AdtpBuildAccessesString
__int64 __fastcall AdtpBuildAccessesString(
const UNICODE_STRING *a1,
const UNICODE_STRING *a2,
int a3,
int a4,
PUNICODE_STRING DestinationString,
__int64 a6,
__int64 a7,
__int64 a8,
__int64 a9){
int v9;
__int64 *v10;
int v11;
NTSTATUS appended;
int v14;
int v15;
WCHAR *v16;
unsigned int v17;
__int64 v18;
int v19;
wchar_t *PoolWithTag;
unsigned int v21;
unsigned int v22;
__int64 *v23;
int *v24;
wchar_t **v25;
_ETHREAD *CurrentThread;
WCHAR v27;
__int64 *v28;
char v29;
UNICODE_STRING *v30;
__int64 *v31;
_QWORD *v32;
WCHAR v33;
wchar_t *Buffer;
char v35;
UNICODE_STRING *v36;
_QWORD *v37;
int v38;
unsigned int v39;
int v40;
NTSTATUS v41;
struct _UNICODE_STRING Destination;
int v43;
WCHAR *v44;
wchar_t **v45;
_QWORD *v46;
PCUNICODE_STRING String2;
PCUNICODE_STRING v48;
wchar_t *v49;
struct _UNICODE_STRING String;
PUNICODE_STRING v51;
UNICODE_STRING v52;
UNICODE_STRING v53;
char v54;
v9 = a3;
v10 = 0i64;
v43 = a3;
v11 = 0;
v48 = a2;
appended = 0;
String2 = a1;
v51 = DestinationString;
v45 = (wchar_t **)a6;
v46 = 0i64;
*(_DWORD *)(&Destination.MaximumLength + 1) = 0;
v52 = 0i64;
v53 = 0i64;
if( !v9 )
{
if( a6 )
{
*(_QWORD *)(a6 + 8) = 4i64;
*(_QWORD *)a6 = "-";
}
else if( DestinationString )
{
RtlInitUnicodeString(DestinationString, L"-", 0);
}
return 0i64;
}
v14 = v9;
do
{
++v11;
v14 &= v14 - 1;
}
while( v14 );
if( a4 )
{
v15 = a4 - 1;
if( !v15 )
{
v16 = (WCHAR *)L"\r\n";
goto LABEL_15;
}
if( v15 == 1 )
{
v16 = (WCHAR *)L":\t";
goto LABEL_15;
}
}
v16 = (WCHAR *)L"\r\n\t\t\t\t";
LABEL_15:
v44 = v16;
v17 = 24 * v11 + 1;
if( a7 && a8 && (v18 = *(unsigned int *)a8, v19 = v18 + v17, (unsigned int)v18 + v17 < 0x400) )
{
PoolWithTag = (wchar_t *)(a7 + 2 * v18);
*(_DWORD *)a8 = v19;
v49 = PoolWithTag;
}
else
{
PoolWithTag = (wchar_t *)ExAllocatePoolWithTag(PagedPool, 2i64 * v17, 0x6B416553ui64);
v49 = PoolWithTag;
if( !PoolWithTag )
return 3221225495i64;
*(_BYTE *)a9 = 1;
appended = 0;
}
Destination.Length = 0;
Destination.MaximumLength = 2 * v17;
v21 = 5;
Destination.Buffer = PoolWithTag;
if( (v9 & 0x1F0000) != 0 )
{
v22 = 0;
v23 = AdtpStandardAccessTypes;
do
{
if( (v9 & *(_DWORD *)v23) != 0 )
{
RtlAppendUnicodeToString(&Destination, (PWCHAR)L"%%");
RtlAppendUnicodeStringToString(&Destination, (UNICODE_STRING *)&AdtpEventIdStringStandard[16 * v22]);
appended = RtlAppendUnicodeToString(&Destination, v16);
}
++v22;
v23 = (__int64 *)((char *)v23 + 4);
}
while( v22 < 5 );
}
v24 = &dword_14001A714;
do
{
if( (v9 & *v24) != 0 )
{
RtlAppendUnicodeToString(&Destination, (PWCHAR)L"%%");
RtlAppendUnicodeStringToString(&Destination, (UNICODE_STRING *)&AdtpEventIdStringStandard[16 * v21]);
appended = RtlAppendUnicodeToString(&Destination, v16);
}
++v21;
++v24;
}
while( v21 < 7 );
v25 = v45;
v41 = appended;
if( (_WORD)v9 )
{
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
--*((_WORD *)CurrentThread + 242);
ExAcquireResourceExclusiveLite(&AdtpSourceModuleLock, 1u);
v28 = &AdtpSourceModules;
v29 = 0;
if( AdtpSourceModules )
{
v30 = (UNICODE_STRING *)String2;
do
{
if( v29 )
break;
v31 = (__int64 *)*v28;
if( RtlEqualUnicodeString((UNICODE_STRING *)(*v28 + 8), v30, 1u) )
{
v29 = 1;
*v28 = *v31;
v10 = v31;
*v31 = AdtpSourceModules;
AdtpSourceModules = (__int64)v31;
}
else
{
v28 = v31;
}
}
while( *v28 );
v25 = v45;
if( v29 == 1 )
{
v29 = 0;
v32 = v10 + 3;
RtlInitUnicodeString(&v52, L"DS", v27);
if( !RtlEqualUnicodeString((UNICODE_STRING *)String2, &v52, 1u)
|| v48->Length != 78
|| (Buffer = v48->Buffer, *Buffer != 37)
|| Buffer[1] != 123
|| (v35 = 1, Buffer[38] != 125) )
{
v35 = 0;
}
RtlInitUnicodeString(&v53, L"Directory Service Object", v33);
if( v10[3] )
{
v36 = (UNICODE_STRING *)v48;
do
{
if( v29 )
break;
if( v35 && (v37 = (_QWORD *)*v32, RtlEqualUnicodeString((UNICODE_STRING *)(*v32 + 8i64), &v53, 1u))
|| (v37 = (_QWORD *)*v32, RtlEqualUnicodeString((UNICODE_STRING *)(*v32 + 8i64), v36, 1u)) )
{
v29 = 1;
v46 = v37;
*v32 = *v37;
*v37 = v10[3];
v10[3] = (__int64)v37;
}
else
{
v32 = v37;
}
}
while( *v32 );
v25 = v45;
v16 = v44;
}
v9 = v43;
}
}
ExReleaseResourceLite(&AdtpSourceModuleLock);
KeLeaveCriticalRegionThread((__int64)KeGetCurrentThread());
if( v29 )
v38 = *((_DWORD *)v46 + 6);
else
v38 = 1552;
*(_QWORD *)&String.Length = 1310720i64;
v39 = 0;
String.Buffer = (wchar_t *)&v54;
v40 = 1;
do
{
if( (v40 & v9) != 0 )
{
v41 = RtlIntegerToUnicodeString(v39 + v38, 0xAui64, &String);
appended = v41;
if( v41 >= 0 )
{
RtlAppendUnicodeToString(&Destination, (PWCHAR)L"%%");
RtlAppendUnicodeStringToString(&Destination, &String);
appended = RtlAppendUnicodeToString(&Destination, v16);
v41 = appended;
}
}
else
{
appended = v41;
}
++v39;
v40 *= 2;
}
while( v39 < 0x10 );
}
if( appended >= 0 )
{
if( v25 )
{
*v25 = v49;
v25[1] = (wchar_t *)((unsigned int)Destination.Length + 2);
}
else
{
*v51 = Destination;
}
}
return(unsigned int)appended;
}Referenced by:
AdtpBuildAccessReasonAuditStringInternal
AdtpBuildObjectTypeStrings
AdtpBuildStagingReasonAuditStringInternal
AdtpPackageParameters