WbDispatchOperation
NTSTATUS __stdcall WbDispatchOperation(VOID *Src, _SIZE_T NumberOfBytes){
_LARGE_INTEGER v2;
VOID *v3;
char *v6;
int WarbirdProcess;
int *v8;
int v9;
_BOOL8 v10;
VOID *ProcessId;
int v12;
int v14;
INT64 v15;
PVOID P;
v15 = 0i64;
P = 0i64;
if( Src )
{
if( (unsigned int)NumberOfBytes < 8 )
{
WarbirdProcess = -1073741811;
goto LABEL_18;
}
v6 = (char *)Src + (unsigned int)NumberOfBytes;
if( (unsigned __int64)v6 > 0x7FFFFFFF0000i64 || v6 < Src )
MEMORY[0x7FFFFFFF0000] = 0;
WarbirdProcess = WbAlloc(NumberOfBytes);
if( WarbirdProcess < 0 )
goto LABEL_18;
v8 = (int *)P;
memmove(P, Src, NumberOfBytes);
v9 = *v8;
v14 = *v8;
}
else
{
v9 = 4;
v14 = 4;
}
v10 = v9 != 7;
ProcessId = PsGetProcessId(KeGetCurrentThread()->ApcState.Process);
WarbirdProcess = WbGetWarbirdProcess((INT64)ProcessId, v10, (INT64 **)&v15);
if( WarbirdProcess < 0 )
goto LABEL_18;
switch( v14 )
{
case 1:
v12 = WbDecryptEncryptionSegment(v15, (wil_details_FeatureReportingCache *)P, (unsigned int)NumberOfBytes);
goto LABEL_17;
case 2:
v12 = WbReEncryptEncryptionSegment(v15, (wil_details_FeatureReportingCache *)P, (unsigned int)NumberOfBytes);
goto LABEL_17;
case 3:
v12 = WbHeapExecuteCall((_EX_PUSH_LOCK *)v15, P, (char *)Src, NumberOfBytes);
goto LABEL_17;
case 4:
if( !P )
{
v12 = sub_14065EC80((_EX_PUSH_LOCK *)v15, *(INT64 *)&NumberOfBytes);
LABEL_17:
WarbirdProcess = v12;
goto LABEL_18;
}
break;
case 5:
case 6:
WarbirdProcess = Src != 0i64 ? -1073741822 : -1073741811;
goto LABEL_18;
case 7:
v12 = WbRemoveWarbirdProcess(*(_QWORD *)v15);
goto LABEL_17;
case 8:
v12 = WbProcessStartup(v15, P, NumberOfBytes);
goto LABEL_17;
case 9:
v12 = WbProcessModuleUnload(v15, P, NumberOfBytes);
goto LABEL_17;
}
WarbirdProcess = -1073741811;
LABEL_18:
sub_14065E8E4(v15, *(UINT64 *)&NumberOfBytes, v2, v3);
if( P )
ExFreePoolWithTag(P, 0x42524157u);
return WarbirdProcess;
}Referenced by:
ExpQuerySystemInformation