SPCallServerHandleWaitForDisplayWindow

INT64 __fastcall SPCallServerHandleWaitForDisplayWindow(INT64 a1, INT64 a2, INT64 a3, INT64 a4){
  __int64 v4; 
  unsigned int *v7; 
  unsigned int v8; 
  int v9; 
  int v10; 
  UINT64 v11; 
  UINT8 v12; 
  NTSTATUS v13; 
  NTSTATUS v14; 
  unsigned int *v15; 
  unsigned int i; 
  __int64 v17; 
  unsigned int *v18; 
  unsigned int v19; 
  unsigned int *v20; 
  NTSTATUS v21; 
  int v22; 
  unsigned int v23; 
  _DWORD *PoolWithTag; 
  int v26; 
  unsigned int v27; 
  __int64 v28; 
  int v29; 
  unsigned int v30; 
  int v31; 
  unsigned int v32; 
  __int64 v33; 
  int v34; 
  unsigned int v35; 
  unsigned int v36; 
  unsigned int v37; 
  unsigned __int64 v38; 
  unsigned int v39; 
  unsigned int v40; 
  _DWORD *v41; 
  unsigned int v42; 
  union _LARGE_INTEGER v43; 
  struct _UNICODE_STRING DestinationString; 
  int v45; 
  int v46; 
  v46 = a3;
  v4 = 0i64;
  if( !a1 || !a2 || !a4 )
    return(unsigned int)-1073741811;
  v15 = *(unsigned int **)(a1 + 8);
  if( v15 && *(_DWORD *)a1 > 3u )
  {
    for( i = 0; i < 3; ++i )
    {
      v17 = *v15;
      v18 = v15 + 1;
      if( v15 + 1 < v15 )
        goto LABEL_32;
      v15 = (unsigned int *)((char *)v18 + v17);
      if( (unsigned int *)((char *)v18 + v17) < v18 )
        goto LABEL_32;
    }
    v19 = *v15;
    v20 = v15 + 1;
    if( v15 + 1 < v15 )
    {
LABEL_32:
      v8 = -1073741675;
      goto LABEL_9;
    }
    v7 = 0i64;
    if( v19 )
      v7 = v20;
    v8 = 0;
    if( v19 == 8 )
    {
      v4 = *(_QWORD *)v7;
      goto LABEL_9;
    }
    return(unsigned int)-1073741789;
  }
  v8 = -1073741811;
LABEL_9:
  if( (v8 & 0x80000000) == 0 )
  {
    v46 = 0;
    v45 = 0;
    v43.LowPart = 0;
    DestinationString = 0i64;
    v9 = 1;
    RtlInitUnicodeString(&DestinationString, L"Security-SPP-GenuineLocalStatus", v8);
    v10 = ((__int64(__fastcall *)(struct _UNICODE_STRING *, int *, int *, __int64))qword_140D2C4B8)(
            &DestinationString,
            &v46,
            &v45,
            4i64);
    v8 = v10;
    if( v10 != -1073741772 )
    {
      if( v10 < 0 )
        return v8;
      if( v46 != 4 || !v45 )
        v9 = 0;
      if( v9 )
        KeResetEvent(&stru_140C13CA0, v11, v10, v12, (IRP *)&v43);
    }
    dword_140D2C1D4 = 1;
    do
    {
      v13 = KeWaitForSingleObject(&stru_140C13CA0, UserRequest, 1, 1u, 0i64);
      v14 = v13;
    }
    while( v13 == 257 );
    if( v13 >= 0 && v13 != 192 )
    {
      do
      {
        v21 = KeWaitForSingleObject(&stru_140C13CC0, UserRequest, 1, 1u, 0i64);
        v14 = v21;
      }
      while( v21 == 257 );
      if( v21 >= 0 && v21 != 192 && v21 != 258 )
        KeReleaseMutex(&stru_140C13CC0, 0);
    }
    v22 = *(_DWORD *)(a2 + 32);
    if( *(_DWORD *)(a2 + 16) >= 0xFFFFFFC8 )
      return(unsigned int)-1073741675;
    v23 = *(_DWORD *)(a2 + 16) + 60;
    if( v23 < *(_DWORD *)(a2 + 16) + 56 )
      return(unsigned int)-1073741675;
    v8 = v23 + v22 < v23 ? 0xC0000095 : 0;
    if( v23 + v22 >= v23 )
    {
      *(_DWORD *)(a4 + 4) = 28;
      PoolWithTag = ExAllocatePoolWithTag(PagedPool, 0x1Cui64, 0x20534C53ui64);
      if( !PoolWithTag )
        return(unsigned int)-1073741801;
      *(_QWORD *)(a4 + 8) = PoolWithTag;
      *(_DWORD *)a4 = 0;
      v26 = v14 | 0x10000000;
      if( PoolWithTag + 1 < PoolWithTag )
        return(unsigned int)-1073741675;
      if( PoolWithTag + 2 <= (_DWORD *)((char *)PoolWithTag + *(unsigned int *)(a4 + 4)) )
      {
        *PoolWithTag = 4;
        PoolWithTag[1] = v26;
        v27 = ++*(_DWORD *)a4;
        v28 = *(_QWORD *)(a4 + 8);
        v29 = -1;
        if( !v28 )
        {
          v30 = *(_DWORD *)(a4 + 4);
          v31 = -1;
          v32 = v30 + 12;
          if( v30 + 12 >= v30 )
            v31 = v30 + 12;
          v8 = v32 < v30 ? 0xC0000095 : 0;
          *(_DWORD *)(a4 + 4) = v31;
          if( v32 >= v30 )
          {
            *(_DWORD *)a4 = v27 + 1;
LABEL_55:
            v33 = *(_QWORD *)(a4 + 8);
            v34 = dword_140D2C064;
            if( !v33 )
            {
              v35 = *(_DWORD *)(a4 + 4);
              v36 = v35 + 8;
              if( v35 + 8 >= v35 )
                v29 = v35 + 8;
              v8 = v36 < v35 ? 0xC0000095 : 0;
              *(_DWORD *)(a4 + 4) = v29;
              if( v36 >= v35 )
              {
                ++*(_DWORD *)a4;
                return 0;
              }
              return v8;
            }
            v40 = 0;
            v41 = *(_DWORD **)(a4 + 8);
            if( *(_DWORD *)a4 )
            {
              while( 1 )
              {
                v42 = *v41 + 4;
                if( *v41 >= 0xFFFFFFFC || (_DWORD *)((char *)v41 + v42) < v41 )
                  break;
                ++v40;
                v41 = (_DWORD *)((char *)v41 + v42);
                if( v40 >= *(_DWORD *)a4 )
                  goto LABEL_72;
              }
            }
            else
            {
LABEL_72:
              if( v41 + 1 >= v41 )
              {
                v8 = 0;
                if( (unsigned __int64)(v41 + 2) <= v33 + (unsigned __int64)*(unsigned int *)(a4 + 4) )
                {
                  *v41 = 4;
                  v41[1] = v34;
                  ++*(_DWORD *)a4;
                  return v8;
                }
                return(unsigned int)-1073741789;
              }
            }
            return(unsigned int)-1073741675;
          }
LABEL_22:
          if( (v8 & 0x80000000) != 0 )
            return v8;
          goto LABEL_55;
        }
        v37 = 0;
        v38 = *(_QWORD *)(a4 + 8);
        if( v27 )
        {
          while( 1 )
          {
            v39 = *(_DWORD *)v38 + 4;
            if( *(_DWORD *)v38 >= 0xFFFFFFFC )
              break;
            if( v38 + v39 < v38 )
              return(unsigned int)-1073741675;
            ++v37;
            v38 += v39;
            if( v37 >= v27 )
              goto LABEL_64;
          }
          v8 = -1073741675;
          goto LABEL_22;
        }
LABEL_64:
        if( v38 + 4 < v38 )
          return(unsigned int)-1073741675;
        v8 = 0;
        if( v38 + 12 <= v28 + (unsigned __int64)*(unsigned int *)(a4 + 4) )
        {
          *(_DWORD *)v38 = 8;
          *(_QWORD *)(v38 + 4) = v4;
          ++*(_DWORD *)a4;
          goto LABEL_22;
        }
      }
      return(unsigned int)-1073741789;
    }
  }
  return v8;
}

Referenced by:

sub_1405F50F8