CcRegistryChangeCallback
NTSTATUS __stdcall CcRegistryChangeCallback(PVOID P){
char *v1;
char *v2;
volatile unsigned __int64 TickCountQuad;
unsigned __int64 v4;
NTSTATUS result;
void *v6;
NTSTATUS v7;
BOOL WatchTree;
BOOL Asynchronous;
struct _IO_STATUS_BLOCK IoStatusBlock;
v1 = (char *)P + 56;
IoStatusBlock = 0i64;
v2 = (char *)P;
TickCountQuad = KUSER_SHARED_DATA.TickCountQuad;
v4 = KUSER_SHARED_DATA.TickCountQuad - *((_QWORD *)P + 6);
result = DbgPrintEx(
0x7Fu,
2u,
"CcRegistryChangeCallback: Something of interest changed(callback:%c), under:\"%wZ\"\n",
*((_BYTE *)P + 72) != 0 ? 70 : 84,
(char *)P + 56);
if( !v2[72] )
{
(*((void(__fastcall **)(char *))v2 + 5))(v2);
*((_QWORD *)v2 + 6) = TickCountQuad;
result = DbgPrintEx(0x7Fu, 2u, "CcRegistryChangeCallback: Processed \"%wZ\", TickDiff=%I64d\n", v1, v4);
}
v2[72] = 0;
if( !*((_QWORD *)v2 + 4) )
{
result = CcOpenRegistryPath((__int64)v1, (HANDLE *)v2 + 4);
if( result < 0 )
{
DbgPrintEx(
0x7Fu,
0,
"CcRegistryChangeCallback: Failed to open Key, status=0x%08x \"%wZ\n",
(unsigned int)result,
v1);
ExFreePoolWithTag(v2, 0x52576343u);
v2 = 0i64;
}
}
if( v2 )
{
v6 = (void *)*((_QWORD *)v2 + 4);
if( v6 )
{
LOBYTE(Asynchronous) = 1;
LOBYTE(WatchTree) = 1;
v7 = ZwNotifyChangeKey(
v6,
0i64,
(PIO_APC_ROUTINE)v2,
(PVOID)1,
&IoStatusBlock,
5u,
WatchTree,
0i64,
0,
Asynchronous);
if( v7 == 259 )
{
result = DbgPrintEx(0x7Fu, 2u, "CcRegistryChangeCallback: Watch queued \"%wZ\"\n", v2 + 56);
}
else if( v7 >= 0 )
{
result = DbgPrintEx(
0x7Fu,
2u,
"CcRegistryChangeCallback: Watch queued \"%wZ\" (for Immediate Processing)\n",
v2 + 56);
}
else
{
ZwClose(*((HANDLE *)v2 + 4));
*((_QWORD *)v2 + 4) = 0i64;
v2[72] = 1;
result = DbgPrintEx(
0x7Fu,
0,
"CcRegistryChangeCallback: Failed Watch request, status=0x%08x \"%wZ\"\n",
(unsigned int)v7,
v2 + 56);
}
}
}
if( !CcRegistryWatchInitComplete && v2 && !v2[72] )
CcRegistryWatchInitComplete = 1;
return result;
}Referenced by:
No references.