CmGetSystemDriverList
VOID **__fastcall CmGetSystemDriverList(const WCHAR *ManufacturingProfileName){
char v1;
UNICODE_STRING *v2;
VOID **v3;
char v4;
bool v5;
WCHAR v6;
NTSTATUS v7;
UNICODE_STRING *j;
PVOID *i;
_LIST_ENTRY *Flink;
int v11;
_LIST_ENTRY *v12;
int v13;
PVOID **v14;
_LIST_ENTRY *v15;
NTSTATUS v17;
_DWORD *v18;
_DWORD *v19;
PVOID *v20;
_LIST_ENTRY *v21;
_LIST_ENTRY *v22;
_LIST_ENTRY *Blink;
PVOID *v24;
_LIST_ENTRY *v25;
_UNICODE_STRING *Context;
const WCHAR *ReturnLength;
_LIST_ENTRY Flags;
PVOID P;
PVOID *p_P;
UINT64 v31;
_LIST_ENTRY v32;
void *DirectoryHandle;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
const WCHAR *v35;
UNICODE_STRING *PoolWithTag;
struct _UNICODE_STRING DestinationString;
INT64 result[6];
ULONG_PTR BugCheckParameter3;
INT64 ControlSet;
INT64 v41[4];
__int64 v42;
_CM_SERVICE_LOAD_TYPE LoadType[2];
WCHAR *BootFileSystem;
KAPC_STATE ApcState;
v35 = ManufacturingProfileName;
v31 = 0i64;
v1 = 0;
DestinationString = 0i64;
memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
memset(&ApcState, 0, sizeof(ApcState));
memset((INT64)result, 0i64);
LODWORD(ControlSet) = -1;
memset((INT64)v41, 0i64);
LODWORD(BootFileSystem) = -1;
p_P = &P;
DirectoryHandle = 0i64;
P = &P;
v2 = 0i64;
v32.Blink = &v32;
v3 = 0i64;
v4 = 0;
v32.Flink = &v32;
v5 = 0;
Flags.Blink = &Flags;
Flags.Flink = &Flags;
if( CmpOpenSystemDriverHiveContext(&CmpSystemHiveNameString) >= 0 )
{
if( !CmStateSeparationEnabled
|| (v17 = CmpOpenSystemDriverHiveContext(&CmpDevicesHiveNameString), (int)(v17 + 0x80000000) < 0)
|| v17 == -1073741772 )
{
RtlInitUnicodeString(&DestinationString, L"\\DriverStores", v6);
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = &DestinationString;
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwOpenDirectoryObject(&DirectoryHandle, 1ui64, &ObjectAttributes) >= 0 )
{
PoolWithTag = (UNICODE_STRING *)ExAllocatePoolWithTag(PagedPool, 0x400ui64, 0x20204D43ui64);
v2 = PoolWithTag;
if( PoolWithTag )
{
v7 = ZwQueryDirectoryObject(
DirectoryHandle,
PoolWithTag,
0x400ui64,
1u,
1u,
(UINT64 *)((char *)&v31 + 4),
&v31);
if( v7 == -2147483622 )
{
LABEL_11:
v5 = CmpAcquireShutdownRundown();
if( v5 )
{
CmpAttachToRegistryProcess(&ApcState);
v1 = 1;
CmpLockRegistryExclusive();
v4 = 1;
if( (int)CmpAcquireSystemDriverHiveContext((INT64)result) >= 0
&& (!v42 || (int)CmpAcquireSystemDriverHiveContext((INT64)v41) >= 0) )
{
for( i = (PVOID *)P; i != &P; i = (PVOID *)*i )
{
if( (int)CmpAcquireSystemDriverHiveContext((INT64)i) >= 0 )
{
v21 = (_LIST_ENTRY *)ExAllocatePoolWithTag(PagedPool, 0x30ui64, 0x20204D43ui64);
v22 = v21;
if( !v21 )
goto LABEL_28;
*v21 = 0i64;
v21[1] = 0i64;
v21[2] = 0i64;
v21[1] = *((_LIST_ENTRY *)i + 1);
v21[2].Flink = (_LIST_ENTRY *)i[6];
LODWORD(v21[2].Blink) = *((_DWORD *)i + 14);
Blink = v32.Blink;
if( v32.Blink->Flink != &v32 )
goto LABEL_60;
v22->Blink = v32.Blink;
v22->Flink = &v32;
Blink->Flink = v22;
v32.Blink = v22;
}
}
if( (unsigned __int8)CmpFindDrivers(
(_HHIVE *)BugCheckParameter3,
(unsigned int)ControlSet,
LoadType[0],
(WCHAR *)(unsigned int)BootFileSystem,
&v32,
Context,
ReturnLength,
(UINT64 *)&Flags)
&& (unsigned __int8)CmpSortDriverList((_HHIVE *)BugCheckParameter3, (unsigned int)ControlSet, &Flags) )
{
CmpUnlockRegistry();
Flink = Flags.Flink;
v11 = 0;
v4 = 0;
while( Flink != &Flags )
{
Flink = Flink->Flink;
++v11;
}
v3 = (VOID **)ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * (unsigned int)(v11 + 1), 0x32384D43ui64);
if( !v3 )
KeBugCheckEx(0x67u, 2ui64, 1ui64, 0i64, 0i64);
v12 = Flags.Flink;
v13 = 0;
if( Flags.Flink != &Flags )
{
do
{
ObjectAttributes.Length = 48;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)&v12[2];
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.Attributes = 576;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwOpenKey(&v3[v13], 0x2001Fu, &ObjectAttributes) >= 0 )
++v13;
v12 = v12->Flink;
}
while( v12 != &Flags );
v2 = PoolWithTag;
}
v3[v13] = 0i64;
}
}
}
}
else
{
while( v7 >= 0 )
{
for( j = v2; j->Length; j += 2 )
{
if( !RtlEqualUnicodeString(j, &CmpSystemFileName, 1u) )
{
v18 = ExAllocatePoolWithTag(PagedPool, 0x40ui64, 0x20204D43ui64);
v19 = v18;
if( !v18 )
goto LABEL_28;
memset((INT64)v18, 0i64);
v19[14] = -1;
if( CmpOpenSystemDriverHiveContext(j) >= 0 )
{
v20 = p_P;
if( *p_P != &P )
LABEL_60:
__fastfail(3u);
*((_QWORD *)v19 + 1) = p_P;
*(_QWORD *)v19 = &P;
*v20 = v19;
p_P = (PVOID *)v19;
}
else
{
ExFreePoolWithTag(v19, 0);
}
}
}
v7 = ZwQueryDirectoryObject(DirectoryHandle, v2, 0x400ui64, 1u, 0, (UINT64 *)((char *)&v31 + 4), &v31);
if( v7 == -2147483622 )
goto LABEL_11;
}
}
}
}
}
}
LABEL_28:
if( Flags.Flink != &Flags )
CmpFreeDriverList((_HHIVE *)BugCheckParameter3, &Flags);
if( v4 )
CmpUnlockRegistry();
if( v1 )
CmpDetachFromRegistryProcess(&ApcState);
if( v5 )
CmpReleaseShutdownRundown();
CmpCloseSystemDriverHiveContext((INT64)result);
if( v42 )
CmpCloseSystemDriverHiveContext((INT64)v41);
if( DirectoryHandle )
ZwClose(DirectoryHandle);
if( v2 )
ExFreePoolWithTag(v2, 0);
v14 = (PVOID **)P;
if( P != &P )
{
do
{
v24 = *v14;
CmpCloseSystemDriverHiveContext((INT64)v14);
ExFreePoolWithTag(v14, 0);
v14 = (PVOID **)v24;
}
while( v24 != &P );
}
v15 = v32.Flink;
if( v32.Flink != &v32 )
{
do
{
v25 = v15->Flink;
ExFreePoolWithTag(v15, 0);
v15 = v25;
}
while( v25 != &v32 );
}
return v3;
}Referenced by:
IopInitializeSystemDrivers