NtEnumerateKey

NTSTATUS __stdcall NtEnumerateKey(
        VOID *KeyHandle,
        UINT64 Index,
        KEY_INFORMATION_CLASS KeyInformationClass,
        VOID *KeyInformation,
        UINT64 Length,
        UINT64 *ResultLength){
  unsigned int v8; 
  _ETHREAD *CurrentThread; 
  bool v11; 
  unsigned int v12; 
  NTSTATUS v13; 
  struct _DMA_ADAPTER *v14; 
  unsigned int v15; 
  __int64 v16; 
  _ETHREAD *v17; 
  int v18; 
  unsigned int v19; 
  _DMA_OPERATIONS *v20; 
  __int64 v21; 
  KPROCESSOR_MODE v23; 
  char v24; 
  char v25; 
  bool v26; 
  int v27; 
  PADAPTER_OBJECT DmaAdapter; 
  _DMA_OPERATIONS *DmaOperations; 
  unsigned int v30; 
  int v31; 
  _DMA_OPERATIONS *v32; 
  PADAPTER_OBJECT v33; 
  INT64 v34[2]; 
  PVOID v35; 
  PVOID Object; 
  PVOID v37; 
  SLIST_ENTRY *Argument; 
  NTSTATUS v39; 
  int v40; 
  INT64 *v41; 
  NTSTATUS v42; 
  __int128 v43; 
  __int64 v44; 
  int v45; 
  INT64 v46; 
  int v47; 
  KEY_INFORMATION_CLASS v48; 
  VOID *v49; 
  unsigned int v50; 
  UINT64 *v51; 
  __int64 v52; 
  LARGE_INTEGER v53[2]; 
  __int128 v54; 
  void *Src[2]; 
  char v56; 
  INT64 result[9]; 
  v8 = Index;
  v27 = Index;
  v31 = Index;
  memset((INT64)result, 0i64);
  *(_OWORD *)&v53[0].LowPart = 0i64;
  v54 = 0i64;
  DmaOperations = 0i64;
  v32 = 0i64;
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
    EtwGetKernelTraceTimestamp(v53, 0x20000ui64);
  v24 = 0;
  v25 = 0;
  memset((INT64)&v46, 0i64);
  DmaAdapter = 0i64;
  v30 = 0;
  *(_OWORD *)Src = 0i64;
  v56 = 0;
  v34[1] = (INT64)v34;
  v34[0] = (INT64)v34;
  v33 = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)CurrentThread + 242);
  v11 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
  v26 = v11;
  if( !v11 )
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  if( !v11 )
  {
    v13 = -1073741431;
    v20 = 0i64;
    goto LABEL_31;
  }
  if( (unsigned int)KeyInformationClass > KeyFullInformation )
  {
    if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7)
      && KeyHandle
      && (v23 = *((_BYTE *)KeGetCurrentThread() + 562),
          v35 = 0i64,
          ObReferenceObjectByHandle(KeyHandle, 0, (POBJECT_TYPE)CmKeyObjectType, v23, &v35, 0i64) >= 0) )
    {
      v20 = (_DMA_OPERATIONS *)*((_QWORD *)v35 + 1);
      HalPutDmaAdapter((PADAPTER_OBJECT)v35);
    }
    else
    {
      v20 = 0i64;
    }
    v13 = -1073741811;
    goto LABEL_31;
  }
  v12 = *((char *)KeGetCurrentThread() + 562);
  v52 = 0i64;
  Object = 0i64;
  v13 = ObReferenceObjectByHandle(KeyHandle, 8u, (POBJECT_TYPE)CmKeyObjectType, v12, &Object, 0i64);
  v14 = (struct _DMA_ADAPTER *)Object;
  v37 = Object;
  if( v13 >= 0 )
  {
    if( *(_DWORD *)Object == 1803104306 )
    {
      DmaAdapter = (PADAPTER_OBJECT)Object;
      v14 = 0i64;
      v37 = 0i64;
      v13 = 0;
    }
    else
    {
      v13 = -1073741816;
    }
  }
  if( v14 )
    HalPutDmaAdapter(v14);
  if( v13 < 0 )
  {
    v8 = v27;
    v20 = 0i64;
    goto LABEL_31;
  }
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) && DmaAdapter )
  {
    DmaOperations = DmaAdapter->DmaOperations;
    v32 = DmaOperations;
  }
  if( (_BYTE)v12 == 1 )
  {
    v15 = Length;
    ProbeForWrite(KeyInformation, (unsigned int)Length, 4ui64);
    v16 = (__int64)ResultLength;
    if( (unsigned __int64)ResultLength >= 0x7FFFFFFF0000i64 )
      v16 = 0x7FFFFFFF0000i64;
    *(_DWORD *)v16 = *(_DWORD *)v16;
  }
  else
  {
    v15 = Length;
  }
  v17 = (_ETHREAD *)KeGetCurrentThread();
  --*((_WORD *)v17 + 242);
  v25 = 1;
  if( CmpCallBackCount && !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock) )
  {
    v46 = (INT64)DmaAdapter;
    v47 = v27;
    v48 = KeyInformationClass;
    v49 = KeyInformation;
    v50 = v15;
    v51 = ResultLength;
    v18 = CmpCallCallBacksEx(
            RegNtEnumerateKey,
            (SLIST_ENTRY **)&v46,
            0i64,
            1,
            RegNtPostEnumerateKey,
            (INT64)DmaAdapter,
            (INT64)v34);
    v13 = v18;
    if( v18 < 0 )
    {
      v8 = v27;
      v20 = DmaOperations;
      if( v18 == -1073740541 )
        v13 = 0;
      goto LABEL_31;
    }
    v24 = 1;
  }
  v13 = CmKeyBodyRemapToVirtualForEnum((__int64 *)&DmaAdapter, v12, 8u, (__int64 *)&v33);
  if( v13 < 0 || (v13 = CmpBounceContextStart((INT64)Src, (struct SLIST_ENTRY *)KeyInformation, v15, v12, 0), v13 < 0) )
  {
    v8 = v27;
LABEL_49:
    v20 = DmaOperations;
    goto LABEL_31;
  }
  v8 = v27;
  v13 = CmEnumerateKey(&DmaAdapter->Version);
  if( v13 < 0 && v13 != -2147483643 && v13 != -1073741789 )
    goto LABEL_49;
  v19 = v30;
  *(_DWORD *)ResultLength = v30;
  if( v13 != -1073741789 )
  {
    if( v15 >= v19 )
      v15 = v19;
    if( Src[0] != Src[1] )
      memmove((UINT8 *)Src[0], (UINT8 *)Src[1], v15);
  }
  v20 = DmaOperations;
LABEL_31:
  if( v33 )
    HalPutDmaAdapter(v33);
  if( v24
    && CmpCallBackCount
    && !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock)
    && (INT64 *)v34[0] != v34 )
  {
    v40 = 0;
    v43 = 0i64;
    v44 = 0i64;
    v45 = 0;
    Argument = (SLIST_ENTRY *)DmaAdapter;
    v39 = v13;
    v42 = v13;
    v41 = &v46;
    CmpCallCallBacksEx(RegNtPostEnumerateKey, &Argument, 0i64, 0, RegNtPostEnumerateKey, (INT64)DmaAdapter, (INT64)v34);
    v13 = v42;
  }
  if( v25 )
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  if( DmaAdapter )
    HalPutDmaAdapter(DmaAdapter);
  CmpBounceContextCleanup((INT64)Src);
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
  {
    LOBYTE(v21) = 17;
    (*(void(__fastcall **)(__int64, LARGE_INTEGER *, _QWORD, _QWORD, _DMA_OPERATIONS *, _QWORD))((char *)&NlsMbCodePageTag
                                                                                                + 7))(
      v21,
      v53,
      (unsigned int)v13,
      v8,
      v20,
      0i64);
  }
  if( v26 )
  {
    ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
  }
  return v13;
}

Referenced by:

AdtpObjsInitialize
ExpWatchLicenseInfoWork
ExpWatchProductTypeInitialization