DIRECTORY *)RtlImageDirectoryEntryToData(DllBase, 1u, 0, &v24);
v4 = v3;
if( !v3 || !v3->NumberOfNames )
return 0;
v5 = 0;
v6 = &DllBase[v3->AddressOfNames];
v7 = 0;
v8 = 0i64;
do
{
v9 = (UINT8 *)&DllBase[*(unsigned int *)&v6[4 * v8]];
strcmp((UINT8 *)"DifLoadPlugins", v9);
if( !v10 )
{
if( VfIsRuleClassEnabled(0x23ui64) )
{
ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
if( !ViXdvSetRequestedAPIsforDIF() )
VfDifAPIThunkContextHead = 0i64;
}
goto LABEL_30;
}
strcmp((UINT8 *)"DifUpdatePluginState", v9);
if( !v11 )
{
if( VfIsRuleClassEnabled(0x23ui64) )
PFnViUpdateDIFPlugins = (__int64)ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
goto LABEL_30;
}
strcmp((UINT8 *)"GetXdvDDIWrappers", v9);
if( !v12 )
{
FuncAddress = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
v5 = ViXdvBindXdvDDIWrappers(FuncAddress);
if( v5 == 1 )
goto LABEL_30;
v14 = "Error on Verifier Extention DDI bound process\n";
LABEL_29:
VfUtilDbgPrint(v14);
goto LABEL_30;
}
strcmp((UINT8 *)"GetXdvDriverEntryWrappers", v9);
if( !v15 )
{
v16 = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
v7 = ViXdvBindXdvDriverEntryWrappers(v16);
if( v7 == 1 )
goto LABEL_30;
v14 = "Error on Verifier Extention entry point bound process\n";
goto LABEL_29;
}
strcmp((UINT8 *)"SetXdvKernelUtilities", v9);
if( !v17 )
{
v18 = (void(__fastcall *)(__int64(__fastcall **)(PCONTEXT)))ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
if( ViXdvSetXdvKernelUtilities(v18) )
goto LABEL_30;
v14 = "Error on providing kernel utilities to XDV.\n";
goto LABEL_29;
}
strcmp((UINT8 *)"XdvHibernationNotification", v9);
if( !v19 )
{
ViFnExtensionHiberFunc = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
goto LABEL_30;
}
strcmp((UINT8 *)"XdvNotifyExtensions", v9);
if( !v20 )
{
ViFnXdvNotifyExtensions = (__int64)ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
goto LABEL_30;
}
strcmp((UINT8 *)"XdvQueryDispatchTable", v9);
if( !v21 )
{
v22 = ViXdvGetFuncAddress(DllBase, v4, (unsigned int)v8);
ViFnXdvQueryDispatchTable = (__int64(__fastcall *)(_QWORD, _QWORD))v22;
if( v22 )
{
ViXdvTipUtils = ((__int64(__fastcall *)(__int64))v22)(4i64);
if( ViXdvTipUtils )
goto LABEL_30;
v14 = "Error on getting TiP utilities from XDV.\n";
}
else
{
v14 = (INT8 *)"Error on getting XdvQueryDispatchTable utility from XDV.\n";
}
goto LABEL_29;
}
LABEL_30:
v8 = (unsigned int)(v8 + 1);
}
while( (unsigned int)v8 < v4->NumberOfNames );
if( !v5 || !v7 )
return 0;
return v2;
}Referenced by:
ViLogAndLoadXdv