NtSetInformationKey
VOID __stdcall NtSetInformationKey(
PVOID KeyHandle,
KEY_SET_INFORMATION_CLASS KeySetInformationClass,
PVOID KeySetInformation,
UINT64 KeySetInformationLength){
int v4;
char v7;
_ETHREAD *CurrentThread;
bool v9;
KPROCESSOR_MODE v10;
unsigned int v11;
char *v12;
ACCESS_MASK v13;
int v14;
SLIST_ENTRY *v15;
char v16;
_ETHREAD *v17;
char v18;
char v19;
KPROCESSOR_MODE v20;
KPROCESSOR_MODE v21;
__int64 v22;
__int32 v23;
__int32 v24;
__int32 v25;
int v26;
int v27;
int v28;
__int64 v29;
char v30;
char v31;
char v32;
KPROCESSOR_MODE v33;
PADAPTER_OBJECT DmaAdapter;
UINT8 dst[8];
int v36;
__int64 v37;
HANDLE Handle;
int v39;
INT64 v40[2];
PVOID v41;
PVOID v42;
PVOID Object;
PVOID v44;
struct _SECURITY_SUBJECT_CONTEXT SubjectContext;
SLIST_ENTRY *Argument[2];
__int128 v47;
__int128 v48;
__int64 v49;
SLIST_ENTRY *v50;
int v51;
int v52;
SLIST_ENTRY **v53;
int v54;
__int128 v55;
__int64 v56;
int v57;
LARGE_INTEGER v58[2];
__int128 v59;
v4 = KeySetInformationLength;
v39 = KeySetInformationLength;
Handle = KeyHandle;
*(_OWORD *)&v58[0].LowPart = 0i64;
v59 = 0i64;
v37 = 0i64;
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
EtwGetKernelTraceTimestamp(v58, 0x20000ui64);
v31 = 0;
DmaAdapter = 0i64;
v32 = 0;
*(_OWORD *)Argument = 0i64;
v47 = 0i64;
v48 = 0i64;
v49 = 0i64;
v40[1] = (INT64)v40;
v40[0] = (INT64)v40;
v36 = 0;
v7 = 0;
memset(&SubjectContext, 0, sizeof(SubjectContext));
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v9 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
if( !v9 )
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
if( !v9 )
{
v14 = -1073741431;
v15 = (SLIST_ENTRY *)DmaAdapter;
goto LABEL_50;
}
v10 = *((_BYTE *)KeGetCurrentThread() + 562);
v33 = v10;
if( KeySetInformationClass == KeySetHandleTagsInformation )
goto LABEL_7;
if( KeySetInformationClass )
{
if( KeySetInformationClass != KeyWow64FlagsInformation )
{
if( KeySetInformationClass == KeyControlFlagsInformation
|| KeySetInformationClass == KeySetVirtualizationInformation )
{
LABEL_7:
v30 = 0;
LABEL_8:
v11 = 4;
goto LABEL_9;
}
if( KeySetInformationClass != KeySetDebugInformation )
{
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
{
if( Handle )
{
v20 = *((_BYTE *)KeGetCurrentThread() + 562);
v41 = 0i64;
if( ObReferenceObjectByHandle(Handle, 0, (POBJECT_TYPE)CmKeyObjectType, v20, &v41, 0i64) >= 0 )
{
v37 = *((_QWORD *)v41 + 1);
HalPutDmaAdapter((PADAPTER_OBJECT)v41);
}
}
}
v14 = -1073741821;
v15 = (SLIST_ENTRY *)DmaAdapter;
v18 = 0;
v19 = 0;
goto LABEL_30;
}
}
v30 = 1;
goto LABEL_8;
}
v11 = 8;
v30 = 1;
LABEL_9:
if( v4 != v11 )
{
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
{
if( Handle )
{
v21 = *((_BYTE *)KeGetCurrentThread() + 562);
v42 = 0i64;
if( ObReferenceObjectByHandle(Handle, 0, (POBJECT_TYPE)CmKeyObjectType, v21, &v42, 0i64) >= 0 )
{
v37 = *((_QWORD *)v42 + 1);
HalPutDmaAdapter((PADAPTER_OBJECT)v42);
}
}
}
v14 = -1073741820;
v15 = (SLIST_ENTRY *)DmaAdapter;
v18 = 0;
v19 = 0;
goto LABEL_30;
}
*(_QWORD *)dst = 0i64;
if( v10 )
{
v12 = (char *)KeySetInformation + v11;
if( (unsigned __int64)v12 > 0x7FFFFFFF0000i64 || v12 < KeySetInformation )
MEMORY[0x7FFFFFFF0000] = 0;
}
memmove(dst, (UINT8 *)KeySetInformation, v11);
if( KeySetInformationClass == KeySetHandleTagsInformation )
v13 = 0;
else
v13 = 2;
Object = 0i64;
v14 = ObReferenceObjectByHandle(Handle, v13, (POBJECT_TYPE)CmKeyObjectType, v10, &Object, 0i64);
v15 = (SLIST_ENTRY *)Object;
DmaAdapter = (PADAPTER_OBJECT)Object;
if( v14 == -1073741790 )
{
if( !v30 )
{
v14 = -1073741790;
v18 = 0;
v19 = 0;
goto LABEL_30;
}
SeCaptureSubjectContext(&SubjectContext);
v7 = 1;
if( !CmDoVirtualTest((UINT64 *)&SubjectContext) )
{
v14 = -1073741790;
v18 = 0;
v19 = 0;
goto LABEL_30;
}
v44 = 0i64;
v14 = ObReferenceObjectByHandle(Handle, 0x20019u, (POBJECT_TYPE)CmKeyObjectType, v33, &v44, 0i64);
v15 = (SLIST_ENTRY *)v44;
DmaAdapter = (PADAPTER_OBJECT)v44;
if( v14 < 0 )
{
LABEL_50:
v18 = 0;
v19 = 0;
goto LABEL_30;
}
if( !CmKeyBodyNeedsVirtualImage((__int64)v44) )
{
v14 = -1073741790;
v18 = 0;
v19 = 0;
goto LABEL_30;
}
v14 = 0;
v16 = 1;
v32 = 1;
}
else
{
v16 = 0;
}
v7 = v16;
if( v14 < 0 )
goto LABEL_50;
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) && v15 )
v37 = *((_QWORD *)&v15->Next + 1);
if( KeySetInformationClass == KeySetHandleTagsInformation )
{
LABEL_21:
v17 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v17 + 242);
if( CmpCallBackCount )
{
v15 = (SLIST_ENTRY *)DmaAdapter;
if( !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock) )
{
Argument[0] = (SLIST_ENTRY *)DmaAdapter;
LODWORD(Argument[1]) = KeySetInformationClass;
*(_QWORD *)&v47 = KeySetInformation;
DWORD2(v47) = v39;
v14 = CmpCallCallBacksEx(
RegNtSetInformationKey,
Argument,
0i64,
1,
RegNtPostSetInformationKey,
(INT64)DmaAdapter,
(INT64)v40);
if( v14 < 0 )
{
if( v14 == -1073740541 )
v14 = 0;
v7 = v32;
v18 = 0;
goto LABEL_29;
}
v31 = 1;
}
}
else
{
v15 = (SLIST_ENTRY *)DmaAdapter;
}
if( !v32
|| (v14 = CmKeyBodyReplicateToVirtual((__int64 *)&DmaAdapter, v33, 2u, (__int64 *)&SubjectContext),
v7 = v32,
v15 = (SLIST_ENTRY *)DmaAdapter,
v14 >= 0) )
{
v7 = v32;
if( KeySetInformationClass != KeySetHandleTagsInformation )
{
if( KeySetInformationClass )
{
v23 = KeySetInformationClass - 1;
if( v23 )
{
v24 = v23 - 1;
if( v24 )
{
v25 = v24 - 1;
if( v25 )
{
if( v25 != 1 )
goto LABEL_28;
v26 = *(_DWORD *)dst;
v27 = 4;
}
else
{
v26 = *(_DWORD *)dst;
v27 = 3;
}
}
else
{
v26 = *(_DWORD *)dst;
v27 = 2;
}
}
else
{
v26 = *(_DWORD *)dst;
v27 = 1;
}
v28 = CmSetKeyFlags((__int64)v15, v27, v26);
}
else
{
v28 = CmSetLastWriteTimeKey((__int64 *)v15, dst);
}
v14 = v28;
goto LABEL_28;
}
WORD1(v15[3].Next) = *(_WORD *)dst;
v14 = 0;
}
LABEL_28:
v18 = v31;
LABEL_29:
v19 = 1;
goto LABEL_30;
}
v22 = *((_QWORD *)&v15->Next + 1);
if( (*(_DWORD *)(v22 + 8) & 0x80u) == 0 )
{
if( (*(_DWORD *)(*(_QWORD *)(v22 + 32) + 160i64) & 0x100000) == 0 )
goto LABEL_21;
v14 = -1073741790;
v18 = 0;
v19 = 0;
}
else
{
v14 = -1073741790;
v18 = 0;
v19 = 0;
}
LABEL_30:
if( v7 )
SeReleaseSubjectContext(&SubjectContext);
if( v18
&& CmpCallBackCount
&& !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock)
&& (INT64 *)v40[0] != v40 )
{
v52 = 0;
v55 = 0i64;
v56 = 0i64;
v57 = 0;
v50 = v15;
v51 = v14;
v54 = v14;
v53 = Argument;
CmpCallCallBacksEx(RegNtPostSetInformationKey, &v50, 0i64, 0, RegNtPostSetInformationKey, (INT64)v15, (INT64)v40);
v14 = v54;
}
if( v19 )
{
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
v15 = (SLIST_ENTRY *)DmaAdapter;
}
if( v15 )
HalPutDmaAdapter((PADAPTER_OBJECT)v15);
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
{
v29 = v37;
LOBYTE(v29) = 20;
(*(void(__fastcall **)(__int64, LARGE_INTEGER *, _QWORD, _QWORD, __int64, _QWORD))((char *)&NlsMbCodePageTag + 7))(
v29,
v58,
(unsigned int)v14,
0i64,
v37,
0i64);
}
if( v9 )
{
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
}
}Referenced by:
No references.