KsepRegistryOpenKey
NTSTATUS __stdcall KsepRegistryOpenKey(PWCHAR EnginePath, PWCHAR SearchKey, PVOID *Handle){
NTSTATUS v6;
int v7;
__int64 v9;
__int64 v10;
UNICODE_STRING ResultString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
void *KeyHandle;
*(_QWORD *)&ResultString.Length = 0i64;
ResultString.Buffer = 0i64;
KeyHandle = 0i64;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
if( !EnginePath )
{
v9 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
KsepHistoryErrors[2 * v9 + 1] = -1073740768;
KsepHistoryErrors[2 * v9] = 262566;
if( (KsepDebugFlag & 4) != 0 )
RtlAssert("EnginePath != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x1A6u, 0i64);
}
if( !Handle )
{
v10 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
KsepHistoryErrors[2 * v10 + 1] = -1073740768;
KsepHistoryErrors[2 * v10] = 262567;
if( (KsepDebugFlag & 4) != 0 )
RtlAssert("Handle != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x1A7u, 0i64);
}
if( SearchKey )
v6 = KsepStringConcatenate(&ResultString, EnginePath, SearchKey, 1ui64);
else
v6 = KsepStringDuplicate(&ResultString, EnginePath);
v7 = v6;
if( v6 >= 0 )
{
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = &ResultString;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
v7 = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
if( v7 >= 0 )
{
*Handle = KeyHandle;
_InterlockedIncrement(&dword_140C2A7F8);
}
}
KsepStringFree(&ResultString);
return v7;
}Referenced by:
KsepDbQueryRegistryDeviceData
KsepDbQueryRegistryDeviceDataList
KsepEngineReadFlags
KsepMatchInitBiosInfo
KsepRegistryQueryDriverShims