WdInstrExecuteInstruction
NTSTATUS __stdcall WdInstrExecuteInstruction(_WD_INSTRUCTION *Instruction, INT64 InputValue){
_DWORD *v2;
_DWORD *v4;
signed __int8 InstructionFlags;
NTSTATUS v6;
int v7;
unsigned int v8;
unsigned int v9;
unsigned int Value;
unsigned int v11;
v4 = v2;
InstructionFlags = Instruction->InstructionFlags;
v6 = 0;
switch( InstructionFlags & 0x7F )
{
case 0:
if( v4 )
{
v9 = ((__int64(__fastcall *)(unsigned __int64, INT64))Instruction->Register.Read)(
Instruction->Register.Address,
InputValue);
Value = Instruction->Value;
v11 = Instruction->Mask & (v9 >> Instruction->BitOffset);
LOBYTE(v6) = v11 == Value;
*v4 = v6;
return Value != v11 ? 0xC0000001 : 0;
}
return -1073741811;
case 1:
if( v4 )
{
*v4 = Instruction->Mask & (((unsigned int(__fastcall *)(unsigned __int64, INT64))Instruction->Register.Read)(
Instruction->Register.Address,
InputValue) >> Instruction->BitOffset);
return v6;
}
return -1073741811;
case 2:
v7 = Instruction->Mask & Instruction->Value;
break;
case 3:
v7 = InputValue & Instruction->Mask;
break;
default:
return v6;
}
v8 = v7 << Instruction->BitOffset;
if( InstructionFlags < 0 )
v8 |= ((__int64(__fastcall *)(unsigned __int64))Instruction->Register.Read)(Instruction->Register.Address) & ~(Instruction->Mask << Instruction->BitOffset);
Instruction->Register.Write(Instruction->Register.Address, v8);
return v6;
}Referenced by:
HalpWdatExecuteActionBeforeInitialize
WdInstrExecuteAction