NtQueryKey

NTSTATUS __stdcall NtQueryKey(
        VOID *KeyHandle,
        _KEY_INFORMATION_CLASS KeyInformationClass,
        VOID *KeyInformation,
        UINT64 Length,
        UINT64 *ResultLength){
  __int64 v5; 
  _ETHREAD *CurrentThread; 
  INT64 v10; 
  INT64 v11; 
  char v12; 
  unsigned __int64 v13; 
  unsigned __int64 v14; 
  unsigned __int64 v15; 
  __int64 v16; 
  NTSTATUS v17; 
  _QWORD *v18; 
  _ETHREAD *v19; 
  NTSTATUS IsResourceAcquiredSharedLite; 
  unsigned __int16 *v21; 
  int v22; 
  _ETHREAD *v23; 
  bool v24; 
  VOID *v25; 
  size_t v27; 
  unsigned int v28; 
  char PreviousMode; 
  NTSTATUS v30; 
  char v31; 
  char v32; 
  char v33; 
  UINT8 v34; 
  unsigned int Size; 
  unsigned int v36; 
  PVOID Object; 
  PADAPTER_OBJECT DmaAdapter; 
  PADAPTER_OBJECT v39; 
  __int64 v40; 
  INT64 v41[2]; 
  PVOID v42; 
  _OBJECT_HANDLE_INFORMATION HandleInformation; 
  _SLIST_ENTRY *v44; 
  NTSTATUS v45; 
  int v46; 
  _SLIST_ENTRY **v47; 
  NTSTATUS v48; 
  __int128 v49; 
  __int64 v50; 
  int v51; 
  _SLIST_ENTRY *Argument[8]; 
  VOID *Src[2]; 
  char v54; 
  char v55[71]; 
  _LARGE_INTEGER TimeStamp[2]; 
  __int128 v57; 

  v5 = (unsigned int)Length;
  Size = Length;
  HandleInformation = 0i64;
  v36 = 0;
  memset(v55, 0i64, sizeof(v55));
  *(_OWORD *)&TimeStamp[0].anonymous_0.LowPart = 0i64;
  v57 = 0i64;
  v40 = 0i64;
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
    EtwGetKernelTraceTimestamp(TimeStamp, 0x20000ui64);
  v32 = 0;
  v33 = 0;
  DmaAdapter = 0i64;
  memset(Argument, 0i64, sizeof(Argument));
  *(_OWORD *)Src = 0i64;
  v54 = 0;
  v41[1] = (INT64)v41;
  v41[0] = (INT64)v41;
  v39 = 0i64;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  --CurrentThread->Tcb.KernelApcDisable;
  v34 = ExAcquireRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
  if( !v34 )
    KeLeaveCriticalRegionThread(KeGetCurrentThread());
  if( !v34 )
  {
    v17 = -1073741431;
    goto LABEL_35;
  }
  if( (unsigned int)KeyInformationClass > KeyTrustInformation )
  {
    if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
    {
      if( KeyHandle )
      {
        PreviousMode = KeGetCurrentThread()->PreviousMode;
        v42 = 0i64;
        if( ObReferenceObjectByHandle(KeyHandle, 0i64, (_OBJECT_TYPE *)CmKeyObjectType, PreviousMode, &v42, 0i64) >= 0 )
        {
          v40 = *((_QWORD *)v42 + 1);
          HalPutDmaAdapter((PADAPTER_OBJECT)v42);
        }
      }
    }
    v17 = -1073741811;
    goto LABEL_35;
  }
  v12 = KeGetCurrentThread()->PreviousMode;
  v31 = v12;
  if( v12 == 1 )
  {
    if( (_DWORD)v5 )
    {
      v13 = (unsigned __int64)KeyInformation;
      if( ((unsigned __int8)KeyInformation & 3) != 0 )
        ExRaiseDatatypeMisalignment();
      v14 = (unsigned __int64)KeyInformation + v5 - 1;
      if( (unsigned __int64)KeyInformation > v14 || v14 >= 0x7FFFFFFF0000i64 )
        ExRaiseAccessViolation();
      v15 = (v14 & 0xFFFFFFFFFFFFF000ui64) + 4096;
      do
      {
        *(_BYTE *)v13 = *(_BYTE *)v13;
        v13 = (v13 & 0xFFFFFFFFFFFFF000ui64) + 4096;
      }
      while( v13 != v15 );
    }
    v16 = (__int64)ResultLength;
    if( (unsigned __int64)ResultLength >= 0x7FFFFFFF0000i64 )
      v16 = 0x7FFFFFFF0000i64;
    *(_DWORD *)v16 = *(_DWORD *)v16;
    v12 = 1;
  }
  Object = 0i64;
  v17 = ObReferenceObjectByHandle(
          KeyHandle,
          ((KeyInformationClass - 3) & 0xFFFFFFFB) != 0,
          (_OBJECT_TYPE *)CmKeyObjectType,
          v12,
          &Object,
          &HandleInformation);
  v18 = Object;
  DmaAdapter = (PADAPTER_OBJECT)Object;
  v30 = v17;
  if( v17 < 0 )
    goto LABEL_36;
  if( *(_DWORD *)Object != 1803104306 )
  {
    if( KeyInformationClass != KeyCachedInformation )
    {
      v17 = -1073741816;
      goto LABEL_35;
    }
    *(_DWORD *)ResultLength = 40;
    if( (unsigned int)v5 < 0x28 )
    {
      v17 = -1073741789;
      v30 = -1073741789;
      goto LABEL_36;
    }
    *(_OWORD *)KeyInformation = 0i64;
    *((_OWORD *)KeyInformation + 1) = 0i64;
    *((_QWORD *)KeyInformation + 4) = 0i64;
    *((_DWORD *)KeyInformation + 5) = *(_DWORD *)(v18[1] + 96i64);
    goto LABEL_34;
  }
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
    v40 = *((_QWORD *)Object + 1);
  if( ((KeyInformationClass - 3) & 0xFFFFFFFB) == 0 && !HandleInformation.GrantedAccess )
  {
    v17 = -1073741790;
    goto LABEL_35;
  }
  v19 = (_ETHREAD *)KeGetCurrentThread();
  --v19->Tcb.KernelApcDisable;
  v33 = 1;
  if( !dword_140C5083C )
  {
    v21 = (unsigned __int16 *)Object;
    goto LABEL_30;
  }
  IsResourceAcquiredSharedLite = ExIsResourceAcquiredSharedLite((UINT64)&CmpRegistryLock, v10, v11);
  v21 = (unsigned __int16 *)Object;
  if( !IsResourceAcquiredSharedLite )
  {
    Argument[0] = (_SLIST_ENTRY *)Object;
    LODWORD(Argument[1]) = KeyInformationClass;
    Argument[2] = (_SLIST_ENTRY *)KeyInformation;
    LODWORD(Argument[3]) = Size;
    Argument[4] = (_SLIST_ENTRY *)ResultLength;
    v22 = CmpCallCallBacksEx(RegNtQueryKey, Argument, 0i64, 1, RegNtPostQueryKey, (INT64)Object, (INT64)v41);
    v17 = v22;
    v30 = v22;
    if( v22 >= 0 )
    {
      v32 = 1;
      goto LABEL_30;
    }
    if( v22 != -1073740541 )
      goto LABEL_36;
LABEL_34:
    v17 = 0;
LABEL_35:
    v30 = v17;
    goto LABEL_36;
  }
LABEL_30:
  if( KeyInformationClass == KeyHandleTagsInformation )
  {
    *(_DWORD *)ResultLength = 4;
    if( Size < 4 )
    {
      v17 = -1073741789;
      v30 = -1073741789;
      goto LABEL_36;
    }
    *(_DWORD *)KeyInformation = v21[25];
    goto LABEL_34;
  }
  v17 = CmKeyBodyRemapToVirtualForEnum((CM_KEY_BODY **)&DmaAdapter, (CM_KEY_BODY **)(unsigned __int8)v31);
  v30 = v17;
  if( v17 >= 0 )
  {
    v27 = Size;
    v17 = CmpBounceContextStart((INT64)Src, (struct SLIST_ENTRY *)KeyInformation, Size, (unsigned int)v31, 2);
    v30 = v17;
    if( v17 >= 0 )
    {
      v17 = CmQueryKey((__int64)DmaAdapter, (__int64)v39, KeyInformationClass, (unsigned int *)Src[1], Size, &v36);
      v30 = v17;
      if( v17 >= 0 || v17 == -2147483643 || v17 == -1073741789 )
      {
        v28 = v36;
        *(_DWORD *)ResultLength = v36;
        if( v17 != -1073741789 )
        {
          if( Size >= v28 )
            v27 = v28;
          if( Src[0] != Src[1] )
            memmove(Src[0], Src[1], v27);
        }
      }
    }
  }
LABEL_36:
  if( v39 )
    HalPutDmaAdapter(v39);
  if( v32 )
  {
    if( dword_140C5083C
      && !ExIsResourceAcquiredSharedLite((UINT64)&CmpRegistryLock, v10, v11)
      && (INT64 *)v41[0] != v41 )
    {
      v46 = 0;
      v49 = 0i64;
      v50 = 0i64;
      v51 = 0;
      v44 = (_SLIST_ENTRY *)DmaAdapter;
      v45 = v17;
      v48 = v17;
      v47 = Argument;
      CmpCallCallBacksEx(RegNtPostQueryKey, &v44, 0i64, 0, RegNtPostQueryKey, (INT64)DmaAdapter, (INT64)v41);
      v17 = v48;
    }
    v30 = v17;
  }
  if( v33 )
  {
    v23 = (_ETHREAD *)KeGetCurrentThread();
    v24 = v23->Tcb.KernelApcDisable++ == -1;
    if( v24
      && ($F25F8C4BA33AF922A5F1AF68CD89DDDF *)v23->Tcb.ApcState.ApcListHead[0].Flink != &v23->Tcb.152
      && !v23->Tcb.SpecialApcDisable )
    {
      KiCheckForKernelApcDelivery();
    }
    v17 = v30;
  }
  if( DmaAdapter )
    HalPutDmaAdapter(DmaAdapter);
  v25 = Src[1];
  if( Src[1] && Src[1] != Src[0] && Src[1] != v55 )
  {
    if( (v54 & 1) != 0 )
    {
      ++*(&WheapErrorSourceTable + 401);
      if( *(&WheapErrorSourceTable + 788) >= *(&WheapErrorSourceTable + 796) )
      {
        ++*(&WheapErrorSourceTable + 402);
        (*(&WheapErrorSourceTable + 204))(Src[1], (char *)&WheapErrorSourceTable + 1576);
      }
      else
      {
        RtlpInterlockedPushEntrySList((PSLIST_HEADER)((char *)&WheapErrorSourceTable + 1576), (PSLIST_ENTRY)Src[1]);
      }
    }
    else
    {
      CmSiFreeMemory((PPRIVILEGE_SET)Src[1]);
    }
  }
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
  {
    LOBYTE(v25) = 13;
    (*(void(__fastcall **)(VOID *, _LARGE_INTEGER *, _QWORD, _QWORD, __int64, _QWORD))((char *)&NlsMbCodePageTag + 7))(
      v25,
      TimeStamp,
      (unsigned int)v17,
      (unsigned int)KeyInformationClass,
      v40,
      0i64);
  }
  if( v34 )
  {
    ExReleaseRundownProtection((_EX_RUNDOWN_REF *)&CmpDummyThreadEvent + 132);
    KeLeaveCriticalRegionThread(KeGetCurrentThread());
    return v30;
  }
  return v17;
}

Referenced by:

ExpWatchLicenseInfoWork
ExpWatchProductTypeInitialization
IopLoadDriver
PiDevCfgConfigureDeviceLocation
PiDevCfgFindDeviceMigrationNode
PiDevCfgQueryPolicyStringList