HvStoreModifiedData

INT64 __fastcall HvStoreModifiedData(UINT64 a1, CHAR a2, CHAR a3){
  bool v3; 
  unsigned int *v5; 
  PVOID *v6; 
  unsigned int *v7; 
  PVOID *v8; 
  unsigned int v9; 
  UINT64 v10; 
  UINT8 *PoolWithTag; 
  int v12; 
  unsigned int v13; 
  unsigned int v14; 
  int v15; 
  unsigned int v16; 
  void *v18; 
  __int64 v19; 
  _OWORD *v20; 
  _OWORD *v21; 
  __int128 v22; 
  UINT8 *v23; 
  PVOID *v24; 
  char *v25; 
  UINT8 *v26; 
  int v27; 
  int v28; 
  int v29; 
  unsigned int v30; 
  PVOID v31; 
  PVOID *v32; 
  __int64 v33; 
  PVOID *v34; 
  __int64 v35; 
  INT64 Allocate; 
  unsigned int Size; 
  UINT Size_4; 
  UINT64 Length; 
  unsigned int SizeOfBitMap; 
  int v41; 
  PVOID P; 
  PVOID v43; 
  UINT64 Current; 
  struct _RTL_BITMAP BitMapHeader; 
  UINT8 *Address; 
  RTL_BITMAP Source; 
  unsigned int v48; 
  UINT64 Offset; 
  v3 = (*(_DWORD *)(a1 + 160) & 0x8000) == 0;
  Address = 0i64;
  LODWORD(Length) = 0;
  v5 = 0i64;
  LODWORD(Offset) = 0;
  v6 = 0i64;
  P = 0i64;
  v7 = 0i64;
  Size_4 = 0;
  v8 = 0i64;
  v41 = 0;
  v48 = 0;
  v43 = 0i64;
  Source = 0i64;
  BitMapHeader = 0i64;
  if( !v3 )
    return 1;
  *(_DWORD *)(a1 + 1720) = (unsigned __int8)HvpTruncateBins(a1);
  if( (*(_DWORD *)(a1 + 160) & 1) != 0 )
    return 1;
  v9 = *(_DWORD *)(a1 + 108);
  v10 = v9;
  Size = v9;
  if( *(_DWORD *)(a1 + 104) )
  {
    PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, v9, 0x30354D43ui64);
    v5 = (unsigned int *)PoolWithTag;
    if( !PoolWithTag )
      return 2;
    memmove(PoolWithTag, *(UINT8 **)(a1 + 96), (unsigned int)v10);
    SizeOfBitMap = *(_DWORD *)(a1 + 88);
    Source.SizeOfBitMap = SizeOfBitMap;
    Source.Buffer = v5;
    v12 = HvpGenerateLogEntry((_HHIVE *)a1, (UINT8 **)&P, &Size_4);
    v6 = (PVOID *)P;
    if( v12 < 0 )
      goto LABEL_48;
  }
  else
  {
    SizeOfBitMap = Source.SizeOfBitMap;
  }
  if( !a3 && !a2 )
    goto LABEL_8;
  v18 = ExAllocatePoolWithTag(PagedPool, 0x1000ui64, 0x30354D43ui64);
  v43 = v18;
  if( v18 )
  {
    memset((INT64)v18, 0i64);
    v19 = 4i64;
    *(_DWORD *)(*(_QWORD *)(a1 + 64) + 40i64) = *(_DWORD *)(a1 + 272);
    v20 = *(_OWORD **)(a1 + 64);
    v21 = v43;
    do
    {
      *v21 = *v20;
      v21[1] = v20[1];
      v21[2] = v20[2];
      v21[3] = v20[3];
      v21[4] = v20[4];
      v21[5] = v20[5];
      v21[6] = v20[6];
      v21 += 8;
      v22 = v20[7];
      v20 += 8;
      *(v21 - 1) = v22;
      --v19;
    }
    while( v19 );
    if( !a3 )
    {
LABEL_8:
      v13 = BitMapHeader.SizeOfBitMap;
LABEL_9:
      v14 = *(_DWORD *)(a1 + 272);
      if( *(_DWORD *)(a1 + 1784) < v14 || *(_DWORD *)(a1 + 1720) )
        *(_DWORD *)(a1 + 1784) = v14;
      if( *(_DWORD *)(a1 + 104) )
      {
        *(_DWORD *)(a1 + 1680) = SizeOfBitMap;
        *(_QWORD *)(a1 + 1688) = v5;
        v5 = 0i64;
        *(_DWORD *)(a1 + 1696) = Size;
        *(_DWORD *)(a1 + 1712) = Size_4;
        v15 = v41;
        *(_QWORD *)(a1 + 1704) = v6;
        v6 = 0i64;
        *(_DWORD *)(a1 + 1716) = v15;
        HvResetDirtyData((_HHIVE *)a1);
      }
      if( a2 || a3 )
      {
        v31 = v43;
        v43 = 0i64;
        v3 = *(_BYTE *)(a1 + 191) == 0;
        *(_QWORD *)(a1 + 1768) = v31;
        if( !v3 )
          *(_BYTE *)(a1 + 1724) = 1;
        if( a3 )
        {
          *(_QWORD *)(a1 + 1736) = v7;
          v7 = 0i64;
          *(_DWORD *)(a1 + 1728) = v13;
          *(_QWORD *)(a1 + 1752) = v8;
          v8 = 0i64;
          *(_DWORD *)(a1 + 1744) = Size;
          *(_DWORD *)(a1 + 1760) = v48;
          if( *(_QWORD *)(a1 + 120) )
          {
            RtlClearAllBits((RTL_BITMAP *)(a1 + 112));
            *(_DWORD *)(a1 + 128) = 0;
            *(_BYTE *)(a1 + 191) = 0;
          }
        }
      }
      v16 = 0;
      goto LABEL_16;
    }
    v23 = (UINT8 *)ExAllocatePoolWithTag(PagedPool, v10, 0x30354D43ui64);
    v7 = (unsigned int *)v23;
    if( v23 )
    {
      memmove(v23, *(UINT8 **)(a1 + 120), v10);
      LODWORD(P) = *(_DWORD *)(a1 + 112);
      BitMapHeader.SizeOfBitMap = (unsigned int)P;
      BitMapHeader.Buffer = v7;
      if( *(_DWORD *)(a1 + 104) )
        RtlMergeBitMaps(&BitMapHeader, &Source);
      v48 = HvpCountSetRangesInVector(&BitMapHeader);
      v24 = (PVOID *)ExAllocatePoolWithTag(PagedPool, 24i64 * v48, 0x32354D43ui64);
      v8 = v24;
      if( v24 )
      {
        memset((INT64)v24, 0i64);
        HIDWORD(Length) = 0;
        LODWORD(Current) = 0;
        if( v48 )
        {
          v25 = (char *)(v8 + 1);
          do
          {
            LOBYTE(Allocate) = 1;
            if( !(unsigned __int8)HvpFindNextDirtyBlock(
                                     (_HHIVE *)a1,
                                     &BitMapHeader,
                                     &Current,
                                     &Address,
                                     &Length,
                                     &Offset,
                                     Allocate) )
              break;
            v26 = Address;
            if( !Address )
              goto LABEL_48;
            v27 = Offset;
            v28 = Length;
            *((_DWORD *)v25 + 2) = Length;
            *((_DWORD *)v25 - 2) = v27;
            v29 = v28 + v27;
            v30 = HIDWORD(Length) + 1;
            *(_QWORD *)v25 = v26;
            v25 += 24;
            LODWORD(Offset) = v29;
            HIDWORD(Length) = v30;
          }
          while( v30 < v48 );
        }
        memmove((UINT8 *)v7, *(UINT8 **)(a1 + 120), Size);
        v13 = (unsigned int)P;
        goto LABEL_9;
      }
    }
  }
LABEL_48:
  v16 = 2;
LABEL_16:
  if( v5 )
    ExFreePoolWithTag(v5, 0);
  if( v6 )
  {
    if( Size_4 )
    {
      v32 = v6 + 1;
      v33 = Size_4;
      do
      {
        if( *v32 )
        {
          ExFreePoolWithTag(*v32, 0);
          *v32 = 0i64;
        }
        v32 += 3;
        --v33;
      }
      while( v33 );
    }
    ExFreePoolWithTag(v6, 0);
  }
  if( v7 )
    ExFreePoolWithTag(v7, 0);
  if( v8 )
  {
    if( v48 )
    {
      v34 = v8 + 1;
      v35 = v48;
      do
      {
        if( *v34 )
          ExFreePoolWithTag(*v34, 0);
        v34 += 3;
        --v35;
      }
      while( v35 );
    }
    ExFreePoolWithTag(v8, 0);
  }
  if( v43 )
    ExFreePoolWithTag(v43, 0);
  return v16;
}

Referenced by:

CmpFlushHive