VRegSetup

INT64 __stdcall VRegSetup(DRIVER_OBJECT *DriverObject, UNICODE_STRING *RegistryPath){
  WCHAR v3; 
  NTSTATUS v4; 
  NTSTATUS v5; 
  WCHAR v6; 
  int v7; 
  int v8; 
  INT64 v9; 
  UINT64 DeviceCharacteristics; 
  struct _UNICODE_STRING DestinationString; 
  UNICODE_STRING SourceString; 
  __int16 result; 
  char result_2; 
  int v15; 
  int v16; 
  int v17; 
  int v18; 
  int v19; 
  int v20; 
  int v21; 
  int v22; 
  VOID(__stdcall *v23)(PVOID); 
  DestinationString = 0i64;
  SourceString = 0i64;
  TraceLoggingRegisterEx_EtwRegister_EtwSetInformation(&CallbackContext);
  RtlpQueryRegistryValues((_KTRAP_FRAME *)0x80000002i64, (_KEXCEPTION_FRAME *)&stru_1407CDE30);
  RtlInitUnicodeString(&DestinationString, (PCWSTR)&stru_1407CDE30.Xmm8, v3);
  LODWORD(DeviceCharacteristics) = 256;
  v4 = IoCreateDevice(DriverObject, 0i64, &DestinationString, 0x22ui64, DeviceCharacteristics, 0, &VrpDeviceObject);
  if( v4 < 0 )
    KeBugCheckEx(0x51u, 0x1Eui64, v4, 1ui64, 0i64);
  VrpActiveSilosLock = 0i64;
  VrpDriverObject = (__int64)DriverObject;
  v5 = ObSetSecurityObjectByPointer(VrpDeviceObject, 0xCui64, VrpHardCodedSdBlob);
  if( v5 < 0 )
    KeBugCheckEx(0x51u, 0x1Eui64, v5, 2ui64, 0i64);
  *((_DWORD *)VrpDeviceObject + 12) &= ~0x80u;
  DriverObject->DriverUnload = (void(__fastcall *)(_DRIVER_OBJECT *))VrpRegistryUnload;
  DriverObject->MajorFunction[0] = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *))VrpRegistryDispatch;
  DriverObject->MajorFunction[2] = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *))VrpRegistryDispatch;
  DriverObject->MajorFunction[14] = (int(__fastcall *)(_DEVICE_OBJECT *, _IRP *))VrpIoctlDeviceDispatch;
  RtlInitUnicodeString(&SourceString, (PCWSTR)&stru_1407CDE30.Xmm11, v6);
  memset((INT64)&result, 0i64);
  result_2 |= 4u;
  result = 120;
  v16 = 0x20000;
  v17 = 0x20000;
  v18 = 0x20000;
  v15 = 256;
  v19 = 983040;
  v20 = 983040;
  v23 = VrpJobContextDelete;
  v21 = 1;
  v22 = 96;
  v7 = ObCreateObjectTypeEx(&SourceString, (__int64)&result, 0i64, 0i64, (__int64)&VrpJobContextType);
  if( v7 < 0 )
    KeBugCheckEx(0x51u, 0x1Eui64, v7, 4ui64, 0i64);
  v8 = VrpInitializeLoadedDifferencingHives();
  if( v8 < 0 )
    KeBugCheckEx(0x51u, 0x1Eui64, v8, 5ui64, 0i64);
  v9 = PspStorageAllocSlot((UINT64)&VrpSiloContextSlot);
  if( (int)v9 < 0 )
    KeBugCheckEx(0x51u, 0x1Eui64, (int)v9, 6ui64, 0i64);
  return v9;
}

Referenced by:

No references.