IopAppendLegacyVeto
char __fastcall IopAppendLegacyVeto(const void ***a1, const void **a2){
unsigned int v3;
UINT8 *PoolWithTag;
UINT8 *v6;
const void **v7;
UINT8 *v8;
char result;
v3 = *(unsigned __int16 *)a2 + 2 + *((_DWORD *)a1 + 2);
PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(NonPagedPoolNx, v3, 0x6F697050ui64);
v6 = PoolWithTag;
if( PoolWithTag )
{
v7 = *a1;
v8 = (UINT8 *)**a1;
if( v8 )
{
memmove(PoolWithTag, v8, *((unsigned int *)a1 + 2));
ExFreePoolWithTag((PVOID)*v7, 0);
v7 = *a1;
}
memmove(&v6[2 * ((unsigned __int64)*((unsigned int *)a1 + 2) >> 1)], (UINT8 *)a2[1], *(unsigned __int16 *)a2);
result = 1;
*((_DWORD *)a1 + 2) = v3;
*(_WORD *)&v6[2 * ((unsigned __int64)v3 >> 1) - 2] = 0;
*v7 = v6;
}
else
{
*(_DWORD *)a1[3] = -1073741670;
return 0;
}
return result;
}Referenced by:
IoGetLegacyVetoList
IopGetLegacyVetoListDeviceNode
IopGetLegacyVetoListDrivers