CmKeyBodyRemapToVirtualForEnum

__int64 __fastcall CmKeyBodyRemapToVirtualForEnum(__int64 *a1, char a2, DWORD a3, __int64 *a4){
  DWORD v4; 
  WCHAR v8; 
  __int64 v9; 
  char v10; 
  UINT64 v11; 
  int AccessStateFromSubjectContext; 
  _UNICODE_STRING *v14; 
  __int64 v15; 
  int v16; 
  __int64 v17; 
  int v18; 
  char v19; 
  DWORD v20[3]; 
  struct _UNICODE_STRING DestinationString; 
  struct _SECURITY_SUBJECT_CONTEXT SubjectContext; 
  int v23[2]; 
  __int64 v24; 
  struct _UNICODE_STRING *p_DestinationString; 
  int v26; 
  int v27; 
  __int128 v28; 
  INT64 v29[12]; 
  int v30; 
  _QWORD v31[9]; 
  __int128 v32; 
  __int128 v33; 
  __int128 v34; 
  __int128 v35; 
  __int128 v36; 
  KAPC_STATE ApcState; 
  struct _SECURITY_SUBJECT_CONTEXT result[5]; 
  __int64 v39[28]; 
  v4 = a3;
  v20[0] = a3;
  DestinationString = 0i64;
  memset((INT64)result, 0i64);
  memset((INT64)v39, 0i64);
  v23[1] = 0;
  v27 = 0;
  RtlInitUnicodeString(&DestinationString, 0i64, v8);
  v9 = *a1;
  *(_QWORD *)&v20[1] = 0i64;
  memset(&ApcState, 0, sizeof(ApcState));
  memset((INT64)v29, 0i64);
  v30 = -1;
  *a4 = 0i64;
  v31[1] = v31;
  v10 = 0;
  v32 = 0i64;
  v19 = 0;
  v31[0] = v31;
  v33 = 0i64;
  v34 = 0i64;
  v35 = 0i64;
  v36 = 0i64;
  v11 = *(_QWORD *)(v9 + 8);
  memset(&SubjectContext, 0, sizeof(SubjectContext));
  if( !*(_WORD *)(v11 + 66) && (*(_DWORD *)(v9 + 48) & 0x10) == 0 )
  {
    if( KCBIsVirtualizable(v11) )
    {
      v10 = 1;
      goto LABEL_5;
    }
    if( CmpVEEnabled && (*(_DWORD *)(v11 + 184) & 0x1000000) != 0 )
    {
      v19 = 1;
LABEL_5:
      SeCaptureSubjectContext(&SubjectContext);
      if( CmpIsSystemEntity((UINT64 *)(unsigned __int8)a2) )
      {
        AccessStateFromSubjectContext = 0;
LABEL_7:
        SeReleaseSubjectContext(&SubjectContext);
        goto LABEL_8;
      }
      if( v10 && (*(_DWORD *)(v11 + 184) & 0x800000) == 0 )
      {
        AccessStateFromSubjectContext = 0;
        goto LABEL_7;
      }
      CmpAttachToRegistryProcess(&ApcState);
      CmpLockRegistry();
      CmpLockKcbShared((_CM_KEY_CONTROL_BLOCK *)v11);
      if( v10 )
      {
        AccessStateFromSubjectContext = CmpPerformKeyBodyDeletionCheck(v9, 0i64);
        if( AccessStateFromSubjectContext < 0 )
        {
LABEL_32:
          CmpUnlockKcb(v11);
          CmpUnlockRegistry();
LABEL_38:
          CmpDetachFromRegistryProcess(&ApcState);
          goto LABEL_7;
        }
        if( (unsigned __int8)CmpReparseToVirtualPath(
                                (_CM_KEY_CONTROL_BLOCK *)v11,
                                v14,
                                (_UNICODE_STRING *)&SubjectContext) )
        {
          v4 = v20[0];
          goto LABEL_22;
        }
      }
      else if( CmVirtualKCBToRealPath((_CM_KEY_CONTROL_BLOCK *)v11, &DestinationString) >= 0 )
      {
LABEL_22:
        CmpUnlockKcb(v11);
        CmpUnlockRegistry();
        v15 = *a1;
        v16 = 8;
        LODWORD(v29[0]) = 8;
        if( !v4 )
          v16 = 4104;
        v29[9] = *(_QWORD *)(v15 + 56);
        LODWORD(v29[0]) = v16;
        AccessStateFromSubjectContext = SeCreateAccessStateFromSubjectContext(
                                          (INT64)&SubjectContext,
                                          (INT64)result,
                                          (INT64)v39,
                                          v4,
                                          (GENERIC_MAPPING *)((char *)CmKeyObjectType + 76));
        if( AccessStateFromSubjectContext < 0 )
          goto LABEL_38;
        v18 = 1600;
        v23[0] = 48;
        v24 = 0i64;
        v28 = 0i64;
        if( a2 != 1 )
          v18 = 576;
        v26 = v18;
        p_DestinationString = &DestinationString;
        AccessStateFromSubjectContext = CmObReferenceObjectByName(
                                          (__int64)v23,
                                          result,
                                          v20[0],
                                          v17,
                                          0,
                                          (__int64)v29,
                                          &v20[1]);
        if( AccessStateFromSubjectContext >= 0 )
        {
          if( v10 )
          {
            *a4 = *(_QWORD *)&v20[1];
          }
          else
          {
            *a1 = *(_QWORD *)&v20[1];
            *a4 = v9;
          }
        }
        else if( !v19 )
        {
          goto LABEL_37;
        }
        AccessStateFromSubjectContext = 0;
LABEL_37:
        SeDeleteAccessState((_ACCESS_STATE *)result);
        goto LABEL_38;
      }
      AccessStateFromSubjectContext = 0;
      goto LABEL_32;
    }
  }
  AccessStateFromSubjectContext = 0;
LABEL_8:
  if( DestinationString.Buffer )
    ExFreePoolWithTag(DestinationString.Buffer, 0);
  CmpCleanupParseContext((__int64)v29, 0);
  return(unsigned int)AccessStateFromSubjectContext;
}

Referenced by:

NtEnumerateKey
NtEnumerateValueKey
NtQueryKey
NtQueryMultipleValueKey
NtQueryValueKey