ViXdvDriverLoadImage
UINT8 __stdcall ViXdvDriverLoadImage(_KLDR_DATA_TABLE_ENTRY *DataTableEntry){
char *v1;
UINT8 v2;
_IMAGE_EXPORT_DIRECTORY *v3;
_IMAGE_EXPORT_DIRECTORY *v4;
UINT8 v5;
char *v6;
UINT8 v7;
__int64 v8;
const CHAR *v9;
int(__fastcall *FuncAddress)(__int64 *, __int64(__fastcall **)());
UINT64 *v11;
INT8 *v12;
UINT64 *v13;
void(__fastcall *v14)(__int64(__fastcall **)(PCONTEXT));
UINT64 *v15;
UINT64 v17;
v1 = (char *)*((_QWORD *)DataTableEntry + 6);
v2 = 1;
LODWORD(v3) = RtlImageDirectoryEntryToData(v1, 1u, 0, &v17);
v4 = v3;
if( !v3 || !v3->NumberOfNames )
return 0;
v5 = 0;
v6 = &v1[v3->AddressOfNames];
v7 = 0;
v8 = 0i64;
do
{
v9 = &v1[*(unsigned int *)&v6[4 * v8]];
if( !(unsigned int)strcmp("DifLoadPlugins", v9) )
{
if( VfIsRuleClassEnabled(0x23ui64) )
{
FuncAddress = (int(__fastcall *)(__int64 *, __int64(__fastcall **)()))ViXdvGetFuncAddress(
v1,
v4,
(unsigned int)v8);
if( !ViXdvSetRequestedAPIsforDIF(FuncAddress) )
VfDifAPIThunkContextHead = 0i64;
}
goto LABEL_30;
}
if( !(unsigned int)strcmp("DifUpdatePluginState", v9) )
{
if( VfIsRuleClassEnabled(0x23ui64) )
PFnViUpdateDIFPlugins = (__int64)ViXdvGetFuncAddress(v1, v4, (unsigned int)v8);
goto LABEL_30;
}
if( !(unsigned int)strcmp("GetXdvDDIWrappers", v9) )
{
v11 = ViXdvGetFuncAddress(v1, v4, (unsigned int)v8);
v5 = ViXdvBindXdvDDIWrappers(v11);
if( v5 == 1 )
goto LABEL_30;
v12 = "Error on Verifier Extention DDI bound process\n";
LABEL_29:
VfUtilDbgPrint(v12);
goto LABEL_30;
}
if( !(unsigned int)strcmp("GetXdvDriverEntryWrappers", v9) )
{
v13 = ViXdvGetFuncAddress(v1, v4, (unsigned int)v8);
v7 = ViXdvBindXdvDriverEntryWrappers(v13);
if( v7 == 1 )
goto LABEL_30;
v12 = "Error on Verifier Extention entry point bound process\n";
goto LABEL_29;
}
if( !(unsigned int)strcmp("SetXdvKernelUtilities", v9) )
{
v14 = (void(__fastcall *)(__int64(__fastcall **)(PCONTEXT)))ViXdvGetFuncAddress(v1, v4, (unsigned int)v8);
if( ViXdvSetXdvKernelUtilities(v14) )
goto LABEL_30;
v12 = "Error on providing kernel utilities to XDV.\n";
goto LABEL_29;
}
if( !(unsigned int)strcmp("XdvHibernationNotification", v9) )
{
ViFnExtensionHiberFunc = ViXdvGetFuncAddress(v1, v4, (unsigned int)v8);
goto LABEL_30;
}
if( !(unsigned int)strcmp("XdvNotifyExtensions", v9) )
{
ViFnXdvNotifyExtensions = (__int64)ViXdvGetFuncAddress(v1, v4, (unsigned int)v8);
goto LABEL_30;
}
if( !(unsigned int)strcmp("XdvQueryDispatchTable", v9) )
{
v15 = ViXdvGetFuncAddress(v1, v4, (unsigned int)v8);
ViFnXdvQueryDispatchTable = (__int64(__fastcall *)(_QWORD))v15;
if( v15 )
{
ViXdvTipUtils = ((__int64(__fastcall *)(__int64))v15)(4i64);
if( ViXdvTipUtils )
goto LABEL_30;
v12 = "Error on getting TiP utilities from XDV.\n";
}
else
{
v12 = (INT8 *)"Error on getting XdvQueryDispatchTable utility from XDV.\n";
}
goto LABEL_29;
}
LABEL_30:
v8 = (unsigned int)(v8 + 1);
}
while( (unsigned int)v8 < v4->NumberOfNames );
if( !v5 || !v7 )
return 0;
return v2;
}Referenced by:
ViLogAndLoadXdv