CmKeyBodyRemapToVirtualForEnum
__int64 __fastcall CmKeyBodyRemapToVirtualForEnum(__int64 *a1, char a2, DWORD a3, __int64 *a4){
DWORD v4;
WCHAR v8;
__int64 v9;
char v10;
UINT64 v11;
int AccessStateFromSubjectContext;
_UNICODE_STRING *v14;
__int64 v15;
int v16;
__int64 v17;
int v18;
char v19;
DWORD v20[3];
struct _UNICODE_STRING DestinationString;
struct _SECURITY_SUBJECT_CONTEXT SubjectContext;
int v23[2];
__int64 v24;
struct _UNICODE_STRING *p_DestinationString;
int v26;
int v27;
__int128 v28;
INT64 v29[12];
int v30;
_QWORD v31[9];
__int128 v32;
__int128 v33;
__int128 v34;
__int128 v35;
__int128 v36;
KAPC_STATE ApcState;
struct _SECURITY_SUBJECT_CONTEXT result[5];
__int64 v39[28];
v4 = a3;
v20[0] = a3;
DestinationString = 0i64;
memset((INT64)result, 0i64);
memset((INT64)v39, 0i64);
v23[1] = 0;
v27 = 0;
RtlInitUnicodeString(&DestinationString, 0i64, v8);
v9 = *a1;
*(_QWORD *)&v20[1] = 0i64;
memset(&ApcState, 0, sizeof(ApcState));
memset((INT64)v29, 0i64);
v30 = -1;
*a4 = 0i64;
v31[1] = v31;
v10 = 0;
v32 = 0i64;
v19 = 0;
v31[0] = v31;
v33 = 0i64;
v34 = 0i64;
v35 = 0i64;
v36 = 0i64;
v11 = *(_QWORD *)(v9 + 8);
memset(&SubjectContext, 0, sizeof(SubjectContext));
if( !*(_WORD *)(v11 + 66) && (*(_DWORD *)(v9 + 48) & 0x10) == 0 )
{
if( KCBIsVirtualizable(v11) )
{
v10 = 1;
goto LABEL_5;
}
if( CmpVEEnabled && (*(_DWORD *)(v11 + 184) & 0x1000000) != 0 )
{
v19 = 1;
LABEL_5:
SeCaptureSubjectContext(&SubjectContext);
if( CmpIsSystemEntity((UINT64 *)(unsigned __int8)a2) )
{
AccessStateFromSubjectContext = 0;
LABEL_7:
SeReleaseSubjectContext(&SubjectContext);
goto LABEL_8;
}
if( v10 && (*(_DWORD *)(v11 + 184) & 0x800000) == 0 )
{
AccessStateFromSubjectContext = 0;
goto LABEL_7;
}
CmpAttachToRegistryProcess(&ApcState);
CmpLockRegistry();
CmpLockKcbShared((_CM_KEY_CONTROL_BLOCK *)v11);
if( v10 )
{
AccessStateFromSubjectContext = CmpPerformKeyBodyDeletionCheck(v9, 0i64);
if( AccessStateFromSubjectContext < 0 )
{
LABEL_32:
CmpUnlockKcb(v11);
CmpUnlockRegistry();
LABEL_38:
CmpDetachFromRegistryProcess(&ApcState);
goto LABEL_7;
}
if( (unsigned __int8)CmpReparseToVirtualPath(
(_CM_KEY_CONTROL_BLOCK *)v11,
v14,
(_UNICODE_STRING *)&SubjectContext) )
{
v4 = v20[0];
goto LABEL_22;
}
}
else if( CmVirtualKCBToRealPath((_CM_KEY_CONTROL_BLOCK *)v11, &DestinationString) >= 0 )
{
LABEL_22:
CmpUnlockKcb(v11);
CmpUnlockRegistry();
v15 = *a1;
v16 = 8;
LODWORD(v29[0]) = 8;
if( !v4 )
v16 = 4104;
v29[9] = *(_QWORD *)(v15 + 56);
LODWORD(v29[0]) = v16;
AccessStateFromSubjectContext = SeCreateAccessStateFromSubjectContext(
(INT64)&SubjectContext,
(INT64)result,
(INT64)v39,
v4,
(GENERIC_MAPPING *)((char *)CmKeyObjectType + 76));
if( AccessStateFromSubjectContext < 0 )
goto LABEL_38;
v18 = 1600;
v23[0] = 48;
v24 = 0i64;
v28 = 0i64;
if( a2 != 1 )
v18 = 576;
v26 = v18;
p_DestinationString = &DestinationString;
AccessStateFromSubjectContext = CmObReferenceObjectByName(
(__int64)v23,
result,
v20[0],
v17,
0,
(__int64)v29,
&v20[1]);
if( AccessStateFromSubjectContext >= 0 )
{
if( v10 )
{
*a4 = *(_QWORD *)&v20[1];
}
else
{
*a1 = *(_QWORD *)&v20[1];
*a4 = v9;
}
}
else if( !v19 )
{
goto LABEL_37;
}
AccessStateFromSubjectContext = 0;
LABEL_37:
SeDeleteAccessState((_ACCESS_STATE *)result);
goto LABEL_38;
}
AccessStateFromSubjectContext = 0;
goto LABEL_32;
}
}
AccessStateFromSubjectContext = 0;
LABEL_8:
if( DestinationString.Buffer )
ExFreePoolWithTag(DestinationString.Buffer, 0);
CmpCleanupParseContext((__int64)v29, 0);
return(unsigned int)AccessStateFromSubjectContext;
}Referenced by:
NtEnumerateKey
NtEnumerateValueKey
NtQueryKey
NtQueryMultipleValueKey
NtQueryValueKey