AdtpBuildAccessesString

__int64 __fastcall AdtpBuildAccessesString(
        const UNICODE_STRING *a1,
        const UNICODE_STRING *a2,
        int a3,
        int a4,
        PUNICODE_STRING DestinationString,
        __int64 a6,
        __int64 a7,
        __int64 a8,
        __int64 a9){
  int v9; 
  __int64 *v10; 
  int v11; 
  NTSTATUS appended; 
  int v14; 
  int v15; 
  WCHAR *v16; 
  unsigned int v17; 
  __int64 v18; 
  int v19; 
  wchar_t *PoolWithTag; 
  unsigned int v21; 
  unsigned int v22; 
  __int64 *v23; 
  int *v24; 
  wchar_t **v25; 
  _ETHREAD *CurrentThread; 
  WCHAR v27; 
  __int64 *v28; 
  char v29; 
  UNICODE_STRING *v30; 
  __int64 *v31; 
  _QWORD *v32; 
  WCHAR v33; 
  wchar_t *Buffer; 
  char v35; 
  UNICODE_STRING *v36; 
  _QWORD *v37; 
  int v38; 
  unsigned int v39; 
  int v40; 
  NTSTATUS v41; 
  struct _UNICODE_STRING Destination; 
  int v43; 
  WCHAR *v44; 
  wchar_t **v45; 
  _QWORD *v46; 
  PCUNICODE_STRING String2; 
  PCUNICODE_STRING v48; 
  wchar_t *v49; 
  struct _UNICODE_STRING String; 
  PUNICODE_STRING v51; 
  UNICODE_STRING v52; 
  UNICODE_STRING v53; 
  char v54; 
  v9 = a3;
  v10 = 0i64;
  v43 = a3;
  v11 = 0;
  v48 = a2;
  appended = 0;
  String2 = a1;
  v51 = DestinationString;
  v45 = (wchar_t **)a6;
  v46 = 0i64;
  *(_DWORD *)(&Destination.MaximumLength + 1) = 0;
  v52 = 0i64;
  v53 = 0i64;
  if( !v9 )
  {
    if( a6 )
    {
      *(_QWORD *)(a6 + 8) = 4i64;
      *(_QWORD *)a6 = "-";
    }
    else if( DestinationString )
    {
      RtlInitUnicodeString(DestinationString, L"-", 0);
    }
    return 0i64;
  }
  v14 = v9;
  do
  {
    ++v11;
    v14 &= v14 - 1;
  }
  while( v14 );
  if( a4 )
  {
    v15 = a4 - 1;
    if( !v15 )
    {
      v16 = (WCHAR *)L"\r\n";
      goto LABEL_15;
    }
    if( v15 == 1 )
    {
      v16 = (WCHAR *)L":\t";
      goto LABEL_15;
    }
  }
  v16 = (WCHAR *)L"\r\n\t\t\t\t";
LABEL_15:
  v44 = v16;
  v17 = 24 * v11 + 1;
  if( a7 && a8 && (v18 = *(unsigned int *)a8, v19 = v18 + v17, (unsigned int)v18 + v17 < 0x400) )
  {
    PoolWithTag = (wchar_t *)(a7 + 2 * v18);
    *(_DWORD *)a8 = v19;
    v49 = PoolWithTag;
  }
  else
  {
    PoolWithTag = (wchar_t *)ExAllocatePoolWithTag(PagedPool, 2i64 * v17, 0x6B416553ui64);
    v49 = PoolWithTag;
    if( !PoolWithTag )
      return 3221225495i64;
    *(_BYTE *)a9 = 1;
    appended = 0;
  }
  Destination.Length = 0;
  Destination.MaximumLength = 2 * v17;
  v21 = 5;
  Destination.Buffer = PoolWithTag;
  if( (v9 & 0x1F0000) != 0 )
  {
    v22 = 0;
    v23 = AdtpStandardAccessTypes;
    do
    {
      if( (v9 & *(_DWORD *)v23) != 0 )
      {
        RtlAppendUnicodeToString(&Destination, (PWCHAR)L"%%");
        RtlAppendUnicodeStringToString(&Destination, (UNICODE_STRING *)&AdtpEventIdStringStandard[16 * v22]);
        appended = RtlAppendUnicodeToString(&Destination, v16);
      }
      ++v22;
      v23 = (__int64 *)((char *)v23 + 4);
    }
    while( v22 < 5 );
  }
  v24 = &dword_14001A714;
  do
  {
    if( (v9 & *v24) != 0 )
    {
      RtlAppendUnicodeToString(&Destination, (PWCHAR)L"%%");
      RtlAppendUnicodeStringToString(&Destination, (UNICODE_STRING *)&AdtpEventIdStringStandard[16 * v21]);
      appended = RtlAppendUnicodeToString(&Destination, v16);
    }
    ++v21;
    ++v24;
  }
  while( v21 < 7 );
  v25 = v45;
  v41 = appended;
  if( (_WORD)v9 )
  {
    CurrentThread = (_ETHREAD *)KeGetCurrentThread();
    --*((_WORD *)CurrentThread + 242);
    ExAcquireResourceExclusiveLite(&AdtpSourceModuleLock, 1u);
    v28 = &AdtpSourceModules;
    v29 = 0;
    if( AdtpSourceModules )
    {
      v30 = (UNICODE_STRING *)String2;
      do
      {
        if( v29 )
          break;
        v31 = (__int64 *)*v28;
        if( RtlEqualUnicodeString((UNICODE_STRING *)(*v28 + 8), v30, 1u) )
        {
          v29 = 1;
          *v28 = *v31;
          v10 = v31;
          *v31 = AdtpSourceModules;
          AdtpSourceModules = (__int64)v31;
        }
        else
        {
          v28 = v31;
        }
      }
      while( *v28 );
      v25 = v45;
      if( v29 == 1 )
      {
        v29 = 0;
        v32 = v10 + 3;
        RtlInitUnicodeString(&v52, L"DS", v27);
        if( !RtlEqualUnicodeString((UNICODE_STRING *)String2, &v52, 1u)
          || v48->Length != 78
          || (Buffer = v48->Buffer, *Buffer != 37)
          || Buffer[1] != 123
          || (v35 = 1, Buffer[38] != 125) )
        {
          v35 = 0;
        }
        RtlInitUnicodeString(&v53, L"Directory Service Object", v33);
        if( v10[3] )
        {
          v36 = (UNICODE_STRING *)v48;
          do
          {
            if( v29 )
              break;
            if( v35 && (v37 = (_QWORD *)*v32, RtlEqualUnicodeString((UNICODE_STRING *)(*v32 + 8i64), &v53, 1u))
              || (v37 = (_QWORD *)*v32, RtlEqualUnicodeString((UNICODE_STRING *)(*v32 + 8i64), v36, 1u)) )
            {
              v29 = 1;
              v46 = v37;
              *v32 = *v37;
              *v37 = v10[3];
              v10[3] = (__int64)v37;
            }
            else
            {
              v32 = v37;
            }
          }
          while( *v32 );
          v25 = v45;
          v16 = v44;
        }
        v9 = v43;
      }
    }
    ExReleaseResourceLite(&AdtpSourceModuleLock);
    KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
    if( v29 )
      v38 = *((_DWORD *)v46 + 6);
    else
      v38 = 1552;
    *(_QWORD *)&String.Length = 1310720i64;
    v39 = 0;
    String.Buffer = (wchar_t *)&v54;
    v40 = 1;
    do
    {
      if( (v40 & v9) != 0 )
      {
        v41 = RtlIntegerToUnicodeString(v39 + v38, 0xAui64, &String);
        appended = v41;
        if( v41 >= 0 )
        {
          RtlAppendUnicodeToString(&Destination, (PWCHAR)L"%%");
          RtlAppendUnicodeStringToString(&Destination, &String);
          appended = RtlAppendUnicodeToString(&Destination, v16);
          v41 = appended;
        }
      }
      else
      {
        appended = v41;
      }
      ++v39;
      v40 *= 2;
    }
    while( v39 < 0x10 );
  }
  if( appended >= 0 )
  {
    if( v25 )
    {
      *v25 = v49;
      v25[1] = (wchar_t *)((unsigned int)Destination.Length + 2);
    }
    else
    {
      *v51 = Destination;
    }
  }
  return(unsigned int)appended;
}

Referenced by:

AdtpBuildAccessReasonAuditStringInternal
AdtpBuildObjectTypeStrings
AdtpBuildStagingReasonAuditStringInternal
AdtpPackageParameters