NtEnumerateKey
NTSTATUS __stdcall NtEnumerateKey(
VOID *KeyHandle,
UINT64 Index,
KEY_INFORMATION_CLASS KeyInformationClass,
VOID *KeyInformation,
UINT64 Length,
UINT64 *ResultLength){
unsigned int v8;
_ETHREAD *CurrentThread;
bool v11;
unsigned int v12;
NTSTATUS v13;
struct _DMA_ADAPTER *v14;
unsigned int v15;
__int64 v16;
_ETHREAD *v17;
int v18;
unsigned int v19;
_DMA_OPERATIONS *v20;
__int64 v21;
KPROCESSOR_MODE v23;
char v24;
char v25;
bool v26;
int v27;
PADAPTER_OBJECT DmaAdapter;
_DMA_OPERATIONS *DmaOperations;
unsigned int v30;
int v31;
_DMA_OPERATIONS *v32;
PADAPTER_OBJECT v33;
INT64 v34[2];
PVOID v35;
PVOID Object;
PVOID v37;
SLIST_ENTRY *Argument;
NTSTATUS v39;
int v40;
INT64 *v41;
NTSTATUS v42;
__int128 v43;
__int64 v44;
int v45;
INT64 v46;
int v47;
KEY_INFORMATION_CLASS v48;
VOID *v49;
unsigned int v50;
UINT64 *v51;
__int64 v52;
LARGE_INTEGER v53[2];
__int128 v54;
void *Src[2];
char v56;
INT64 result[9];
v8 = Index;
v27 = Index;
v31 = Index;
memset((INT64)result, 0i64);
*(_OWORD *)&v53[0].LowPart = 0i64;
v54 = 0i64;
DmaOperations = 0i64;
v32 = 0i64;
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
EtwGetKernelTraceTimestamp(v53, 0x20000ui64);
v24 = 0;
v25 = 0;
memset((INT64)&v46, 0i64);
DmaAdapter = 0i64;
v30 = 0;
*(_OWORD *)Src = 0i64;
v56 = 0;
v34[1] = (INT64)v34;
v34[0] = (INT64)v34;
v33 = 0i64;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
v11 = ExAcquireRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
v26 = v11;
if( !v11 )
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
if( !v11 )
{
v13 = -1073741431;
v20 = 0i64;
goto LABEL_31;
}
if( (unsigned int)KeyInformationClass > KeyFullInformation )
{
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7)
&& KeyHandle
&& (v23 = *((_BYTE *)KeGetCurrentThread() + 562),
v35 = 0i64,
ObReferenceObjectByHandle(KeyHandle, 0, (POBJECT_TYPE)CmKeyObjectType, v23, &v35, 0i64) >= 0) )
{
v20 = (_DMA_OPERATIONS *)*((_QWORD *)v35 + 1);
HalPutDmaAdapter((PADAPTER_OBJECT)v35);
}
else
{
v20 = 0i64;
}
v13 = -1073741811;
goto LABEL_31;
}
v12 = *((char *)KeGetCurrentThread() + 562);
v52 = 0i64;
Object = 0i64;
v13 = ObReferenceObjectByHandle(KeyHandle, 8u, (POBJECT_TYPE)CmKeyObjectType, v12, &Object, 0i64);
v14 = (struct _DMA_ADAPTER *)Object;
v37 = Object;
if( v13 >= 0 )
{
if( *(_DWORD *)Object == 1803104306 )
{
DmaAdapter = (PADAPTER_OBJECT)Object;
v14 = 0i64;
v37 = 0i64;
v13 = 0;
}
else
{
v13 = -1073741816;
}
}
if( v14 )
HalPutDmaAdapter(v14);
if( v13 < 0 )
{
v8 = v27;
v20 = 0i64;
goto LABEL_31;
}
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) && DmaAdapter )
{
DmaOperations = DmaAdapter->DmaOperations;
v32 = DmaOperations;
}
if( (_BYTE)v12 == 1 )
{
v15 = Length;
ProbeForWrite(KeyInformation, (unsigned int)Length, 4ui64);
v16 = (__int64)ResultLength;
if( (unsigned __int64)ResultLength >= 0x7FFFFFFF0000i64 )
v16 = 0x7FFFFFFF0000i64;
*(_DWORD *)v16 = *(_DWORD *)v16;
}
else
{
v15 = Length;
}
v17 = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)v17 + 242);
v25 = 1;
if( CmpCallBackCount && !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock) )
{
v46 = (INT64)DmaAdapter;
v47 = v27;
v48 = KeyInformationClass;
v49 = KeyInformation;
v50 = v15;
v51 = ResultLength;
v18 = CmpCallCallBacksEx(
RegNtEnumerateKey,
(SLIST_ENTRY **)&v46,
0i64,
1,
RegNtPostEnumerateKey,
(INT64)DmaAdapter,
(INT64)v34);
v13 = v18;
if( v18 < 0 )
{
v8 = v27;
v20 = DmaOperations;
if( v18 == -1073740541 )
v13 = 0;
goto LABEL_31;
}
v24 = 1;
}
v13 = CmKeyBodyRemapToVirtualForEnum((__int64 *)&DmaAdapter, v12, 8u, (__int64 *)&v33);
if( v13 < 0 || (v13 = CmpBounceContextStart((INT64)Src, (struct SLIST_ENTRY *)KeyInformation, v15, v12, 0), v13 < 0) )
{
v8 = v27;
LABEL_49:
v20 = DmaOperations;
goto LABEL_31;
}
v8 = v27;
v13 = CmEnumerateKey(&DmaAdapter->Version);
if( v13 < 0 && v13 != -2147483643 && v13 != -1073741789 )
goto LABEL_49;
v19 = v30;
*(_DWORD *)ResultLength = v30;
if( v13 != -1073741789 )
{
if( v15 >= v19 )
v15 = v19;
if( Src[0] != Src[1] )
memmove((UINT8 *)Src[0], (UINT8 *)Src[1], v15);
}
v20 = DmaOperations;
LABEL_31:
if( v33 )
HalPutDmaAdapter(v33);
if( v24
&& CmpCallBackCount
&& !ExIsResourceAcquiredSharedLite((PERESOURCE)&CmpRegistryLock)
&& (INT64 *)v34[0] != v34 )
{
v40 = 0;
v43 = 0i64;
v44 = 0i64;
v45 = 0;
Argument = (SLIST_ENTRY *)DmaAdapter;
v39 = v13;
v42 = v13;
v41 = &v46;
CmpCallCallBacksEx(RegNtPostEnumerateKey, &Argument, 0i64, 0, RegNtPostEnumerateKey, (INT64)DmaAdapter, (INT64)v34);
v13 = v42;
}
if( v25 )
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
if( DmaAdapter )
HalPutDmaAdapter(DmaAdapter);
CmpBounceContextCleanup((INT64)Src);
if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
{
LOBYTE(v21) = 17;
(*(void(__fastcall **)(__int64, LARGE_INTEGER *, _QWORD, _QWORD, _DMA_OPERATIONS *, _QWORD))((char *)&NlsMbCodePageTag
+ 7))(
v21,
v53,
(unsigned int)v13,
v8,
v20,
0i64);
}
if( v26 )
{
ExReleaseRundownProtection((PEX_RUNDOWN_REF)&CmpShutdownRundown);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
}
return v13;
}Referenced by:
AdtpObjsInitialize
ExpWatchLicenseInfoWork
ExpWatchProductTypeInitialization