ExpWatchLicenseInfoWork
NTSTATUS __fastcall ExpWatchLicenseInfoWork(__int64 a1, __int64 a2, WCHAR a3){
char v4;
VOID *v5;
int v6;
NTSTATUS v7;
unsigned int v8;
VOID **PoolWithTag;
__int64 v10;
__int64 v11;
__int64 v12;
unsigned __int16 v13;
UINT64 v14;
unsigned __int64 v15;
NTSTATUS v16;
unsigned int v17;
UINT64 i;
__int64 v19;
int v20;
NTSTATUS v21;
NTSTATUS v22;
NTSTATUS result;
PVOID BugCheckParameter4;
UINT64 DataSize;
UINT64 DataSizea;
_UNICODE_STRING DestinationString;
UINT64 ResultLength;
VOID *KeyHandle;
VOID *Handle;
_OBJECT_ATTRIBUTES v31;
_UNICODE_STRING ValueName;
__int128 KeyInformation;
__int128 v34;
__int128 v35;
Handle = 0i64;
v4 = 0;
KeyInformation = 0i64;
LODWORD(ResultLength) = 0;
v34 = 0i64;
KeyHandle = 0i64;
v35 = 0i64;
*(&v31.Length + 1) = 0;
DestinationString = 0i64;
*(&v31.Attributes + 1) = 0;
ValueName = 0i64;
if( !ExpSetupModeDetected )
{
RtlInitUnicodeString(&DestinationString, *(PCWSTR *)(a1 + 16));
v5 = *(VOID **)a1;
v31.ObjectName = &DestinationString;
v31.RootDirectory = 0i64;
*(_OWORD *)&v31.SecurityDescriptor = 0i64;
v31.Length = 48;
v31.Attributes = 576;
NtClose((UINT64)v5);
v6 = CmOpenKey((VOID **)a1, 131103, &v31, 0, 0i64);
if( v6 < 0 )
KeBugCheckEx(0x9Au, (PVOID)0x12, (PVOID)v6, 0i64, 0i64);
v7 = NtQueryKey(*(VOID **)a1, KeyFullInformation, &KeyInformation, 0x30ui64, &ResultLength);
if( v7 < 0 )
KeBugCheckEx(0x9Au, (PVOID)0x13, (PVOID)v7, 0i64, 0i64);
v8 = 2 * DWORD2(v34) + 56;
if( v8 < DWORD2(v34) || v8 < 2 * (unsigned __int64)(unsigned int)(DWORD2(v34) + 16) )
v4 = 1;
PoolWithTag = ExAllocatePoolWithTag(0x200ui64, v8, 544826699i64);
if( !PoolWithTag || v4 )
KeBugCheckEx(0x9Au, (PVOID)0x14, (PVOID)v8, 0i64, 0i64);
v10 = *(_QWORD *)(a1 + 16);
v11 = -1i64;
v12 = -1i64;
do
++v12;
while( *(_WORD *)(v10 + 2 * v12 + 32) );
v13 = 2 * (WORD4(v34) + v12);
DestinationString.Length = v13;
if( (unsigned int)v13 < DWORD2(v34) )
goto LABEL_19;
v14 = v13;
v15 = -1i64;
do
++v15;
while( *(_WORD *)(v10 + 2 * v15 + 32) );
if( v13 < v15 )
goto LABEL_19;
do
++v11;
while( *(_WORD *)(v10 + 2 * v11 + 32) );
if( v13 < (unsigned __int64)DWORD2(v34) + v11 )
{
LABEL_19:
v4 = 1;
v14 = v13;
}
DestinationString.MaximumLength = v13;
DestinationString.Buffer = (wchar_t *)ExAllocatePoolWithTag(0x200ui64, v14, 544826699i64);
if( !DestinationString.Buffer || v4 )
KeBugCheckEx(0x9Au, (PVOID)0x14, (PVOID)DestinationString.Length, (PVOID)1, 0i64);
RtlInitUnicodeString(&ValueName, L"ConcurrentLimit");
LODWORD(DataSize) = 4;
v16 = NtSetValueKey(*(VOID **)a1, &ValueName, 0i64, 4ui64, (VOID *)(a1 + 8), DataSize);
if( v16 < 0 )
KeBugCheckEx(0x9Au, (PVOID)0x15, (PVOID)v16, 0i64, 0i64);
v17 = 0;
for( i = 0i64; ; i = v17 )
{
LODWORD(BugCheckParameter4) = v8;
v22 = NtEnumerateKey(*(VOID **)a1, i, KeyBasicInformation, PoolWithTag, (UINT64)BugCheckParameter4, &ResultLength);
if( v22 == -2147483622 )
break;
if( v22 >= 0 )
{
*((_WORD *)PoolWithTag + ((unsigned __int64)*((unsigned int *)PoolWithTag + 3) >> 1) + 8) = 0;
wcscpy_s(DestinationString.Buffer, (unsigned __int64)DestinationString.MaximumLength >> 1, *(PWCHAR *)(a1 + 16));
wcscat_s(DestinationString.Buffer, (unsigned __int64)DestinationString.MaximumLength >> 1, (WCHAR *)L"\\");
wcscat_s(
DestinationString.Buffer,
(unsigned __int64)DestinationString.MaximumLength >> 1,
(WCHAR *)PoolWithTag + 8);
v19 = -1i64;
do
++v19;
while( DestinationString.Buffer[v19] );
v31.Length = 48;
DestinationString.Length = 2 * v19;
v31.RootDirectory = 0i64;
v31.ObjectName = &DestinationString;
v31.Attributes = 576;
*(_OWORD *)&v31.SecurityDescriptor = 0i64;
v20 = CmOpenKey(&KeyHandle, 131103, &v31, 0, 0i64);
if( v20 < 0 )
KeBugCheckEx(0x9Au, (PVOID)0x16, (PVOID)v20, 0i64, 0i64);
LODWORD(DataSizea) = 4;
v21 = NtSetValueKey(KeyHandle, &ValueName, 0i64, 4ui64, (VOID *)(a1 + 8), DataSizea);
if( v21 < 0 )
KeBugCheckEx(0x9Au, (PVOID)0x17, (PVOID)v21, 0i64, 0i64);
NtClose((UINT64)KeyHandle);
}
++v17;
}
ExFreePoolWithTag(PoolWithTag, 0);
ExFreePoolWithTag(DestinationString.Buffer, 0);
}
result = NtNotifyChangeKey(
*(_QWORD *)a1,
0,
(PIO_APC_ROUTINE)(a1 + 24),
(PVOID)1,
(PIO_STATUS_BLOCK)(a1 + 56),
0x10000005u,
1u,
(PVOID)(a1 + 72),
4u,
1u);
if( result < 0 )
KeBugCheckEx(0x9Au, (PVOID)0x18, (PVOID)result, 0i64, 0i64);
if( !ExpSetupModeDetected )
{
result = PsCreateSystemThreadEx(
(__int64)&Handle,
0x1FFFFF,
0i64,
0i64,
0i64,
ExpExpirationThread,
3221226090i64,
0i64,
0i64);
if( result >= 0 )
return ZwClose((_HANDLE)Handle);
}
return result;
}Referenced by:
No references.