CmGetSystemDriverList

VOID **__fastcall CmGetSystemDriverList(const WCHAR *ManufacturingProfileName){
  char v1; 
  UNICODE_STRING *v2; 
  VOID **v3; 
  char v4; 
  bool v5; 
  WCHAR v6; 
  NTSTATUS v7; 
  UNICODE_STRING *j; 
  PVOID *i; 
  _LIST_ENTRY *Flink; 
  int v11; 
  _LIST_ENTRY *v12; 
  int v13; 
  PVOID **v14; 
  _LIST_ENTRY *v15; 
  NTSTATUS v17; 
  _DWORD *v18; 
  _DWORD *v19; 
  PVOID *v20; 
  _LIST_ENTRY *v21; 
  _LIST_ENTRY *v22; 
  _LIST_ENTRY *Blink; 
  PVOID *v24; 
  _LIST_ENTRY *v25; 
  _UNICODE_STRING *Context; 
  const WCHAR *ReturnLength; 
  _LIST_ENTRY Flags; 
  PVOID P; 
  PVOID *p_P; 
  UINT64 v31; 
  _LIST_ENTRY v32; 
  void *DirectoryHandle; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  const WCHAR *v35; 
  UNICODE_STRING *PoolWithTag; 
  struct _UNICODE_STRING DestinationString; 
  INT64 result[6]; 
  ULONG_PTR BugCheckParameter3; 
  INT64 ControlSet; 
  INT64 v41[4]; 
  __int64 v42; 
  _CM_SERVICE_LOAD_TYPE LoadType[2]; 
  WCHAR *BootFileSystem; 
  KAPC_STATE ApcState; 
  v35 = ManufacturingProfileName;
  v31 = 0i64;
  v1 = 0;
  DestinationString = 0i64;
  memset(&ObjectAttributes, 0, sizeof(ObjectAttributes));
  memset(&ApcState, 0, sizeof(ApcState));
  memset((INT64)result, 0i64);
  LODWORD(ControlSet) = -1;
  memset((INT64)v41, 0i64);
  LODWORD(BootFileSystem) = -1;
  p_P = &P;
  DirectoryHandle = 0i64;
  P = &P;
  v2 = 0i64;
  v32.Blink = &v32;
  v3 = 0i64;
  v4 = 0;
  v32.Flink = &v32;
  v5 = 0;
  Flags.Blink = &Flags;
  Flags.Flink = &Flags;
  if( CmpOpenSystemDriverHiveContext(&CmpSystemHiveNameString) >= 0 )
  {
    if( !CmStateSeparationEnabled
      || (v17 = CmpOpenSystemDriverHiveContext(&CmpDevicesHiveNameString), (int)(v17 + 0x80000000) < 0)
      || v17 == -1073741772 )
    {
      RtlInitUnicodeString(&DestinationString, L"\\DriverStores", v6);
      ObjectAttributes.Length = 48;
      ObjectAttributes.ObjectName = &DestinationString;
      ObjectAttributes.RootDirectory = 0i64;
      ObjectAttributes.Attributes = 576;
      *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
      if( ZwOpenDirectoryObject(&DirectoryHandle, 1ui64, &ObjectAttributes) >= 0 )
      {
        PoolWithTag = (UNICODE_STRING *)ExAllocatePoolWithTag(PagedPool, 0x400ui64, 0x20204D43ui64);
        v2 = PoolWithTag;
        if( PoolWithTag )
        {
          v7 = ZwQueryDirectoryObject(
                 DirectoryHandle,
                 PoolWithTag,
                 0x400ui64,
                 1u,
                 1u,
                 (UINT64 *)((char *)&v31 + 4),
                 &v31);
          if( v7 == -2147483622 )
          {
LABEL_11:
            v5 = CmpAcquireShutdownRundown();
            if( v5 )
            {
              CmpAttachToRegistryProcess(&ApcState);
              v1 = 1;
              CmpLockRegistryExclusive();
              v4 = 1;
              if( (int)CmpAcquireSystemDriverHiveContext((INT64)result) >= 0
                && (!v42 || (int)CmpAcquireSystemDriverHiveContext((INT64)v41) >= 0) )
              {
                for( i = (PVOID *)P; i != &P; i = (PVOID *)*i )
                {
                  if( (int)CmpAcquireSystemDriverHiveContext((INT64)i) >= 0 )
                  {
                    v21 = (_LIST_ENTRY *)ExAllocatePoolWithTag(PagedPool, 0x30ui64, 0x20204D43ui64);
                    v22 = v21;
                    if( !v21 )
                      goto LABEL_28;
                    *v21 = 0i64;
                    v21[1] = 0i64;
                    v21[2] = 0i64;
                    v21[1] = *((_LIST_ENTRY *)i + 1);
                    v21[2].Flink = (_LIST_ENTRY *)i[6];
                    LODWORD(v21[2].Blink) = *((_DWORD *)i + 14);
                    Blink = v32.Blink;
                    if( v32.Blink->Flink != &v32 )
                      goto LABEL_60;
                    v22->Blink = v32.Blink;
                    v22->Flink = &v32;
                    Blink->Flink = v22;
                    v32.Blink = v22;
                  }
                }
                if( (unsigned __int8)CmpFindDrivers(
                                        (_HHIVE *)BugCheckParameter3,
                                        (unsigned int)ControlSet,
                                        LoadType[0],
                                        (WCHAR *)(unsigned int)BootFileSystem,
                                        &v32,
                                        Context,
                                        ReturnLength,
                                        (UINT64 *)&Flags)
                  && (unsigned __int8)CmpSortDriverList((_HHIVE *)BugCheckParameter3, (unsigned int)ControlSet, &Flags) )
                {
                  CmpUnlockRegistry();
                  Flink = Flags.Flink;
                  v11 = 0;
                  v4 = 0;
                  while( Flink != &Flags )
                  {
                    Flink = Flink->Flink;
                    ++v11;
                  }
                  v3 = (VOID **)ExAllocatePoolWithTag(NonPagedPoolNx, 8i64 * (unsigned int)(v11 + 1), 0x32384D43ui64);
                  if( !v3 )
                    KeBugCheckEx(0x67u, 2ui64, 1ui64, 0i64, 0i64);
                  v12 = Flags.Flink;
                  v13 = 0;
                  if( Flags.Flink != &Flags )
                  {
                    do
                    {
                      ObjectAttributes.Length = 48;
                      ObjectAttributes.ObjectName = (_UNICODE_STRING *)&v12[2];
                      ObjectAttributes.RootDirectory = 0i64;
                      ObjectAttributes.Attributes = 576;
                      *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
                      if( ZwOpenKey(&v3[v13], 0x2001Fu, &ObjectAttributes) >= 0 )
                        ++v13;
                      v12 = v12->Flink;
                    }
                    while( v12 != &Flags );
                    v2 = PoolWithTag;
                  }
                  v3[v13] = 0i64;
                }
              }
            }
          }
          else
          {
            while( v7 >= 0 )
            {
              for( j = v2; j->Length; j += 2 )
              {
                if( !RtlEqualUnicodeString(j, &CmpSystemFileName, 1u) )
                {
                  v18 = ExAllocatePoolWithTag(PagedPool, 0x40ui64, 0x20204D43ui64);
                  v19 = v18;
                  if( !v18 )
                    goto LABEL_28;
                  memset((INT64)v18, 0i64);
                  v19[14] = -1;
                  if( CmpOpenSystemDriverHiveContext(j) >= 0 )
                  {
                    v20 = p_P;
                    if( *p_P != &P )
LABEL_60:
                      __fastfail(3u);
                    *((_QWORD *)v19 + 1) = p_P;
                    *(_QWORD *)v19 = &P;
                    *v20 = v19;
                    p_P = (PVOID *)v19;
                  }
                  else
                  {
                    ExFreePoolWithTag(v19, 0);
                  }
                }
              }
              v7 = ZwQueryDirectoryObject(DirectoryHandle, v2, 0x400ui64, 1u, 0, (UINT64 *)((char *)&v31 + 4), &v31);
              if( v7 == -2147483622 )
                goto LABEL_11;
            }
          }
        }
      }
    }
  }
LABEL_28:
  if( Flags.Flink != &Flags )
    CmpFreeDriverList((_HHIVE *)BugCheckParameter3, &Flags);
  if( v4 )
    CmpUnlockRegistry();
  if( v1 )
    CmpDetachFromRegistryProcess(&ApcState);
  if( v5 )
    CmpReleaseShutdownRundown();
  CmpCloseSystemDriverHiveContext((INT64)result);
  if( v42 )
    CmpCloseSystemDriverHiveContext((INT64)v41);
  if( DirectoryHandle )
    ZwClose(DirectoryHandle);
  if( v2 )
    ExFreePoolWithTag(v2, 0);
  v14 = (PVOID **)P;
  if( P != &P )
  {
    do
    {
      v24 = *v14;
      CmpCloseSystemDriverHiveContext((INT64)v14);
      ExFreePoolWithTag(v14, 0);
      v14 = (PVOID **)v24;
    }
    while( v24 != &P );
  }
  v15 = v32.Flink;
  if( v32.Flink != &v32 )
  {
    do
    {
      v25 = v15->Flink;
      ExFreePoolWithTag(v15, 0);
      v15 = v25;
    }
    while( v25 != &v32 );
  }
  return v3;
}

Referenced by:

IopInitializeSystemDrivers