SbpStartLanman
INT64 __fastcall SbpStartLanman(){
char *v0;
void *v1;
NTSTATUS DeviceObjectPointer;
PFILE_OBJECT v3;
NTSTATUS Status;
char *PoolWithTag;
_DEVICE_OBJECT *v6;
_IRP *v7;
IRP *v8;
__int64 v9;
_DEVICE_OBJECT *v10;
char *v11;
_DEVICE_OBJECT *v12;
_IRP *v13;
IRP *v14;
__int64 v15;
_DEVICE_OBJECT *v16;
UINT64 OutputBufferLength;
UINT64 OutputBufferLengtha;
_KEVENT Object;
PDEVICE_OBJECT DeviceObject;
PFILE_OBJECT FileObject;
_IO_STATUS_BLOCK IoStatusBlock;
__int128 InputBuffer[2];
int v25;
PVOID ReturnAddress;
DeviceObject = 0i64;
v25 = 0;
memset(&Object, 0, sizeof(Object));
FileObject = 0i64;
v0 = 0i64;
IoStatusBlock = 0i64;
v1 = 0i64;
memset(InputBuffer, 0, sizeof(InputBuffer));
DeviceObjectPointer = IoGetDeviceObjectPointer(
(UNICODE_STRING *)&LanmanRedirectorName,
0x10000000ui64,
&FileObject,
&DeviceObject);
v3 = FileObject;
Status = DeviceObjectPointer;
if( DeviceObjectPointer < 0 )
goto LABEL_12;
PoolWithTag = (char *)ExAllocatePoolWithTag(NonPagedPoolNx, 0x8Cui64, 0x42626D53ui64);
v1 = PoolWithTag;
if( !PoolWithTag )
goto LABEL_3;
*((_DWORD *)PoolWithTag + 15) = -1;
*((_DWORD *)PoolWithTag + 4) = 5;
*(_DWORD *)PoolWithTag = 3600;
*((_DWORD *)PoolWithTag + 2) = 16;
*((_DWORD *)PoolWithTag + 1) = 250;
*((_DWORD *)PoolWithTag + 3) = 600;
*((_DWORD *)PoolWithTag + 5) = 45;
*((_DWORD *)PoolWithTag + 9) = 10;
*((_DWORD *)PoolWithTag + 6) = 512;
*((_DWORD *)PoolWithTag + 7) = 17;
*((_DWORD *)PoolWithTag + 8) = 6144;
*((_DWORD *)PoolWithTag + 10) = 500;
*((_DWORD *)PoolWithTag + 12) = 500;
*((_DWORD *)PoolWithTag + 11) = 10;
*((_DWORD *)PoolWithTag + 14) = 45;
*((_DWORD *)PoolWithTag + 18) = 5;
v6 = DeviceObject;
*((_DWORD *)PoolWithTag + 13) = 40;
*((_DWORD *)PoolWithTag + 16) = 3;
*((_DWORD *)PoolWithTag + 17) = 20;
*(_QWORD *)(PoolWithTag + 76) = 60i64;
*((_DWORD *)PoolWithTag + 21) = 1;
*((_DWORD *)PoolWithTag + 22) = 1;
*((_DWORD *)PoolWithTag + 23) = 1;
*((_DWORD *)PoolWithTag + 24) = 1;
*((_DWORD *)PoolWithTag + 25) = 1;
*((_DWORD *)PoolWithTag + 26) = 1;
*((_DWORD *)PoolWithTag + 27) = 1;
*((_DWORD *)PoolWithTag + 28) = 1;
*((_DWORD *)PoolWithTag + 29) = 1;
*((_DWORD *)PoolWithTag + 30) = 1;
*((_DWORD *)PoolWithTag + 31) = 1;
*((_DWORD *)PoolWithTag + 32) = 1;
*(_QWORD *)(PoolWithTag + 132) = 1i64;
Object.Header.WaitListHead.Blink = &Object.Header.WaitListHead;
Object.Header.WaitListHead.Flink = &Object.Header.WaitListHead;
LODWORD(OutputBufferLength) = 140;
LOWORD(Object.Header.Lock) = 1;
Object.Header.Size = 6;
Object.Header.SignalState = 0;
v7 = IopBuildDeviceIoControlRequest(
0x80140191ui64,
v6,
InputBuffer,
0x24ui64,
PoolWithTag,
OutputBufferLength,
0,
&Object,
&IoStatusBlock,
ReturnAddress);
v8 = v7;
if( !v7 )
goto LABEL_3;
v9 = *((_QWORD *)v7 + 23);
v10 = DeviceObject;
*(_QWORD *)(v9 - 24) = v3;
*(_BYTE *)(v9 - 72) = 13;
Status = IofCallDriver(v10, v8);
if( Status == 259 )
{
KeWaitForSingleObject(&Object, Executive, 0, 0, 0i64);
Status = IoStatusBlock.Status;
}
if( Status >= 0 )
{
v11 = (char *)ExAllocatePoolWithTag(NonPagedPoolNx, 0x76ui64, 0x42626D53ui64);
v0 = v11;
if( v11 )
{
memset((INT64)v11, 0i64);
v0[65] |= 1u;
*((_DWORD *)v0 + 17) = -1;
v12 = DeviceObject;
*((_WORD *)v0 + 6) = 94;
v0[84] = 1;
*((_DWORD *)v0 + 19) = 30;
*((_WORD *)v0 + 43) = 26;
*((_DWORD *)v0 + 20) = 30;
*((_DWORD *)v0 + 8) = 20;
*((_DWORD *)v0 + 10) = 20;
*((_DWORD *)v0 + 6) = 30;
v0[64] = 31;
*((_DWORD *)v0 + 18) = 10;
*((_DWORD *)v0 + 5) = 120;
*((_DWORD *)v0 + 7) = 0x8000;
*((_DWORD *)v0 + 9) = 5;
*((_DWORD *)v0 + 11) = 2048;
*((_DWORD *)v0 + 12) = 32;
*((_DWORD *)v0 + 13) = 512;
*((_DWORD *)v0 + 14) = 0x1000000;
*((_DWORD *)v0 + 15) = 0x100000;
*(_OWORD *)(v0 + 88) = *(_OWORD *)L"\\Device\\vmsmb";
*((_QWORD *)v0 + 13) = *(_QWORD *)L"vmsmb";
*((_WORD *)v0 + 56) = aDeviceVmsmb[12];
Object.Header.WaitListHead.Blink = &Object.Header.WaitListHead;
Object.Header.WaitListHead.Flink = &Object.Header.WaitListHead;
LODWORD(OutputBufferLengtha) = 0;
LOWORD(Object.Header.Lock) = 1;
Object.Header.Size = 6;
Object.Header.SignalState = 0;
v13 = IopBuildDeviceIoControlRequest(
0x1403A0ui64,
v12,
v0,
0x76ui64,
0i64,
OutputBufferLengtha,
0,
&Object,
&IoStatusBlock,
ReturnAddress);
v14 = v13;
if( v13 )
{
v15 = *((_QWORD *)v13 + 23);
v16 = DeviceObject;
*(_QWORD *)(v15 - 24) = v3;
*(_BYTE *)(v15 - 72) = 13;
Status = IofCallDriver(v16, v14);
if( Status == 259 )
{
KeWaitForSingleObject(&Object, Executive, 0, 0, 0i64);
Status = IoStatusBlock.Status;
}
goto LABEL_12;
}
}
LABEL_3:
Status = -1073741670;
}
LABEL_12:
if( v3 )
ObfDereferenceObjectWithTag(v3, 0x746C6644ui64);
if( v1 )
ExFreeHeapPool(v1);
if( v0 )
ExFreeHeapPool(v0);
return(unsigned int)Status;
}Referenced by:
IopInitializeBootDrivers