IopAppendLegacyVeto

char __fastcall IopAppendLegacyVeto(const void ***a1, const void **a2){
  unsigned int v3; 
  UINT8 *PoolWithTag; 
  UINT8 *v6; 
  const void **v7; 
  UINT8 *v8; 
  char result; 
  v3 = *(unsigned __int16 *)a2 + 2 + *((_DWORD *)a1 + 2);
  PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(NonPagedPoolNx, v3, 0x6F697050ui64);
  v6 = PoolWithTag;
  if( PoolWithTag )
  {
    v7 = *a1;
    v8 = (UINT8 *)**a1;
    if( v8 )
    {
      memmove(PoolWithTag, v8, *((unsigned int *)a1 + 2));
      ExFreePoolWithTag((PVOID)*v7, 0);
      v7 = *a1;
    }
    memmove(&v6[2 * ((unsigned __int64)*((unsigned int *)a1 + 2) >> 1)], (UINT8 *)a2[1], *(unsigned __int16 *)a2);
    result = 1;
    *((_DWORD *)a1 + 2) = v3;
    *(_WORD *)&v6[2 * ((unsigned __int64)v3 >> 1) - 2] = 0;
    *v7 = v6;
  }
  else
  {
    *(_DWORD *)a1[3] = -1073741670;
    return 0;
  }
  return result;
}

Referenced by:

IoGetLegacyVetoList
IopGetLegacyVetoListDeviceNode
IopGetLegacyVetoListDrivers