IoOpenDriverRegistryKey
__int64 __fastcall IoOpenDriverRegistryKey(__int64 a1, int a2, unsigned int a3, int a4, _QWORD *a5){
_KEY_VALUE_FULL_INFORMATION *v7;
void *v8;
CHAR *v9;
void *v10;
__int64 v11;
NTSTATUS v12;
NTSTATUS v13;
NTSTATUS RegistryValue;
INT64 v15;
NTSTATUS DriverRedirectedStateKey;
INT64 v17;
NTSTATUS v18;
NTSTATUS ServiceStateSecurityObject;
VOID *v20;
INT64 CreateEnum;
INT64 v23;
UINT64 v24;
INT64 v25;
INT64 v26;
_KEY_VALUE_FULL_INFORMATION *Information;
CHAR *v28;
void *v29;
VOID *ServiceHandle;
_OBJECT_ATTRIBUTES ObjectAttributes;
VOID *KeyHandle;
int v33;
v33 = a2;
KeyHandle = 0i64;
Information = 0i64;
v29 = 0i64;
v7 = 0i64;
v28 = 0i64;
v8 = 0i64;
ServiceHandle = 0i64;
v9 = 0i64;
v10 = 0i64;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
if( !a1 )
goto LABEL_34;
v11 = *(_QWORD *)(a1 + 48);
if( !v11 || !*(_QWORD *)(v11 + 32) || !*(_WORD *)(v11 + 24) || a4 || !a5 )
goto LABEL_34;
v12 = PipOpenServiceEnumKeys((_UNICODE_STRING *)(v11 + 24), 0x2001Dui64, &ServiceHandle, 0i64, 0);
v10 = ServiceHandle;
v13 = v12;
if( v12 < 0 )
goto LABEL_37;
RegistryValue = IopGetRegistryValue(ServiceHandle, (PWCHAR)L"Type", 0i64, &Information);
v7 = Information;
v13 = RegistryValue;
if( RegistryValue == -1073741772 )
goto LABEL_34;
if( RegistryValue < 0 )
goto LABEL_35;
if( Information->Type != 4 || Information->DataLength != 4 )
{
v13 = -1073741492;
goto LABEL_35;
}
if( (*(ULONG *)((_BYTE *)&Information->TitleIndex + Information->DataOffset) & 0xB) == 0 )
goto LABEL_34;
if( !v33 )
{
if( (a3 & 0x2000000) != 0 )
a3 = a3 & 0xFDFDFFE6 | 0x20019;
if( (a3 & 0x7FFDFFE6) == 0 )
{
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)&PiDriverRegKeyParametersName;
ObjectAttributes.RootDirectory = v10;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v13 = ZwOpenKey(&KeyHandle, a3, &ObjectAttributes, v15, CreateEnum, v23, v25, v26);
goto LABEL_28;
}
v13 = -1073741790;
goto LABEL_35;
}
if( v33 != 1 )
{
LABEL_34:
v13 = -1073741811;
goto LABEL_35;
}
DriverRedirectedStateKey = PiCreateDriverRedirectedStateKey(*(_QWORD *)(a1 + 48) + 24);
v13 = DriverRedirectedStateKey;
if( DriverRedirectedStateKey == -1073741772 )
{
v8 = v10;
}
else
{
v8 = v29;
if( DriverRedirectedStateKey < 0 )
goto LABEL_35;
}
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)&PiDriverRegKeyPersistentStateName;
ObjectAttributes.RootDirectory = v8;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v18 = ZwOpenKey(&KeyHandle, a3, &ObjectAttributes, v17, CreateEnum, v23, v25, v26);
v13 = v18;
if( v18 == -1073741772 )
{
ServiceStateSecurityObject = PiAuGetServiceStateSecurityObject(&v28);
v9 = v28;
v13 = ServiceStateSecurityObject;
if( ServiceStateSecurityObject < 0 )
goto LABEL_35;
LODWORD(v24) = 0;
ObjectAttributes.SecurityQualityOfService = 0i64;
ObjectAttributes.Length = 48;
ObjectAttributes.RootDirectory = v8;
ObjectAttributes.Attributes = 576;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)&PiDriverRegKeyPersistentStateName;
ObjectAttributes.SecurityDescriptor = v28;
v18 = ZwCreateKey(&KeyHandle, a3, &ObjectAttributes, 0i64, 0i64, v24, 0i64);
v13 = v18;
}
if( v18 >= 0 )
{
LABEL_28:
if( v13 >= 0 )
{
v20 = KeyHandle;
if( v33 == 1 && KeyHandle )
{
IopApplyMutableTagToRegistryKey((_HANDLE)KeyHandle);
v20 = KeyHandle;
}
KeyHandle = 0i64;
*a5 = v20;
}
}
LABEL_35:
if( v7 )
ExFreePoolWithTag(v7, 0);
LABEL_37:
if( KeyHandle )
ZwClose((_HANDLE)KeyHandle);
if( v8 && v8 != v10 )
ZwClose((_HANDLE)v8);
if( v10 )
ZwClose((_HANDLE)v10);
if( v9 )
ExFreePoolWithTag(v9, 0);
return(unsigned int)v13;
}Referenced by:
No references.