CcRegistryChangeCallback

NTSTATUS __stdcall CcRegistryChangeCallback(PVOID P){
  char *v1; 
  char *v2; 
  volatile unsigned __int64 TickCountQuad; 
  unsigned __int64 v4; 
  NTSTATUS result; 
  void *v6; 
  NTSTATUS v7; 
  BOOL WatchTree; 
  BOOL Asynchronous; 
  struct _IO_STATUS_BLOCK IoStatusBlock; 
  v1 = (char *)P + 56;
  IoStatusBlock = 0i64;
  v2 = (char *)P;
  TickCountQuad = KUSER_SHARED_DATA.TickCountQuad;
  v4 = KUSER_SHARED_DATA.TickCountQuad - *((_QWORD *)P + 6);
  result = DbgPrintEx(
             0x7Fu,
             2u,
             "CcRegistryChangeCallback: Something of interest changed(callback:%c), under:\"%wZ\"\n",
             *((_BYTE *)P + 72) != 0 ? 70 : 84,
             (char *)P + 56);
  if( !v2[72] )
  {
    (*((void(__fastcall **)(char *))v2 + 5))(v2);
    *((_QWORD *)v2 + 6) = TickCountQuad;
    result = DbgPrintEx(0x7Fu, 2u, "CcRegistryChangeCallback: Processed \"%wZ\", TickDiff=%I64d\n", v1, v4);
  }
  v2[72] = 0;
  if( !*((_QWORD *)v2 + 4) )
  {
    result = CcOpenRegistryPath((__int64)v1, (HANDLE *)v2 + 4);
    if( result < 0 )
    {
      DbgPrintEx(
        0x7Fu,
        0,
        "CcRegistryChangeCallback: Failed to open Key, status=0x%08x \"%wZ\n",
        (unsigned int)result,
        v1);
      ExFreePoolWithTag(v2, 0x52576343u);
      v2 = 0i64;
    }
  }
  if( v2 )
  {
    v6 = (void *)*((_QWORD *)v2 + 4);
    if( v6 )
    {
      LOBYTE(Asynchronous) = 1;
      LOBYTE(WatchTree) = 1;
      v7 = ZwNotifyChangeKey(
             v6,
             0i64,
             (PIO_APC_ROUTINE)v2,
             (PVOID)1,
             &IoStatusBlock,
             5u,
             WatchTree,
             0i64,
             0,
             Asynchronous);
      if( v7 == 259 )
      {
        result = DbgPrintEx(0x7Fu, 2u, "CcRegistryChangeCallback: Watch queued \"%wZ\"\n", v2 + 56);
      }
      else if( v7 >= 0 )
      {
        result = DbgPrintEx(
                   0x7Fu,
                   2u,
                   "CcRegistryChangeCallback: Watch queued \"%wZ\" (for Immediate Processing)\n",
                   v2 + 56);
      }
      else
      {
        ZwClose(*((HANDLE *)v2 + 4));
        *((_QWORD *)v2 + 4) = 0i64;
        v2[72] = 1;
        result = DbgPrintEx(
                   0x7Fu,
                   0,
                   "CcRegistryChangeCallback: Failed Watch request, status=0x%08x \"%wZ\"\n",
                   (unsigned int)v7,
                   v2 + 56);
      }
    }
  }
  if( !CcRegistryWatchInitComplete && v2 && !v2[72] )
    CcRegistryWatchInitComplete = 1;
  return result;
}

Referenced by:

No references.