PspCreateProcess
INT64 __stdcall PspCreateProcess(
PVOID *ProcessHandle,
UINT64 DesiredAccess,
OBJECT_ATTRIBUTES *ObjectAttributes,
PVOID ParentProcess,
UINT64 CreateFlags,
PVOID SectionHandle,
PVOID DebugPort,
PVOID TokenHandle){
struct _DMA_ADAPTER *v10;
PVOID v11;
int ProcessProtectionRequirementsFromImage;
VOID *v13;
UINT8 v14;
int v15;
int v16;
char v17;
INT64 v18;
_UNICODE_STRING *ObjectName;
unsigned int Attributes;
int v21;
_UNICODE_STRING *v22;
VOID **HandleInformation;
__int64 v24;
UINT8 v25;
CHAR v26;
CHAR v27;
char v28;
char v29;
int v30;
PVOID Object;
PADAPTER_OBJECT DmaAdapter;
int v33;
PVOID v34;
PVOID v35;
void *v36;
__int64 v37;
__int64 v38;
PVOID v39;
HANDLE v40;
INT64 result[48];
unsigned int v42;
char v43;
__int64 v44;
void *v45;
v33 = DesiredAccess;
v38 = (__int64)ProcessHandle;
v40 = TokenHandle;
v36 = v45;
v37 = 0i64;
v29 = 0;
v34 = 0i64;
Object = 0i64;
v26 = 0;
v27 = 0;
DmaAdapter = 0i64;
if( ((unsigned int)SectionHandle & 0xFFF94040) != 0
|| (*(_BYTE *)(*((_QWORD *)KeGetCurrentThread() + 23) + 2170i64) & 7) != 0 && (_BYTE)CreateFlags )
{
return 3221225485i64;
}
if( ((unsigned __int16)SectionHandle & 0x4000) != 0 && ((unsigned __int16)SectionHandle & 0x2000) == 0 )
return 3221225485i64;
v30 = (unsigned __int16)SectionHandle & 0x800;
if( ((unsigned __int16)SectionHandle & 0x2000) != 0 && ((unsigned __int16)SectionHandle & 0x800) == 0 )
return 3221225485i64;
if( ((unsigned __int16)SectionHandle & 0x800) != 0 )
{
if( (_BYTE)CreateFlags )
return 3221225485i64;
if( ObjectAttributes )
{
if( ObjectAttributes->RootDirectory )
return 3221225485i64;
ObjectName = ObjectAttributes->ObjectName;
if( !ObjectName
|| !ObjectName->Buffer
|| !ObjectName->Length
|| ObjectAttributes->Attributes != 512
|| ObjectAttributes->SecurityDescriptor
|| ObjectAttributes->SecurityQualityOfService )
{
return 3221225485i64;
}
}
if( DebugPort || TokenHandle || !ParentProcess )
return 3221225485i64;
}
if( ((unsigned int)SectionHandle & 0x20000) != 0
&& ((_BYTE)CreateFlags || ((unsigned __int16)SectionHandle & 0x800) == 0) )
{
return 3221225485i64;
}
memset((INT64)result, 0i64);
v43 = CreateFlags;
if( ObjectAttributes )
{
if( (_BYTE)CreateFlags )
{
if( ((unsigned __int8)ObjectAttributes & 3) != 0 )
ExRaiseDatatypeMisalignment();
Attributes = ObjectAttributes->Attributes;
v42 = Attributes;
}
else
{
Attributes = ObjectAttributes->Attributes;
}
if( (_BYTE)CreateFlags )
v21 = Attributes & 0x1DF2;
else
v21 = Attributes & 0x11FF2;
v42 = v21;
}
if( DebugPort )
{
v35 = 0i64;
LODWORD(v18) = ObReferenceObjectByHandle(DebugPort, 8u, MmSectionObjectType, CreateFlags, &v35, 0i64);
v10 = (struct _DMA_ADAPTER *)v35;
v39 = v35;
if( (int)v18 < 0 )
return v18;
}
else
{
v10 = 0i64;
v39 = 0i64;
}
if( !ParentProcess
|| (ProcessProtectionRequirementsFromImage = ObReferenceObjectByHandleWithTag(
ParentProcess,
0x80u,
(POBJECT_TYPE)PsProcessType,
CreateFlags,
0x72437350u,
&v34,
0i64),
ProcessProtectionRequirementsFromImage >= 0) )
{
v11 = v34;
ProcessProtectionRequirementsFromImage = PspReferenceTokenForNewProcess(
(_EPROCESS *)v34,
v45,
CreateFlags,
&DmaAdapter);
if( ProcessProtectionRequirementsFromImage < 0 )
goto LABEL_28;
if( v11 )
{
if( v10 )
{
v25 = 0;
ProcessProtectionRequirementsFromImage = SeQuerySigningPolicy(DmaAdapter, 0i64, 0, 0, &v26, &v27, &v25);
if( ProcessProtectionRequirementsFromImage < 0 )
goto LABEL_27;
v28 = v26;
if( (unsigned __int8)v26 > 1u || (v14 = v25) != 0 )
{
LABEL_72:
ProcessProtectionRequirementsFromImage = -1073741637;
goto LABEL_27;
}
LABEL_15:
if( !v10 )
goto LABEL_16;
ProcessProtectionRequirementsFromImage = PspGetProcessProtectionRequirementsFromImage((INT64)v10);
if( ProcessProtectionRequirementsFromImage >= 0 )
{
if( v14 == v29 )
{
LABEL_16:
if( v30 )
{
if( ObjectAttributes )
v22 = ObjectAttributes->ObjectName;
else
v22 = 0i64;
LODWORD(HandleInformation) = (_DWORD)SectionHandle;
LOBYTE(v13) = v14;
ProcessProtectionRequirementsFromImage = PsCreateMinimalProcess(
(_EPROCESS *)v11,
v22,
0,
v13,
(unsigned __int64)DmaAdapter & -(__int64)(v36 != 0i64),
HandleInformation);
}
else
{
LODWORD(v24) = 0;
v15 = PspAllocateProcess(
(__int64)v11,
CreateFlags,
(volatile signed __int32 *)ObjectAttributes,
v14,
v28,
v27,
v10,
DmaAdapter,
(int)SectionHandle,
v24,
0i64,
v36 != 0i64,
0i64,
(__int64)&v37,
&Object);
ProcessProtectionRequirementsFromImage = v15;
if( v15 >= 0 )
{
v16 = v15;
v30 = v15;
v17 = 1;
if( (_DWORD)v37 )
v17 = 3;
ProcessProtectionRequirementsFromImage = PspInsertProcess(
(PADAPTER_OBJECT)Object,
v40,
v17,
0i64,
(PACCESS_STATE)result);
if( ProcessProtectionRequirementsFromImage >= 0 )
{
ProcessProtectionRequirementsFromImage = PspCreateObjectHandle(
Object,
(INT64)result,
(struct OBJECT_TYPE *)PsProcessType);
if( ProcessProtectionRequirementsFromImage >= 0 )
{
*(_QWORD *)v38 = v44;
ProcessProtectionRequirementsFromImage = v16;
}
PspDeleteObjectAccessState((ACCESS_STATE *)result);
}
if( ProcessProtectionRequirementsFromImage < 0 )
PspRundownSingleProcess((ULONG_PTR)Object, 0);
ObfDereferenceObjectWithTag(Object, 0x72437350ui64);
}
}
goto LABEL_27;
}
goto LABEL_72;
}
LABEL_27:
HalPutDmaAdapter(DmaAdapter);
LABEL_28:
if( v11 )
ObfDereferenceObjectWithTag(v11, 0x72437350ui64);
goto LABEL_30;
}
v14 = *((_BYTE *)v11 + 2170);
v27 = *((_BYTE *)v11 + 2169);
v28 = *((_BYTE *)v11 + 2168);
v26 = v28;
}
else
{
v14 = 114;
v28 = 30;
v26 = 30;
v27 = 28;
}
v25 = v14;
goto LABEL_15;
}
LABEL_30:
if( v10 )
HalPutDmaAdapter(v10);
return(unsigned int)ProcessProtectionRequirementsFromImage;
}Referenced by:
NtCreateProcessEx
PspInitPhase0