PspCreateProcess
NTSTATUS __stdcall PspCreateProcess(
VOID **ProcessHandle,
UINT64 DesiredAccess,
_OBJECT_ATTRIBUTES *ObjectAttributes,
VOID *ParentProcess,
UINT64 CreateFlags,
VOID *SectionHandle,
VOID *DebugPort,
VOID *TokenHandle){
_KPROCESSOR_MODE v10;
_ADAPTER_OBJECT *v11;
_EPROCESS *v12;
int ProcessProtectionRequirementsFromImage;
UINT64 v14;
PS_PROTECTION v15;
NTSTATUS Process;
int v17;
int v18;
NTSTATUS result;
_UNICODE_STRING *ObjectName;
unsigned int Attributes;
int v22;
_UNICODE_STRING *v23;
PVOID *Object;
POBJECT_HANDLE_INFORMATION HandleInformation;
UINT64 v26;
PSP_CREATE_PROCESS_CONTEXT *CreateContext;
PSP_ALLOCATE_PROCESS_STATE *AllocateProcessState;
_PS_PROTECTION Protection;
UINT8 ExeSigningLevel;
UINT8 DllSigningLevel;
UINT8 SignatureLevel;
char v33;
int v34;
VOID *NewObject;
VOID *NewToken;
UINT64 DesiredAccessa;
_EPROCESS *ParentProcessa;
PVOID v39;
VOID *v40;
__int64 v41;
VOID **v42;
PVOID v43;
_HANDLE Handle[2];
_PSP_OBJECT_CREATION_STATE ObjectAccessState[100];
VOID *v46;
LODWORD(DesiredAccessa) = DesiredAccess;
v42 = ProcessHandle;
*(_QWORD *)Handle = TokenHandle;
v40 = v46;
v41 = 0i64;
v33 = 0;
ParentProcessa = 0i64;
NewObject = 0i64;
ExeSigningLevel = 0;
DllSigningLevel = 0;
NewToken = 0i64;
if( ((unsigned int)SectionHandle & 0xFFF94040) != 0
|| (KeGetCurrentThread()->ApcState.Process->Protection.Level & 7) != 0 && (_BYTE)CreateFlags )
{
return -1073741811;
}
if( ((unsigned __int16)SectionHandle & 0x4000) != 0 && ((unsigned __int16)SectionHandle & 0x2000) == 0 )
return -1073741811;
v34 = (unsigned __int16)SectionHandle & 0x800;
if( ((unsigned __int16)SectionHandle & 0x2000) != 0 && ((unsigned __int16)SectionHandle & 0x800) == 0 )
return -1073741811;
if( ((unsigned __int16)SectionHandle & 0x800) != 0 )
{
if( (_BYTE)CreateFlags )
return -1073741811;
if( ObjectAttributes )
{
if( ObjectAttributes->RootDirectory )
return -1073741811;
ObjectName = ObjectAttributes->ObjectName;
if( !ObjectName
|| !ObjectName->Buffer
|| !ObjectName->Length
|| ObjectAttributes->Attributes != 512
|| ObjectAttributes->SecurityDescriptor
|| ObjectAttributes->SecurityQualityOfService )
{
return -1073741811;
}
}
if( DebugPort || TokenHandle || !ParentProcess )
return -1073741811;
}
if( ((unsigned int)SectionHandle & 0x20000) != 0
&& ((_BYTE)CreateFlags || ((unsigned __int16)SectionHandle & 0x800) == 0) )
{
return -1073741811;
}
memset(ObjectAccessState, 0i64, sizeof(ObjectAccessState));
LOBYTE(ObjectAccessState[97]) = CreateFlags;
if( ObjectAttributes )
{
if( (_BYTE)CreateFlags )
{
if( ((unsigned __int8)ObjectAttributes & 3) != 0 )
ExRaiseDatatypeMisalignment();
Attributes = ObjectAttributes->Attributes;
ObjectAccessState[96] = Attributes;
}
else
{
Attributes = ObjectAttributes->Attributes;
}
if( (_BYTE)CreateFlags )
v22 = Attributes & 0x1DF2;
else
v22 = Attributes & 0x11FF2;
ObjectAccessState[96] = v22;
}
if( DebugPort )
{
v39 = 0i64;
result = ObReferenceObjectByHandle(DebugPort, 8ui64, MmSectionObjectType, CreateFlags, &v39, 0i64);
v11 = (_ADAPTER_OBJECT *)v39;
v43 = v39;
if( result < 0 )
return result;
}
else
{
v11 = 0i64;
v43 = 0i64;
}
if( !ParentProcess
|| (LODWORD(Object) = 1917023056,
ProcessProtectionRequirementsFromImage = ObReferenceObjectByHandleWithTag(
ParentProcess,
0x80ui64,
(_OBJECT_TYPE *)PsProcessType,
CreateFlags,
(UINT64)Object,
(VOID **)&ParentProcessa,
0i64),
ProcessProtectionRequirementsFromImage >= 0) )
{
LOBYTE(v10) = CreateFlags;
v12 = ParentProcessa;
ProcessProtectionRequirementsFromImage = PspReferenceTokenForNewProcess(&ParentProcessa->Pcb, v46, v10, &NewToken);
if( ProcessProtectionRequirementsFromImage < 0 )
goto LABEL_28;
if( v12 )
{
if( v11 )
{
Protection.Level = 0;
ProcessProtectionRequirementsFromImage = SeQuerySigningPolicy(
NewToken,
0i64,
0i64,
0,
&ExeSigningLevel,
&DllSigningLevel,
&Protection);
if( ProcessProtectionRequirementsFromImage < 0 )
goto LABEL_27;
SignatureLevel = ExeSigningLevel;
if( ExeSigningLevel > 1u || (v15.Level = Protection.Level) != 0 )
{
LABEL_72:
ProcessProtectionRequirementsFromImage = -1073741637;
goto LABEL_27;
}
LABEL_15:
if( !v11 )
goto LABEL_16;
ProcessProtectionRequirementsFromImage = PspGetProcessProtectionRequirementsFromImage((INT64)v11);
if( ProcessProtectionRequirementsFromImage >= 0 )
{
if( v15.Level == v33 )
{
LABEL_16:
if( v34 )
{
if( ObjectAttributes )
v23 = ObjectAttributes->ObjectName;
else
LOBYTE(v23) = 0;
LOBYTE(v14) = v15;
ProcessProtectionRequirementsFromImage = PsCreateMinimalProcess(
v12,
(PS_PROTECTION)v23,
0i64,
v14,
(VOID **)((unsigned __int64)NewToken & -(__int64)(v40 != 0i64)));
}
else
{
LODWORD(AllocateProcessState) = v40 != 0i64;
LODWORD(CreateContext) = 0;
LODWORD(v26) = (_DWORD)SectionHandle;
Process = PspAllocateProcess(
v12,
CreateFlags,
ObjectAttributes,
v15,
SignatureLevel,
DllSigningLevel,
v11,
NewToken,
v26,
CreateContext,
0i64,
AllocateProcessState,
0i64);
ProcessProtectionRequirementsFromImage = Process;
if( Process >= 0 )
{
v17 = Process;
v34 = Process;
v18 = 1;
if( (_DWORD)v41 )
v18 = 3;
LODWORD(HandleInformation) = v18;
ProcessProtectionRequirementsFromImage = PspInsertProcess(
(_EPROCESS *)NewObject,
v12,
(unsigned int)DesiredAccessa,
(unsigned int)SectionHandle,
*(VOID **)Handle,
(UINT64)HandleInformation,
0i64,
ObjectAccessState);
if( ProcessProtectionRequirementsFromImage >= 0 )
{
ProcessProtectionRequirementsFromImage = PspCreateObjectHandle(
NewObject,
ObjectAccessState,
(_OBJECT_TYPE *)PsProcessType);
if( ProcessProtectionRequirementsFromImage >= 0 )
{
*v42 = *(VOID **)&ObjectAccessState[98];
ProcessProtectionRequirementsFromImage = v17;
}
PspDeleteObjectAccessState((_ACCESS_STATE *)ObjectAccessState);
}
if( ProcessProtectionRequirementsFromImage < 0 )
PspRundownSingleProcess((_EPROCESS *)NewObject, 0);
ObfDereferenceObjectWithTag(NewObject, 0x72437350ui64);
}
}
goto LABEL_27;
}
goto LABEL_72;
}
LABEL_27:
HalPutDmaAdapter((PADAPTER_OBJECT)NewToken);
LABEL_28:
if( v12 )
ObfDereferenceObjectWithTag(v12, 0x72437350ui64);
goto LABEL_30;
}
v15.Level = v12->Protection.Level;
DllSigningLevel = v12->SectionSignatureLevel;
SignatureLevel = v12->SignatureLevel;
ExeSigningLevel = SignatureLevel;
}
else
{
v15.Level = 114;
SignatureLevel = 30;
ExeSigningLevel = 30;
DllSigningLevel = 28;
}
Protection.Level = v15.Level;
goto LABEL_15;
}
LABEL_30:
if( v11 )
HalPutDmaAdapter(v11);
return ProcessProtectionRequirementsFromImage;
}Referenced by:
NtCreateProcessEx
PspInitPhase0