PspReadDfssConfigurationValues

VOID __stdcall PspReadDfssConfigurationValues(){
  NTSTATUS v0; 
  INT64(__fastcall *v1)(_WORD *, INT64, INT64); 
  __int64 v2; 
  int ImageFileKeyOption; 
  CHAR v4; 
  WCHAR *v5; 
  PIO_APC_ROUTINE v6; 
  void *v7; 
  PIO_STATUS_BLOCK IoStatusBlock; 
  BOOL WatchTree; 
  BOOL Asynchronous; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  void *KeyHandle; 
  KeyHandle = 0i64;
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  if( *(_QWORD *)PspDfssConfigurationKey )
  {
    v0 = 0;
    KeyHandle = *(void **)PspDfssConfigurationKey;
  }
  else
  {
    ObjectAttributes.Length = 48;
    ObjectAttributes.ObjectName = (_UNICODE_STRING *)PspQuotaKeyNames;
    ObjectAttributes.RootDirectory = 0i64;
    ObjectAttributes.Attributes = 576;
    *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
    v0 = ZwOpenKey(&KeyHandle, 0x11u, &ObjectAttributes);
  }
  if( v0 >= 0 )
  {
    v1 = PspDfssConfigValues;
    v2 = 4i64;
    do
    {
      LODWORD(IoStatusBlock) = 4;
      ImageFileKeyOption = RtlQueryImageFileKeyOption(
                             KeyHandle,
                             *((const WCHAR **)v1 + 1),
                             4ui64,
                             *(VOID **)v1,
                             (UINT64)IoStatusBlock,
                             0i64);
      v5 = *(WCHAR **)v1;
      if( ImageFileKeyOption >= 0 )
      {
        if( !*(_DWORD *)v5 )
          *(_DWORD *)v5 = 1;
      }
      else
      {
        *(_DWORD *)v5 = *((_DWORD *)v1 + 4);
      }
      v1 = (INT64(__fastcall *)(_WORD *, INT64, INT64))((char *)v1 + 24);
      --v2;
    }
    while( v2 );
    if( PspDfssConfigurationNotify )
    {
      KeUpdateGroupSchedulingConstants(0i64, v4);
    }
    else
    {
      PspDfssConfigurationNotify = (PIO_APC_ROUTINE)ExAllocatePoolWithTag(NonPagedPoolNx, 0x30ui64, 0x73736644ui64);
      if( !PspDfssConfigurationNotify )
      {
        ZwClose(KeyHandle);
        return;
      }
      *(_QWORD *)PspDfssConfigurationKey = KeyHandle;
    }
    v6 = PspDfssConfigurationNotify;
    v7 = *(void **)PspDfssConfigurationKey;
    LOBYTE(Asynchronous) = 1;
    *((_QWORD *)PspDfssConfigurationNotify + 2) = PspDfssConfigurationChangeHandler;
    LOBYTE(WatchTree) = 0;
    *((_QWORD *)v6 + 3) = 0i64;
    *(_QWORD *)v6 = 0i64;
    if( ZwNotifyChangeKey(v7, 0i64, v6, (PVOID)1, (PIO_STATUS_BLOCK)v6 + 2, 4u, WatchTree, 0i64, 0, Asynchronous) < 0 )
    {
      ZwClose(PspDfssConfigurationKey);
      *(_QWORD *)PspDfssConfigurationKey = 0i64;
      ExFreePoolWithTag(PspDfssConfigurationNotify, 0x73736644u);
      PspDfssConfigurationNotify = 0i64;
    }
  }
}

Referenced by:

PspDfssConfigurationChangeHandler
PspIsDfssEnabled