SepRegQueryValue
NTSTATUS __stdcall SepRegQueryValue(
PVOID hKey,
PWCHAR ValueName,
UINT64 ValueType,
UINT64 ValueLength,
PVOID ValueBuffer){
size_t v6;
int v7;
int v8;
int v10;
UINT64 Length;
UINT64 ResultLength;
_UNICODE_STRING DestinationString;
char KeyValueInformation[4];
int v15;
int v16;
int Src[17];
LODWORD(ResultLength) = 0;
v6 = ValueLength;
DestinationString = 0i64;
v7 = ValueType;
RtlInitUnicodeString(&DestinationString, ValueName);
LODWORD(Length) = 80;
v8 = ZwQueryValueKey(hKey, &DestinationString, KeyValuePartialInformation, KeyValueInformation, Length, &ResultLength);
if( v8 >= 0 )
{
if( v15 == v7 && v16 == v6 )
{
v10 = v7 - 3;
if( v10 )
{
if( v10 == 1 && v6 >= 4 )
*(_DWORD *)ValueBuffer = Src[0];
else
return -1073741811;
}
else
{
memmove(ValueBuffer, Src, v6);
}
}
else
{
return -1073741788;
}
}
return v8;
}Referenced by:
SepAdtInitializeBounds
SepAdtInitializeCrashOnFail
SepAdtInitializePrivilegeAuditing
SepRegQueryDwordValue