MiInitializeLoadedModuleList
UINT64 __fastcall MiInitializeLoadedModuleList(_LOADER_PARAMETER_BLOCK *LoaderBlock){
bool v2;
__int64 *v3;
__int64 v4;
__int64 v5;
__int64 v6;
int v7;
__int64 v9;
v9 = 0i64;
qword_140C4CA08 = (__int64)&qword_140C4CA00;
qword_140C4CA00 = (__int64)&qword_140C4CA00;
v2 = (KiSpeculationFeatures & 0x2000000) != 0 || (KiSpeculationFeatures & 0x4000000) != 0;
ExInitializeResourceLite(&PsLoadedModuleResource);
ExpCovPushLock.0 = 0i64;
*(&PsLoadedModuleList + 1) = &PsLoadedModuleList;
PsLoadedModuleList = &PsLoadedModuleList;
qword_140C16068 = (__int64)&ExpCovUnloadedModuleList;
ExpCovUnloadedModuleList = (UNICODE_STRING *)&ExpCovUnloadedModuleList;
NtSetDebugFilterState(0x7Eui64, 0i64, 1u);
v3 = (__int64 *)((char *)LoaderBlock + 16);
v4 = *v3;
MiLocateKernelSections(*v3);
if( (__int64 *)v4 == v3 )
{
LABEL_11:
MiBuildImportsForBootDrivers();
return 1i64;
}
else
{
while( (int)MiConstructLoaderEntry(v4, (const void **)(v4 + 88), (const void **)(v4 + 72), 0, 1, &v9) >= 0 )
{
v5 = v9;
v6 = v9 + 160;
if( *(_QWORD *)(v9 + 48) == PsNtosImageBase && (MiFlags & 0x80000) == 0 )
{
RtlCreateInvertedFunctionTableCacheEntry(*(PVOID *)(v9 + 48), *(unsigned int *)(v9 + 64));
v5 = v9;
}
MiLockdownSections(v5);
if( v2 && (*(_DWORD *)(v9 + 104) & 0x800000) == 0 )
{
v7 = MiCaptureBootDriverRetpolineInfo(*(PVOID *)(v9 + 48), *(unsigned int *)(v9 + 64), (UINT64 *)(v6 + 136));
if( ((v7 + 0x80000000) & 0x80000000) == 0 && v7 != -1073741637 )
break;
}
v4 = *(_QWORD *)v4;
if( (__int64 *)v4 == v3 )
goto LABEL_11;
}
return 0i64;
}
}Referenced by:
MiInitSystem