WdInstrExecuteInstruction

NTSTATUS __stdcall WdInstrExecuteInstruction(_WD_INSTRUCTION *Instruction, INT64 InputValue){
  _DWORD *v2; 
  _DWORD *v4; 
  signed __int8 InstructionFlags; 
  NTSTATUS v6; 
  int v7; 
  unsigned int v8; 
  unsigned int v9; 
  unsigned int Value; 
  unsigned int v11; 

  v4 = v2;
  InstructionFlags = Instruction->InstructionFlags;
  v6 = 0;
  switch( InstructionFlags & 0x7F )
  {
    case 0:
      if( v4 )
      {
        v9 = ((__int64(__fastcall *)(unsigned __int64, INT64))Instruction->Register.Read)(
               Instruction->Register.Address,
               InputValue);
        Value = Instruction->Value;
        v11 = Instruction->Mask & (v9 >> Instruction->BitOffset);
        LOBYTE(v6) = v11 == Value;
        *v4 = v6;
        return Value != v11 ? 0xC0000001 : 0;
      }
      return -1073741811;
    case 1:
      if( v4 )
      {
        *v4 = Instruction->Mask & (((unsigned int(__fastcall *)(unsigned __int64, INT64))Instruction->Register.Read)(
                                     Instruction->Register.Address,
                                     InputValue) >> Instruction->BitOffset);
        return v6;
      }
      return -1073741811;
    case 2:
      v7 = Instruction->Mask & Instruction->Value;
      break;
    case 3:
      v7 = InputValue & Instruction->Mask;
      break;
    default:
      return v6;
  }
  v8 = v7 << Instruction->BitOffset;
  if( InstructionFlags < 0 )
    v8 |= ((__int64(__fastcall *)(unsigned __int64))Instruction->Register.Read)(Instruction->Register.Address) & ~(Instruction->Mask << Instruction->BitOffset);
  Instruction->Register.Write(Instruction->Register.Address, v8);
  return v6;
}

Referenced by:

HalpWdatExecuteActionBeforeInitialize
WdInstrExecuteAction