CmpInitHiveFromFile
INT64 __fastcall CmpInitHiveFromFile(
_UNICODE_STRING *FileName,
UINT64 HiveFlags,
_CMHIVE **CmHive,
UINT8 *Allocate,
UINT64 CheckFlags,
_GUID *HiveRmUuid,
_GUID *HiveTmUuid,
UINT8 *NeedRmLogStart,
_HIVE_LOAD_FAILURE *HiveLoadFailure){
_CMHIVE **v9;
int v10;
__int64 a6;
VOID *v13;
unsigned int v14;
UINT64 v15;
PVOID v16;
int v17;
NTSTATUS v18;
int v19;
VOID *v20;
int v22;
_ETHREAD *CurrentThread;
_HIVE_LOAD_FAILURE *a12;
char v25;
VOID **PoolWithTag;
_UNICODE_STRING *v27;
_HHIVE *v28;
NTSTATUS v29;
INT64 v30;
UINT64 Point;
UINT64 Pointa;
UINT64 Flags;
char v34;
char v35;
UINT8 v36;
int v37;
UINT64 a4;
_HHIVE *Hive;
VOID *Handle;
_HIVE_LOAD_FAILURE *HiveLoadFailurea;
UINT64 v42;
__int64 v43;
VOID *FileHandle;
PVOID SecurityDescriptor;
int v46;
int v47;
_CMHIVE **v48;
int v49;
int v50;
UINT64 a3;
__int64 a7;
UINT8 *v53;
INT64 a11;
INT64 v55[2];
__int128 v56;
_IO_STATUS_BLOCK IoStatusBlock;
__int128 FileInformation;
__int128 v59;
__int64 v60;
_KAPC_STATE ApcState;
_EVENT_DATA_DESCRIPTOR v62;
int *v63;
__int64 v64;
wchar_t *Buffer;
int v66[2];
_EVENT_DATA_DESCRIPTOR v67;
int *v68;
int v69;
int v70;
_HIVE_LOAD_FAILURE *v71;
a11 = (INT64)HiveLoadFailure;
v9 = CmHive;
HiveLoadFailurea = v71;
v48 = CmHive;
v10 = HiveFlags;
a6 = (__int64)HiveRmUuid;
v53 = Allocate;
LODWORD(a3) = HiveFlags;
v43 = (__int64)HiveRmUuid;
*(_OWORD *)v55 = 0i64;
v47 = 0;
v56 = 0i64;
v50 = 0;
Hive = 0i64;
v46 = 0;
FileInformation = 0i64;
v60 = 0i64;
v59 = 0i64;
IoStatusBlock = 0i64;
memset(&ApcState, 0, sizeof(ApcState));
if( *(&stru_140C00F40 + 1148) > 4u )
{
if( tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 8i64) )
{
v64 = 2i64;
v63 = v66;
Buffer = FileName->Buffer;
v66[0] = FileName->Length;
v66[1] = 0;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&stru_140C00F40 + 4592,
(unsigned __int8 *)byte_140021A6D,
0i64,
0i64,
4u,
&v62);
Allocate = v53;
v9 = v48;
}
a6 = v43;
}
v35 = 0;
v13 = 0i64;
v14 = ((unsigned int)CheckFlags >> 19) & 0x40;
v36 = 0;
FileHandle = 0i64;
v49 = v10 & 0x8000;
v15 = 0i64;
Handle = 0i64;
v16 = 0i64;
v42 = 0i64;
v34 = 1;
SecurityDescriptor = 0i64;
if( (v10 & 0x8000) != 0 )
{
v34 = 0;
v17 = v14 | ((v10 & 0x40000 | 0x10000u) >> 11);
}
else
{
v17 = v14 | 2;
if( (CheckFlags & 0x40000000) == 0 )
v17 = ((unsigned int)CheckFlags >> 19) & 0x40;
if( *Allocate )
v17 |= 1u;
}
while( 1 )
{
*v9 = 0i64;
a7 = 0i64;
v18 = CmpOpenHiveFile(FileName, 0, &FileHandle, &v46, v17, a6, (__int64)&a7, 0i64, 0i64);
v19 = v18;
if( v18 < 0 )
{
LODWORD(Point) = 16;
SetFailureLocation(HiveLoadFailurea, 0i64, _CmpInitHiveFromFile, (unsigned int)v18, Point);
v20 = FileHandle;
goto LABEL_9;
}
v37 = v17;
if( v46 == 2 )
{
v35 = 1;
v37 = v17 | 0x10;
}
v20 = FileHandle;
if( !v49 )
{
v19 = CmpQueryFileSecurityDescriptor(FileHandle, &SecurityDescriptor);
if( v19 < 0 )
{
LODWORD(Point) = 32;
SetFailureLocation(HiveLoadFailurea, 0i64, _CmpInitHiveFromFile, (unsigned int)v19, Point);
v16 = SecurityDescriptor;
goto LABEL_9;
}
v16 = SecurityDescriptor;
}
if( (CheckFlags & 0x10000000) != 0 )
{
LODWORD(a4) = 1;
v22 = CmpOpenHiveFile(FileName, 1u, &Handle, &v47, v37, v43, 0i64, (__int64)v16, 0i64);
v19 = v22;
if( v22 < 0 )
{
v13 = 0i64;
Handle = 0i64;
if( v34 )
{
LODWORD(Pointa) = 48;
goto LABEL_78;
}
}
else
{
v13 = Handle;
}
}
else
{
LODWORD(a4) = 2;
v19 = CmpOpenHiveFile(FileName, 4u, &Handle, &v47, v37, v43, 0i64, (__int64)v16, 0i64);
if( v19 < 0 )
{
v13 = 0i64;
Handle = 0i64;
if( v34 )
{
LODWORD(Pointa) = 64;
v30 = (unsigned int)v19;
LABEL_79:
SetFailureLocation(HiveLoadFailurea, 0i64, _CmpInitHiveFromFile, v30, Pointa);
goto LABEL_9;
}
}
else
{
v13 = Handle;
}
v22 = CmpOpenHiveFile(FileName, 5u, (VOID **)&v42, &v50, v37, v43, 0i64, (__int64)v16, 0i64);
v19 = v22;
if( v22 >= 0 )
{
v15 = v42;
goto LABEL_31;
}
v15 = 0i64;
v42 = 0i64;
if( v34 )
{
LODWORD(Pointa) = 80;
LABEL_78:
v30 = (unsigned int)v22;
goto LABEL_79;
}
}
LABEL_31:
if( !v34 )
{
if( (_DWORD)a4 != 2 )
{
LODWORD(a4) = v13 != 0i64;
goto LABEL_35;
}
if( v13 )
{
if( v15 )
goto LABEL_35;
ZwClose((_HANDLE)v13);
v13 = 0i64;
Handle = 0i64;
}
if( v15 )
{
ZwClose(v15);
v15 = 0i64;
v42 = 0i64;
}
LODWORD(a4) = 0;
}
LABEL_35:
if( !v36 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--CurrentThread->Tcb.KernelApcDisable;
v36 = ExAcquireRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
if( !v36 )
KeLeaveCriticalRegionThread(KeGetCurrentThread());
v13 = Handle;
v15 = v42;
v20 = FileHandle;
v16 = SecurityDescriptor;
if( !v36 )
{
v19 = -1073741431;
goto LABEL_9;
}
}
a12 = HiveLoadFailurea;
v55[0] = (INT64)v20;
v55[1] = (INT64)v13;
v56 = v15;
memset(HiveLoadFailurea, 0i64, 0x1B0u);
LODWORD(Flags) = CheckFlags;
v22 = CmpCreateHive(
(INT64)&Hive,
v35 == 0 ? 5 : 0,
(unsigned int)a3,
(unsigned int)a4,
0i64,
(INT64)v55,
(INT64)FileName,
Flags,
0i64,
0i64,
a11,
(INT64)a12);
v19 = v22;
if( v22 != -1073741267 )
break;
ZwClose((_HANDLE)v20);
FileHandle = 0i64;
if( v13 )
{
ZwClose((_HANDLE)v13);
v13 = 0i64;
Handle = 0i64;
}
a6 = v43;
v9 = v48;
if( v15 )
{
ZwClose(v15);
a6 = v43;
v15 = 0i64;
v9 = v48;
v42 = 0i64;
}
}
if( v22 < 0 )
{
LODWORD(Pointa) = 96;
goto LABEL_78;
}
v25 = v35;
if( !v35 && (Hive[2].Storage[1].FreeDisplay[6].RealVectorSize & 0x800) != 0 )
{
CmpAttachToRegistryProcess(&ApcState);
v29 = CmpFlushHive((CMHIVE *)Hive, 0xCui64);
KiUnstackDetachProcess(&ApcState, 0i64);
if( v29 < 0 )
{
LODWORD(Pointa) = 230;
SetFailureLocation(HiveLoadFailurea, 1ui64, _CmpCreateHive, (unsigned int)v29, Pointa);
}
v25 = 0;
}
PoolWithTag = ExAllocatePoolWithTag(1ui64, FileName->Length, 1649298755i64);
*(_QWORD *)&Hive[1].Storage[0].FreeDisplay[0].RealVectorSize = PoolWithTag;
v28 = Hive;
if( *(_QWORD *)&Hive[1].Storage[0].FreeDisplay[0].RealVectorSize )
{
LOWORD(Hive[1].Storage[0].Guard) = FileName->Length;
HIWORD(Hive[1].Storage[0].Guard) = FileName->Length;
memmove(*(VOID **)&Hive[1].Storage[0].FreeDisplay[0].RealVectorSize, FileName->Buffer, FileName->Length);
v28 = Hive;
}
if( (v28->BaseBlock->BootType & 4) != 0 )
CmpLogEvent((_EVENT_DESCRIPTOR *)®_EVENT_SELFHEAL, 2147483690i64, FileName, v27);
if( ZwQueryInformationFile(v20, &IoStatusBlock, &FileInformation, 0x28ui64, FileBasicInformation) >= 0 )
*(_QWORD *)&Hive[2].Storage[1].FreeDisplay[9].RealVectorSize = v59;
Hive->LogFileSizeCap = HIDWORD(a7);
*v48 = (_CMHIVE *)Hive;
*v53 = v25;
v19 = 0;
LABEL_9:
if( v36 )
{
ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
KeLeaveCriticalRegionThread(KeGetCurrentThread());
v13 = Handle;
v15 = v42;
v20 = FileHandle;
v16 = SecurityDescriptor;
}
if( v20 )
ZwClose((_HANDLE)v20);
if( v13 )
ZwClose((_HANDLE)v13);
if( v15 )
ZwClose(v15);
if( v16 )
ExFreePoolWithTag(v16, 0);
if( *(&stru_140C00F40 + 1148) > 4u && tlgKeywordOn((__int64)&stru_140C00F40 + 4592, 8i64) )
{
v70 = 0;
v68 = &v37;
v37 = v19;
v69 = 4;
tlgWriteTransfer_EtwWriteTransfer(
(__int64)&stru_140C00F40 + 4592,
(unsigned __int8 *)byte_140021A43,
0i64,
0i64,
3u,
&v67);
}
return(unsigned int)v19;
}Referenced by:
CmpCmdHiveOpen
CmpLoadHiveThread