CmpInitHiveFromFile
INT64 __fastcall CmpInitHiveFromFile(
_UNICODE_STRING *FileName,
UINT64 HiveFlags,
_CMHIVE **CmHive,
UINT8 *Allocate,
UINT64 CheckFlags,
_GUID *HiveRmUuid,
_GUID *HiveTmUuid,
UINT8 *NeedRmLogStart,
_HIVE_LOAD_FAILURE *HiveLoadFailure){
_CMHIVE **v9;
int v10;
INT64 a6;
HANDLE v13;
unsigned int v14;
HANDLE v15;
PVOID v16;
unsigned int v17;
NTSTATUS v18;
NTSTATUS v19;
HANDLE v20;
int Hive;
_ETHREAD *CurrentThread;
INT64 a12;
char v25;
VOID *PoolWithTag;
ULONG_PTR v27;
EVENT_DESCRIPTOR *v28;
int v29;
INT64 v30;
INT64 FileInformationClass;
INT64 FileInformationClassa;
INT64 a8;
char v34;
char v35;
bool v36;
int a5;
unsigned int a5_4;
ULONG_PTR BugCheckParameter2;
HANDLE Handle;
INT64 result;
HANDLE v42;
INT64 v43;
HANDLE FileHandle;
PVOID SecurityDescriptor;
INT64 a4;
_CMHIVE **v47;
int v48;
INT64 v49;
INT64 a7;
UINT8 *v51;
INT64 a11;
INT64 v53[2];
__int128 v54;
struct _IO_STATUS_BLOCK IoStatusBlock;
__int128 FileInformation;
__int128 v57;
__int64 v58;
KAPC_STATE ApcState;
struct _EVENT_DATA_DESCRIPTOR v60;
int *v61;
__int64 v62;
wchar_t *Buffer;
int v64[2];
struct _EVENT_DATA_DESCRIPTOR v65;
int *p_a5;
int v67;
int v68;
INT64 v69;
a11 = (INT64)HiveLoadFailure;
v9 = CmHive;
result = v69;
v47 = CmHive;
v10 = HiveFlags;
a6 = (INT64)HiveRmUuid;
v51 = Allocate;
HIDWORD(v49) = HiveFlags;
v43 = (INT64)HiveRmUuid;
*(_OWORD *)v53 = 0i64;
v54 = 0i64;
LODWORD(v49) = 0;
BugCheckParameter2 = 0i64;
a4 = 0i64;
FileInformation = 0i64;
v58 = 0i64;
v57 = 0i64;
IoStatusBlock = 0i64;
memset(&ApcState, 0, sizeof(ApcState));
if( (unsigned int)dword_140C02130 > 4 )
{
if( tlgKeywordOn((__int64)&dword_140C02130, 8i64) )
{
v62 = 2i64;
v61 = v64;
Buffer = FileName->Buffer;
v64[0] = FileName->Length;
v64[1] = 0;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&dword_140C02130,
(unsigned __int8 *)byte_140021A6D,
0i64,
0i64,
4u,
&v60);
Allocate = v51;
v9 = v47;
}
a6 = v43;
}
v35 = 0;
v13 = 0i64;
v14 = ((unsigned int)CheckFlags >> 19) & 0x40;
v36 = 0;
FileHandle = 0i64;
v48 = v10 & 0x8000;
v15 = 0i64;
Handle = 0i64;
v16 = 0i64;
v42 = 0i64;
v34 = 1;
SecurityDescriptor = 0i64;
if( (v10 & 0x8000) != 0 )
{
v34 = 0;
v17 = v14 | ((v10 & 0x40000 | 0x10000u) >> 11);
}
else
{
v17 = v14 | 2;
if( (CheckFlags & 0x40000000) == 0 )
v17 = ((unsigned int)CheckFlags >> 19) & 0x40;
if( *Allocate )
v17 |= 1u;
}
while( 1 )
{
*v9 = 0i64;
a7 = 0i64;
LODWORD(FileInformationClass) = v17;
v18 = CmpOpenHiveFile(FileName, 0i64, &FileHandle, &a4, FileInformationClass, a6, (INT64)&a7, 0i64, 0i64);
v19 = v18;
if( v18 < 0 )
{
LODWORD(FileInformationClassa) = 16;
SetFailureLocation(result, 0i64, 28i64, (unsigned int)v18, FileInformationClassa);
v20 = FileHandle;
goto LABEL_9;
}
a5 = v17;
if( (_DWORD)a4 == 2 )
{
v35 = 1;
a5 = v17 | 0x10;
}
v20 = FileHandle;
if( !v48 )
{
v19 = CmpQueryFileSecurityDescriptor(FileHandle, &SecurityDescriptor);
if( v19 < 0 )
{
LODWORD(FileInformationClassa) = 32;
SetFailureLocation(result, 0i64, 28i64, (unsigned int)v19, FileInformationClassa);
v16 = SecurityDescriptor;
goto LABEL_9;
}
v16 = SecurityDescriptor;
}
LODWORD(FileInformationClassa) = a5;
if( (CheckFlags & 0x10000000) != 0 )
{
a5_4 = 1;
Hive = CmpOpenHiveFile(
FileName,
1ui64,
&Handle,
(INT64 *)((char *)&a4 + 4),
FileInformationClassa,
v43,
0i64,
(INT64)v16,
0i64);
v19 = Hive;
if( Hive < 0 )
{
v13 = 0i64;
Handle = 0i64;
if( v34 )
{
LODWORD(FileInformationClass) = 48;
goto LABEL_78;
}
}
else
{
v13 = Handle;
}
}
else
{
a5_4 = 2;
v19 = CmpOpenHiveFile(
FileName,
4ui64,
&Handle,
(INT64 *)((char *)&a4 + 4),
FileInformationClassa,
v43,
0i64,
(INT64)v16,
0i64);
if( v19 < 0 )
{
v13 = 0i64;
Handle = 0i64;
if( v34 )
{
LODWORD(FileInformationClass) = 64;
v30 = (unsigned int)v19;
LABEL_79:
SetFailureLocation(result, 0i64, 28i64, v30, FileInformationClass);
goto LABEL_9;
}
}
else
{
v13 = Handle;
}
LODWORD(FileInformationClass) = a5;
Hive = CmpOpenHiveFile(FileName, 5ui64, &v42, &v49, FileInformationClass, v43, 0i64, (INT64)v16, 0i64);
v19 = Hive;
if( Hive >= 0 )
{
v15 = v42;
goto LABEL_31;
}
v15 = 0i64;
v42 = 0i64;
if( v34 )
{
LODWORD(FileInformationClass) = 80;
LABEL_78:
v30 = (unsigned int)Hive;
goto LABEL_79;
}
}
LABEL_31:
if( !v34 )
{
if( a5_4 != 2 )
{
a5_4 = v13 != 0i64;
goto LABEL_35;
}
if( v13 )
{
if( v15 )
goto LABEL_35;
ZwClose(v13);
v13 = 0i64;
Handle = 0i64;
}
if( v15 )
{
ZwClose(v15);
v15 = 0i64;
v42 = 0i64;
}
a5_4 = 0;
}
LABEL_35:
if( !v36 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v36 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
if( !v36 )
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
v13 = Handle;
v15 = v42;
v20 = FileHandle;
v16 = SecurityDescriptor;
if( !v36 )
{
v19 = -1073741431;
goto LABEL_9;
}
}
a12 = result;
v53[0] = (INT64)v20;
v53[1] = (INT64)v13;
v54 = (unsigned __int64)v15;
memset(result, 0i64);
LODWORD(a8) = CheckFlags;
Hive = CmpCreateHive(
(INT64)&BugCheckParameter2,
v35 == 0 ? 5 : 0,
HIDWORD(v49),
a5_4,
0i64,
(INT64)v53,
(INT64)FileName,
a8,
0i64,
0i64,
a11,
a12);
v19 = Hive;
if( Hive != -1073741267 )
break;
ZwClose(v20);
FileHandle = 0i64;
if( v13 )
{
ZwClose(v13);
v13 = 0i64;
Handle = 0i64;
}
a6 = v43;
v9 = v47;
if( v15 )
{
ZwClose(v15);
a6 = v43;
v15 = 0i64;
v9 = v47;
v42 = 0i64;
}
}
if( Hive < 0 )
{
LODWORD(FileInformationClass) = 96;
goto LABEL_78;
}
v25 = v35;
if( !v35 && (*(_DWORD *)(BugCheckParameter2 + 4152) & 0x800) != 0 )
{
CmpAttachToRegistryProcess(&ApcState);
v29 = CmpFlushHive(BugCheckParameter2, 12, v28);
KiUnstackDetachProcess(&ApcState, 0i64);
if( v29 < 0 )
{
LODWORD(FileInformationClass) = 230;
SetFailureLocation(result, 1i64, 1i64, (unsigned int)v29, FileInformationClass);
}
v25 = 0;
}
PoolWithTag = ExAllocatePoolWithTag(PagedPool, FileName->Length, 0x624E4D43ui64);
*(_QWORD *)(BugCheckParameter2 + 1840) = PoolWithTag;
v27 = BugCheckParameter2;
if( *(_QWORD *)(BugCheckParameter2 + 1840) )
{
*(_WORD *)(BugCheckParameter2 + 1832) = FileName->Length;
*(_WORD *)(BugCheckParameter2 + 1834) = FileName->Length;
memmove(*(UINT8 **)(BugCheckParameter2 + 1840), (UINT8 *)FileName->Buffer, FileName->Length);
v27 = BugCheckParameter2;
}
if( (*(_DWORD *)(*(_QWORD *)(v27 + 64) + 4088i64) & 4) != 0 )
CmpLogEvent((INT64)®_EVENT_SELFHEAL);
if( ZwQueryInformationFile(v20, &IoStatusBlock, &FileInformation, 0x28ui64, FileBasicInformation) >= 0 )
*(_QWORD *)(BugCheckParameter2 + 4224) = v57;
*(_DWORD *)(BugCheckParameter2 + 184) = HIDWORD(a7);
*v47 = (_CMHIVE *)BugCheckParameter2;
*v51 = v25;
v19 = 0;
LABEL_9:
if( v36 )
{
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
v13 = Handle;
v15 = v42;
v20 = FileHandle;
v16 = SecurityDescriptor;
}
if( v20 )
ZwClose(v20);
if( v13 )
ZwClose(v13);
if( v15 )
ZwClose(v15);
if( v16 )
ExFreePoolWithTag(v16, 0);
if( (unsigned int)dword_140C02130 > 4 && tlgKeywordOn((__int64)&dword_140C02130, 8i64) )
{
v68 = 0;
p_a5 = &a5;
a5 = v19;
v67 = 4;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&dword_140C02130,
(unsigned __int8 *)byte_140021A43,
0i64,
0i64,
3u,
&v65);
}
return(unsigned int)v19;
}Referenced by:
CmpCmdHiveOpen
CmpLoadHiveThread