IopCreateArcNamesCd

HANDLE __stdcall IopCreateArcNamesCd(PVOID Address, SIZE_T Size, ULONG ProbeMode){
  WCHAR **v3; 
  int v4; 
  ULONG CdRomCount; 
  int ConfigurationInformation; 
  WCHAR *v8; 
  char v9; 
  const WCHAR *v10; 
  WCHAR *v11; 
  __int64 v12; 
  unsigned __int8 *v13; 
  __int64 v14; 
  WCHAR *v15; 
  int v16; 
  int v17; 
  CHAR *Pool_1; 
  WCHAR v20; 
  ULONG v21; 
  int v22; 
  bool v23; 
  int v24; 
  __int64 v25; 
  NTSTATUS DeviceObjectPointer; 
  _DEVICE_OBJECT *v27; 
  _IRP *v28; 
  INT8 v29; 
  INT8 v30; 
  IRP *v31; 
  NTSTATUS Status; 
  unsigned __int64 v33; 
  __m128i v34; 
  __m128i v35; 
  __m128i v36; 
  __m128i v37; 
  int v38; 
  INT8 v39; 
  PKEVENT Event; 
  UINT64 Object; 
  _KEVENT Object_8; 
  WCHAR *P[3]; 
  PDEVICE_OBJECT DeviceObject; 
  PFILE_OBJECT FileObject; 
  struct _STRING DestinationString; 
  struct _IO_STATUS_BLOCK IoStatusBlock; 
  union _LARGE_INTEGER StartingOffset[2]; 
  PVOID v49; 
  struct _UNICODE_STRING SymbolicLinkName; 
  STRING v51; 
  union _LARGE_INTEGER OutputBuffer; 
  int v53; 
  char pszDest[128]; 
  char SourceString[128]; 
  PVOID ReturnAddress; 
  v3 = (WCHAR **)*((_QWORD *)Address + 29);
  v49 = Address;
  v4 = 0;
  DestinationString = 0i64;
  DeviceObject = 0i64;
  FileObject = 0i64;
  v51 = 0i64;
  SymbolicLinkName = 0i64;
  LODWORD(Object) = 0;
  IoStatusBlock = 0i64;
  memset(&Object_8, 0, sizeof(Object_8));
  memset(P, 0, sizeof(P));
  CdRomCount = IoGetConfigurationInformation()->CdRomCount;
  OutputBuffer.QuadPart = 0i64;
  v53 = 0;
  *(GUID *)&StartingOffset[0].LowPart = GUID_DEVINTERFACE_CDROM;
  ConfigurationInformation = IopFetchConfigurationInformation(P, (GUID *)StartingOffset, CdRomCount, &Object);
  v8 = P[0];
  v9 = 0;
  v10 = P[0];
  if( ConfigurationInformation < 0 )
    v9 = 1;
  v11 = *v3;
  if( *v3 == (WCHAR *)v3 )
    goto LABEL_11;
  v12 = *((_QWORD *)Address + 23);
  do
  {
    v13 = (unsigned __int8 *)*((_QWORD *)v11 + 3);
    v14 = v12 - (_QWORD)v13;
    P[0] = v11;
    v15 = v11;
    do
    {
      v16 = v13[v14];
      v17 = *v13 - v16;
      if( v17 )
        break;
      ++v13;
    }
    while( v16 );
    if( !v17 )
      break;
    v11 = *(WCHAR **)v11;
    v15 = 0i64;
    P[0] = 0i64;
  }
  while( v11 != (WCHAR *)v3 );
  if( !v15 )
    goto LABEL_11;
  Pool_1 = IopVerifierExAllocatePool_1(NonPagedPoolNxCacheAligned, 0x800ui64);
  if( !Pool_1 )
    goto LABEL_11;
  v21 = Object;
  v22 = 0;
  v23 = (unsigned int)Object <= CdRomCount;
  LODWORD(Object) = 0;
  if( !v23 )
    CdRomCount = v21;
  if( v9 && !v21 )
    CdRomCount += 5;
  v24 = 0;
  if( !CdRomCount )
    goto LABEL_54;
  while( 1 )
  {
    if( v10 && *v10 )
    {
      RtlInitUnicodeString((PUNICODE_STRING)&P[1], v10, v20);
      v25 = -1i64;
      do
        ++v25;
      while( v10[v25] );
      v10 += v25 + 1;
      DeviceObjectPointer = IoGetDeviceObjectPointer((UNICODE_STRING *)&P[1], 0x80ui64, &FileObject, &DeviceObject);
      if( DeviceObjectPointer < 0 )
        goto LABEL_45;
      v27 = DeviceObject;
      LODWORD(Event) = 12;
      v28 = IopBuildDeviceIoControlRequest(
              0x2D1080ui64,
              DeviceObject,
              0i64,
              0i64,
              &OutputBuffer,
              (UINT64)Event,
              0,
              &Object_8,
              &IoStatusBlock,
              ReturnAddress);
      if( !v28 )
        goto LABEL_57;
      LOWORD(Object_8.Header.Lock) = 0;
      Object_8.Header.WaitListHead.Blink = &Object_8.Header.WaitListHead;
      Object_8.Header.Size = 6;
      Object_8.Header.WaitListHead.Flink = &Object_8.Header.WaitListHead;
      Object_8.Header.SignalState = 0;
      DeviceObjectPointer = IofCallDriver(v27, v28);
      if( DeviceObjectPointer == 259 )
      {
        KeWaitForSingleObject(&Object_8, Executive, 0, 0, 0i64);
        DeviceObjectPointer = IoStatusBlock.Status;
      }
      if( DeviceObjectPointer < 0
        || (RtlStringCchPrintfA(pszDest, 0x80ui64, (INT8 *)"\\Device\\CdRom%d"),
            RtlInitAnsiString(&DestinationString, pszDest, v29),
            DeviceObjectPointer = RtlAnsiStringToUnicodeString((UNICODE_STRING *)&P[1], &DestinationString, 1u),
            DeviceObjectPointer < 0) )
      {
LABEL_45:
        if( v8 )
          ExFreePoolWithTag(v8, 0);
        goto LABEL_48;
      }
      v24 = 0;
    }
    else
    {
      RtlStringCchPrintfA(pszDest, 0x80ui64, (INT8 *)"\\Device\\CdRom%d");
      LODWORD(Object) = v22 + 1;
      RtlInitAnsiString(&DestinationString, pszDest, v30);
      if( RtlAnsiStringToUnicodeString((UNICODE_STRING *)&P[1], &DestinationString, 1u) < 0 )
      {
LABEL_57:
        if( v8 )
          ExFreePoolWithTag(v8, 0);
        DeviceObjectPointer = -1073741670;
LABEL_48:
        ExFreePoolWithTag(Pool_1, 0);
        return(HANDLE)(unsigned int)DeviceObjectPointer;
      }
      if( IoGetDeviceObjectPointer((UNICODE_STRING *)&P[1], 0x80ui64, &FileObject, &DeviceObject) < 0 )
        goto LABEL_53;
      v27 = DeviceObject;
    }
    StartingOffset[0].QuadPart = 0x8000i64;
    v31 = IoBuildSynchronousFsdRequest(3u, v27, Pool_1, 0x800u, StartingOffset, &Object_8, &IoStatusBlock);
    if( v31 )
    {
      LOWORD(Object_8.Header.Lock) = 0;
      Object_8.Header.SignalState = 0;
      Object_8.Header.WaitListHead.Blink = &Object_8.Header.WaitListHead;
      Object_8.Header.WaitListHead.Flink = &Object_8.Header.WaitListHead;
      Object_8.Header.Size = 6;
      Status = IofCallDriver(v27, v31);
      if( Status == 259 )
      {
        KeWaitForSingleObject(&Object_8, Executive, 0, 0, 0i64);
        Status = IoStatusBlock.Status;
      }
      if( Status >= 0 )
      {
        v33 = 0i64;
        v34 = 0i64;
        do
        {
          v35 = _mm_loadu_si128((const __m128i *)&Pool_1[4 * v33]);
          v33 += 4i64;
          v36 = _mm_add_epi32(v35, v34);
          v34 = v36;
        }
        while( v33 < 0x200 );
        v37 = _mm_add_epi32(v36, _mm_srli_si128(v36, 8));
        v24 = _mm_cvtsi128_si32(_mm_add_epi32(v37, _mm_srli_si128(v37, 4)));
      }
    }
    ObfDereferenceObjectWithTag(FileObject, 0x746C6644ui64);
    v38 = v24 + *((_DWORD *)P[0] + 8);
    v24 = 0;
    if( !v38 )
      break;
    RtlFreeAnsiString((_UNICODE_STRING *)&P[1]);
    if( ++v4 >= CdRomCount )
      goto LABEL_54;
    v22 = Object;
  }
  RtlStringCchPrintfA(SourceString, 0x80ui64, (INT8 *)"\\ArcName\\%s");
  RtlInitAnsiString(&v51, SourceString, v39);
  DeviceObjectPointer = RtlAnsiStringToUnicodeString(&SymbolicLinkName, &v51, 1u);
  if( DeviceObjectPointer < 0 )
  {
    ExFreePoolWithTag(Pool_1, 0);
    if( v8 )
      ExFreePoolWithTag(v8, 0);
    RtlFreeAnsiString((_UNICODE_STRING *)&P[1]);
    return(HANDLE)(unsigned int)DeviceObjectPointer;
  }
  IoCreateSymbolicLink(&SymbolicLinkName, (_UNICODE_STRING *)&P[1]);
  RtlFreeAnsiString(&SymbolicLinkName);
LABEL_53:
  RtlFreeAnsiString((_UNICODE_STRING *)&P[1]);
LABEL_54:
  ExFreePoolWithTag(Pool_1, 0);
LABEL_11:
  if( v8 )
    ExFreePoolWithTag(v8, 0);
  return 0i64;
}

Referenced by:

IopCreateArcNames