CmpInitHiveFromFile

INT64 __fastcall CmpInitHiveFromFile(
        _UNICODE_STRING *FileName,
        UINT64 HiveFlags,
        _CMHIVE **CmHive,
        UINT8 *Allocate,
        UINT64 CheckFlags,
        _GUID *HiveRmUuid,
        _GUID *HiveTmUuid,
        UINT8 *NeedRmLogStart,
        _HIVE_LOAD_FAILURE *HiveLoadFailure){
  _CMHIVE **v9; 
  int v10; 
  INT64 a6; 
  HANDLE v13; 
  unsigned int v14; 
  HANDLE v15; 
  PVOID v16; 
  unsigned int v17; 
  NTSTATUS v18; 
  NTSTATUS v19; 
  HANDLE v20; 
  int Hive; 
  _ETHREAD *CurrentThread; 
  INT64 a12; 
  char v25; 
  VOID *PoolWithTag; 
  ULONG_PTR v27; 
  EVENT_DESCRIPTOR *v28; 
  int v29; 
  INT64 v30; 
  INT64 FileInformationClass; 
  INT64 FileInformationClassa; 
  INT64 a8; 
  char v34; 
  char v35; 
  bool v36; 
  int a5; 
  unsigned int a5_4; 
  ULONG_PTR BugCheckParameter2; 
  HANDLE Handle; 
  INT64 result; 
  HANDLE v42; 
  INT64 v43; 
  HANDLE FileHandle; 
  PVOID SecurityDescriptor; 
  INT64 a4; 
  _CMHIVE **v47; 
  int v48; 
  INT64 v49; 
  INT64 a7; 
  UINT8 *v51; 
  INT64 a11; 
  INT64 v53[2]; 
  __int128 v54; 
  struct _IO_STATUS_BLOCK IoStatusBlock; 
  __int128 FileInformation; 
  __int128 v57; 
  __int64 v58; 
  KAPC_STATE ApcState; 
  struct _EVENT_DATA_DESCRIPTOR v60; 
  int *v61; 
  __int64 v62; 
  wchar_t *Buffer; 
  int v64[2]; 
  struct _EVENT_DATA_DESCRIPTOR v65; 
  int *p_a5; 
  int v67; 
  int v68; 
  INT64 v69; 
  a11 = (INT64)HiveLoadFailure;
  v9 = CmHive;
  result = v69;
  v47 = CmHive;
  v10 = HiveFlags;
  a6 = (INT64)HiveRmUuid;
  v51 = Allocate;
  HIDWORD(v49) = HiveFlags;
  v43 = (INT64)HiveRmUuid;
  *(_OWORD *)v53 = 0i64;
  v54 = 0i64;
  LODWORD(v49) = 0;
  BugCheckParameter2 = 0i64;
  a4 = 0i64;
  FileInformation = 0i64;
  v58 = 0i64;
  v57 = 0i64;
  IoStatusBlock = 0i64;
  memset(&ApcState, 0, sizeof(ApcState));
  if( (unsigned int)dword_140C02130 > 4 )
  {
    if( tlgKeywordOn((__int64)&dword_140C02130, 8i64) )
    {
      v62 = 2i64;
      v61 = v64;
      Buffer = FileName->Buffer;
      v64[0] = FileName->Length;
      v64[1] = 0;
      tlgWriteTransfer_EtwWriteTransfer(
        (__int64)&dword_140C02130,
        (unsigned __int8 *)byte_140021A6D,
        0i64,
        0i64,
        4u,
        &v60);
      Allocate = v51;
      v9 = v47;
    }
    a6 = v43;
  }
  v35 = 0;
  v13 = 0i64;
  v14 = ((unsigned int)CheckFlags >> 19) & 0x40;
  v36 = 0;
  FileHandle = 0i64;
  v48 = v10 & 0x8000;
  v15 = 0i64;
  Handle = 0i64;
  v16 = 0i64;
  v42 = 0i64;
  v34 = 1;
  SecurityDescriptor = 0i64;
  if( (v10 & 0x8000) != 0 )
  {
    v34 = 0;
    v17 = v14 | ((v10 & 0x40000 | 0x10000u) >> 11);
  }
  else
  {
    v17 = v14 | 2;
    if( (CheckFlags & 0x40000000) == 0 )
      v17 = ((unsigned int)CheckFlags >> 19) & 0x40;
    if( *Allocate )
      v17 |= 1u;
  }
  while( 1 )
  {
    *v9 = 0i64;
    a7 = 0i64;
    LODWORD(FileInformationClass) = v17;
    v18 = CmpOpenHiveFile(FileName, 0i64, &FileHandle, &a4, FileInformationClass, a6, (INT64)&a7, 0i64, 0i64);
    v19 = v18;
    if( v18 < 0 )
    {
      LODWORD(FileInformationClassa) = 16;
      SetFailureLocation(result, 0i64, 28i64, (unsigned int)v18, FileInformationClassa);
      v20 = FileHandle;
      goto LABEL_9;
    }
    a5 = v17;
    if( (_DWORD)a4 == 2 )
    {
      v35 = 1;
      a5 = v17 | 0x10;
    }
    v20 = FileHandle;
    if( !v48 )
    {
      v19 = CmpQueryFileSecurityDescriptor(FileHandle, &SecurityDescriptor);
      if( v19 < 0 )
      {
        LODWORD(FileInformationClassa) = 32;
        SetFailureLocation(result, 0i64, 28i64, (unsigned int)v19, FileInformationClassa);
        v16 = SecurityDescriptor;
        goto LABEL_9;
      }
      v16 = SecurityDescriptor;
    }
    LODWORD(FileInformationClassa) = a5;
    if( (CheckFlags & 0x10000000) != 0 )
    {
      a5_4 = 1;
      Hive = CmpOpenHiveFile(
               FileName,
               1ui64,
               &Handle,
               (INT64 *)((char *)&a4 + 4),
               FileInformationClassa,
               v43,
               0i64,
               (INT64)v16,
               0i64);
      v19 = Hive;
      if( Hive < 0 )
      {
        v13 = 0i64;
        Handle = 0i64;
        if( v34 )
        {
          LODWORD(FileInformationClass) = 48;
          goto LABEL_78;
        }
      }
      else
      {
        v13 = Handle;
      }
    }
    else
    {
      a5_4 = 2;
      v19 = CmpOpenHiveFile(
              FileName,
              4ui64,
              &Handle,
              (INT64 *)((char *)&a4 + 4),
              FileInformationClassa,
              v43,
              0i64,
              (INT64)v16,
              0i64);
      if( v19 < 0 )
      {
        v13 = 0i64;
        Handle = 0i64;
        if( v34 )
        {
          LODWORD(FileInformationClass) = 64;
          v30 = (unsigned int)v19;
LABEL_79:
          SetFailureLocation(result, 0i64, 28i64, v30, FileInformationClass);
          goto LABEL_9;
        }
      }
      else
      {
        v13 = Handle;
      }
      LODWORD(FileInformationClass) = a5;
      Hive = CmpOpenHiveFile(FileName, 5ui64, &v42, &v49, FileInformationClass, v43, 0i64, (INT64)v16, 0i64);
      v19 = Hive;
      if( Hive >= 0 )
      {
        v15 = v42;
        goto LABEL_31;
      }
      v15 = 0i64;
      v42 = 0i64;
      if( v34 )
      {
        LODWORD(FileInformationClass) = 80;
LABEL_78:
        v30 = (unsigned int)Hive;
        goto LABEL_79;
      }
    }
LABEL_31:
    if( !v34 )
    {
      if( a5_4 != 2 )
      {
        a5_4 = v13 != 0i64;
        goto LABEL_35;
      }
      if( v13 )
      {
        if( v15 )
          goto LABEL_35;
        ZwClose(v13);
        v13 = 0i64;
        Handle = 0i64;
      }
      if( v15 )
      {
        ZwClose(v15);
        v15 = 0i64;
        v42 = 0i64;
      }
      a5_4 = 0;
    }
LABEL_35:
    if( !v36 )
    {
      CurrentThread = (_ETHREAD *)KeGetCurrentThread();
      --*((_WORD *)CurrentThread + 242);
      v36 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
      if( !v36 )
        KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
      v13 = Handle;
      v15 = v42;
      v20 = FileHandle;
      v16 = SecurityDescriptor;
      if( !v36 )
      {
        v19 = -1073741431;
        goto LABEL_9;
      }
    }
    a12 = result;
    v53[0] = (INT64)v20;
    v53[1] = (INT64)v13;
    v54 = (unsigned __int64)v15;
    memset(result, 0i64);
    LODWORD(a8) = CheckFlags;
    Hive = CmpCreateHive(
             (INT64)&BugCheckParameter2,
             v35 == 0 ? 5 : 0,
             HIDWORD(v49),
             a5_4,
             0i64,
             (INT64)v53,
             (INT64)FileName,
             a8,
             0i64,
             0i64,
             a11,
             a12);
    v19 = Hive;
    if( Hive != -1073741267 )
      break;
    ZwClose(v20);
    FileHandle = 0i64;
    if( v13 )
    {
      ZwClose(v13);
      v13 = 0i64;
      Handle = 0i64;
    }
    a6 = v43;
    v9 = v47;
    if( v15 )
    {
      ZwClose(v15);
      a6 = v43;
      v15 = 0i64;
      v9 = v47;
      v42 = 0i64;
    }
  }
  if( Hive < 0 )
  {
    LODWORD(FileInformationClass) = 96;
    goto LABEL_78;
  }
  v25 = v35;
  if( !v35 && (*(_DWORD *)(BugCheckParameter2 + 4152) & 0x800) != 0 )
  {
    CmpAttachToRegistryProcess(&ApcState);
    v29 = CmpFlushHive(BugCheckParameter2, 12, v28);
    KiUnstackDetachProcess(&ApcState, 0i64);
    if( v29 < 0 )
    {
      LODWORD(FileInformationClass) = 230;
      SetFailureLocation(result, 1i64, 1i64, (unsigned int)v29, FileInformationClass);
    }
    v25 = 0;
  }
  PoolWithTag = ExAllocatePoolWithTag(PagedPool, FileName->Length, 0x624E4D43ui64);
  *(_QWORD *)(BugCheckParameter2 + 1840) = PoolWithTag;
  v27 = BugCheckParameter2;
  if( *(_QWORD *)(BugCheckParameter2 + 1840) )
  {
    *(_WORD *)(BugCheckParameter2 + 1832) = FileName->Length;
    *(_WORD *)(BugCheckParameter2 + 1834) = FileName->Length;
    memmove(*(UINT8 **)(BugCheckParameter2 + 1840), (UINT8 *)FileName->Buffer, FileName->Length);
    v27 = BugCheckParameter2;
  }
  if( (*(_DWORD *)(*(_QWORD *)(v27 + 64) + 4088i64) & 4) != 0 )
    CmpLogEvent((INT64)®_EVENT_SELFHEAL);
  if( ZwQueryInformationFile(v20, &IoStatusBlock, &FileInformation, 0x28ui64, FileBasicInformation) >= 0 )
    *(_QWORD *)(BugCheckParameter2 + 4224) = v57;
  *(_DWORD *)(BugCheckParameter2 + 184) = HIDWORD(a7);
  *v47 = (_CMHIVE *)BugCheckParameter2;
  *v51 = v25;
  v19 = 0;
LABEL_9:
  if( v36 )
  {
    ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
    v13 = Handle;
    v15 = v42;
    v20 = FileHandle;
    v16 = SecurityDescriptor;
  }
  if( v20 )
    ZwClose(v20);
  if( v13 )
    ZwClose(v13);
  if( v15 )
    ZwClose(v15);
  if( v16 )
    ExFreePoolWithTag(v16, 0);
  if( (unsigned int)dword_140C02130 > 4 && tlgKeywordOn((__int64)&dword_140C02130, 8i64) )
  {
    v68 = 0;
    p_a5 = &a5;
    a5 = v19;
    v67 = 4;
    tlgWriteTransfer_EtwWriteTransfer(
      (__int64)&dword_140C02130,
      (unsigned __int8 *)byte_140021A43,
      0i64,
      0i64,
      3u,
      &v65);
  }
  return(unsigned int)v19;
}

Referenced by:

CmpCmdHiveOpen
CmpLoadHiveThread