BiConvertBootEnvironmentDeviceToNt
INT64 __fastcall BiConvertBootEnvironmentDeviceToNt(INT64 a1, INT64 a2, CHAR r8, WCHAR **a4, UINT64 *a5){
int v6;
size_t PoolWithTag;
char v8;
unsigned int v9;
int v10;
int v11;
int v12;
int v13;
INT64 *v14;
INT64 v15;
__int64 v16;
int v17;
UINT8 *v18;
__int64 v19;
VOID *v20;
int v22;
int v23;
VOID *v24;
UINT64 v25;
__int64 v26;
__int64 v27;
__int64 v28;
int v29;
__int64 v30;
void *v31;
UINT64 v32;
UINT8 *v33;
VOID *v34;
WCHAR *v35;
int v36;
int v37;
bool v38;
unsigned __int64 v39;
__int64 v40;
__int64 v41;
INT64 v42;
void *v43;
__int64 v44;
unsigned int v45;
unsigned int v46;
int v47;
size_t Size;
size_t v49;
PVOID v50;
PVOID P;
void *Src;
size_t v53;
char v54;
unsigned int v55;
v55 = a2;
v6 = *(_DWORD *)a1;
PoolWithTag = 0i64;
v53 = 0i64;
v8 = 0;
Size = 0i64;
v9 = 0;
LODWORD(v49) = 0;
P = 0i64;
Src = 0i64;
v50 = 0i64;
v54 = 0;
if( v6 )
{
v10 = v6 - 2;
if( !v10 )
{
LABEL_5:
v13 = BiVerifyBootPartition((int *)a1, 0i64, 0i64, 0i64, 0i64, (unsigned int *)&v49);
if( v13 < 0 )
goto LABEL_87;
v16 = (unsigned int)v49;
if( (r8 & 0x20) != 0 && (_DWORD)v49 )
{
v13 = -1073741823;
goto LABEL_59;
}
BiGetNtPartitionPath(a1, (__m256i *)&Src, v14, v15);
v13 = v17;
if( v17 < 0 )
{
P = Src;
LABEL_59:
if( !(_DWORD)v16 )
goto LABEL_86;
v13 = BiConvertBootEnvironmentDeviceToNt(a1 + v16, v55, 0, (WCHAR **)&v50, &Size);
if( v13 >= 0 )
{
v9 = Size + 34;
HIDWORD(Size) = Size + 34;
PoolWithTag = (size_t)ExAllocatePoolWithTag(PagedPool, (unsigned int)(Size + 34), 0x4B444342ui64);
v53 = PoolWithTag;
if( PoolWithTag )
{
memset(PoolWithTag, 0i64);
*(_DWORD *)PoolWithTag = 8;
*(_DWORD *)(PoolWithTag + 20) = 0;
v36 = 301989890;
if( v55 )
{
if( v55 == 553648129 )
{
v36 = 570425346;
}
else if( v55 == 285212739 )
{
v36 = 301989956;
}
}
*(_DWORD *)(PoolWithTag + 28) = v36;
*(_DWORD *)(PoolWithTag + 24) = 34;
memmove((UINT8 *)(PoolWithTag + 34), (UINT8 *)v50, (unsigned int)Size);
LABEL_86:
if( v13 < 0 )
goto LABEL_87;
LABEL_12:
*a4 = (WCHAR *)PoolWithTag;
*(_DWORD *)a5 = v9;
LABEL_13:
v8 = v54;
goto LABEL_14;
}
goto LABEL_65;
}
LABEL_87:
if( v13 == -1073741670 )
goto LABEL_91;
if( PoolWithTag )
ExFreePoolWithTag((PVOID)PoolWithTag, 0x4B444342u);
LABEL_90:
v47 = BiConvertBootEnvironmentDeviceToUnknown((UINT8 *)a1, (UINT8 **)&v53, (size_t *)((char *)&Size + 4));
v9 = HIDWORD(Size);
v13 = v47;
PoolWithTag = v53;
LABEL_91:
if( v13 < 0 )
goto LABEL_13;
goto LABEL_12;
}
v18 = (UINT8 *)Src;
v19 = -1i64;
P = Src;
v54 = 1;
do
++v19;
while( *((_WORD *)Src + v19) );
v9 = 2 * v19 + 22;
v20 = ExAllocatePoolWithTag(PagedPool, v9, 0x4B444342ui64);
PoolWithTag = (size_t)v20;
if( v20 )
{
memset((INT64)v20, 0i64);
*(_DWORD *)PoolWithTag = 2;
memmove((UINT8 *)(PoolWithTag + 20), v18, (unsigned int)(2 * v19 + 2));
v13 = 0;
goto LABEL_12;
}
LABEL_19:
v13 = -1073741670;
goto LABEL_13;
}
v11 = v10 - 3;
if( !v11 )
{
v9 = 20;
PoolWithTag = (size_t)ExAllocatePoolWithTag(PagedPool, 0x14ui64, 0x4B444342ui64);
if( PoolWithTag )
{
*(_OWORD *)PoolWithTag = 0i64;
*(_DWORD *)(PoolWithTag + 16) = 0;
*(_DWORD *)PoolWithTag = 1;
goto LABEL_26;
}
goto LABEL_25;
}
v12 = v11 - 1;
if( !v12 )
goto LABEL_5;
v22 = v12 - 1;
if( !v22 )
{
v9 = 36;
PoolWithTag = (size_t)ExAllocatePoolWithTag(PagedPool, 0x24ui64, 0x4B444342ui64);
if( PoolWithTag )
{
*(_OWORD *)PoolWithTag = 0i64;
*(_OWORD *)(PoolWithTag + 16) = 0i64;
*(_DWORD *)(PoolWithTag + 32) = 0;
*(_DWORD *)PoolWithTag = 7;
*(_OWORD *)(PoolWithTag + 20) = *(_OWORD *)(a1 + 32);
goto LABEL_26;
}
goto LABEL_25;
}
v23 = v22 - 1;
if( v23 )
{
if( v23 != 1 )
goto LABEL_90;
v9 = *(_DWORD *)(a1 + 16) + 21;
v24 = ExAllocatePoolWithTag(PagedPool, v9, 0x4B444342ui64);
PoolWithTag = (size_t)v24;
if( v24 )
{
memset((INT64)v24, 0i64);
*(_DWORD *)PoolWithTag = 9;
strcpy_s((PSTR)(PoolWithTag + 20), 1ui64, (PSTR)(a1 + 20));
goto LABEL_26;
}
LABEL_25:
v13 = -1073741670;
goto LABEL_14;
}
v25 = 34i64;
v26 = -1i64;
v38 = *(_DWORD *)(a1 + 16) == 1;
v9 = 34;
HIDWORD(Size) = 34;
if( v38 )
{
v27 = -1i64;
do
++v27;
while( *(_WORD *)(a1 + 2 * v27 + 28) );
v9 = 2 * v27 + 34;
HIDWORD(Size) = v9;
v25 = v9;
}
v28 = *(unsigned int *)(a1 + 24);
if( !(_DWORD)v28 )
{
LABEL_44:
v34 = ExAllocatePoolWithTag(PagedPool, v25, 0x4B444342ui64);
PoolWithTag = (size_t)v34;
if( !v34 )
goto LABEL_19;
memset((INT64)v34, 0i64);
*(_DWORD *)PoolWithTag = 8;
if( *(_DWORD *)(a1 + 16) )
{
*(_DWORD *)(PoolWithTag + 20) = 1;
v35 = (WCHAR *)(a1 + 28);
do
++v26;
while( v35[v26] );
wcscpy_s((PWCHAR)(PoolWithTag + 32), v26 + 1, v35);
}
else
{
*(_DWORD *)(PoolWithTag + 20) = 0;
*(_DWORD *)(PoolWithTag + 28) = *(_DWORD *)(a1 + 20);
}
if( v50 )
{
*(_DWORD *)(PoolWithTag + 24) = v28;
memmove((UINT8 *)(PoolWithTag + (unsigned int)v28), (UINT8 *)v50, (unsigned int)Size);
}
LABEL_26:
v13 = 0;
goto LABEL_12;
}
if( (r8 & 0x20) == 0 )
{
BiGetNtPartitionPath(a1, (__m256i *)&Src, (INT64 *)r8, (INT64)a4);
P = Src;
if( v29 >= 0 )
{
v54 = 1;
v30 = -1i64;
do
++v30;
while( *((_WORD *)Src + v30) );
LODWORD(v49) = 2 * v30 + 2;
LODWORD(Size) = 2 * v30 + 22;
v31 = ExAllocatePoolWithTag(PagedPool, (unsigned int)Size, 0x4B444342ui64);
v50 = v31;
if( !v31 )
{
v13 = -1073741670;
LABEL_17:
ExFreePoolWithTag(P, 0x4B444342u);
return(unsigned int)v13;
}
memset((INT64)v31, 0i64);
v32 = (unsigned int)v49;
v33 = (UINT8 *)P;
*(_DWORD *)v50 = 2;
memmove((UINT8 *)v50 + 20, v33, v32);
}
if( v50 )
{
LABEL_43:
LODWORD(v28) = v25;
v9 = v25 + Size;
v25 = (unsigned int)(v25 + Size);
goto LABEL_44;
}
a2 = v55;
}
if( (unsigned int)(*(_DWORD *)(a1 + 8) - v28) < 0x4C )
goto LABEL_90;
v13 = BiConvertBootEnvironmentDeviceToNt(v28 + a1 + 40, a2, 0, (WCHAR **)&v50, &Size);
if( v13 < 0 )
goto LABEL_87;
goto LABEL_43;
}
v37 = *(_DWORD *)(a1 + 16);
if( v37 != 3 && v37 != 5 )
goto LABEL_90;
v38 = v37 == 3;
v39 = *(unsigned int *)(a1 + 8);
v40 = 52i64;
if( !v38 )
v40 = 32i64;
v41 = 36i64;
if( !v38 )
v41 = 16i64;
v42 = v41 + a1 + 16;
if( v39 < v40 + 12 || *(_DWORD *)(v42 + 8) > (unsigned int)(v39 - v40) )
{
v13 = -1073741811;
goto LABEL_86;
}
v13 = BiConvertBootEnvironmentDeviceToNt(v42, a2, 0, (WCHAR **)&v50, &Size);
if( v13 < 0 )
goto LABEL_87;
if( *(_DWORD *)v50 == 3 )
goto LABEL_90;
v43 = (void *)(v42 + *(unsigned int *)(v42 + 8));
P = v43;
v44 = -1i64;
do
++v44;
while( *((_WORD *)v43 + v44) );
v45 = 2 * v44 + 2;
if( v45 + 32 < 0x20 || v45 + 32 + (unsigned int)Size < v45 + 32 )
goto LABEL_90;
v46 = (v45 + 31) & 0xFFFFFFF8;
v53 = (unsigned int)Size + v46;
v9 = Size + v46;
PoolWithTag = (size_t)ExAllocatePoolWithTag(PagedPool, v53, 0x4B444342ui64);
if( PoolWithTag )
{
memset(PoolWithTag, 0i64);
memmove((UINT8 *)(PoolWithTag + 24), (UINT8 *)v43, v45);
*(_DWORD *)(PoolWithTag + 20) = v46;
memmove((UINT8 *)(PoolWithTag + v46), (UINT8 *)v50, (unsigned int)Size);
*(_DWORD *)PoolWithTag = 4 - (*(_DWORD *)(a1 + 16) != 3);
v13 = 0;
goto LABEL_12;
}
LABEL_65:
v13 = -1073741670;
v8 = 0;
LABEL_14:
if( v50 )
ExFreePoolWithTag(v50, 0x4B444342u);
if( v8 )
goto LABEL_17;
return(unsigned int)v13;
}Referenced by:
BiConvertBootEnvironmentDeviceToNt
BiConvertRegistryDataToElement
BiVerifyBootPartition