EtwpReadConfigParameters
VOID __stdcall EtwpReadConfigParameters(){
WCHAR v0;
const WCHAR *v1;
int v2;
int v3;
UINT8 *PoolWithTag;
unsigned __int64 v5;
unsigned int v6;
unsigned int v7;
__int16 UnicodeString;
_UNICODE_STRING UnicodeString_8;
void *DestinationString[3];
struct _OBJECT_ATTRIBUTES ObjectAttributes;
int v12;
_UNICODE_STRING *p_UnicodeString_8;
int v14;
unsigned int *v15;
int v16;
unsigned int *v17;
_RTL_QUERY_REGISTRY_TABLE result;
INT64(__stdcall *v19)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v20;
int *v21;
int v22;
INT64(__stdcall *v23)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID);
const wchar_t *v24;
int *v25;
int v26;
*(_QWORD *)&ObjectAttributes.Length = 48i64;
memset(DestinationString, 0, sizeof(DestinationString));
*(_QWORD *)&ObjectAttributes.Attributes = 576i64;
UnicodeString = 0;
v7 = 0;
v6 = 10;
v1 = 0i64;
UnicodeString_8 = 0i64;
RtlInitUnicodeString(
(PUNICODE_STRING)&DestinationString[1],
L"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\WMI",
v0);
ObjectAttributes.RootDirectory = 0i64;
ObjectAttributes.ObjectName = (_UNICODE_STRING *)&DestinationString[1];
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
if( ZwOpenKey(DestinationString, 0x20019u, &ObjectAttributes) < 0 )
goto LABEL_21;
memset((INT64)&result, 0i64);
result.QueryRoutine = (int(__fastcall *)(wchar_t *, unsigned int, void *, unsigned int, void *, void *))EtwpQueryRegistryCallback;
v19 = EtwpQueryRegistryCallback;
result.EntryContext = &v12;
v23 = EtwpQueryRegistryCallback;
result.Name = L"RTBacklogRoot";
result.DefaultType = 1;
result.DefaultData = &UnicodeString;
v12 = 1;
p_UnicodeString_8 = &UnicodeString_8;
v21 = &v14;
v20 = L"MaxNonPagedPoolUsage";
v15 = &v6;
v25 = &v16;
v24 = L"StackCaptureTimeout";
v17 = &v7;
v22 = 4;
v14 = 4;
v26 = 4;
v16 = 4;
if( (int)RtlQueryRegistryValuesEx(0x40000000ui64, (const WCHAR *)DestinationString[0], &result, 0i64, 0i64) < 0 )
{
LABEL_21:
v2 = v6;
v3 = v7;
}
else
{
if( UnicodeString_8.Buffer )
{
if( UnicodeString_8.Length >= 4u )
{
PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, UnicodeString_8.MaximumLength + 2i64, 0x50777445ui64);
v1 = (const WCHAR *)PoolWithTag;
if( PoolWithTag )
{
memmove(PoolWithTag, (UINT8 *)UnicodeString_8.Buffer, UnicodeString_8.MaximumLength);
v5 = (unsigned __int64)UnicodeString_8.Length >> 1;
if( v1[v5 - 1] != 92 )
{
v1[v5] = 92;
v1[((unsigned __int64)UnicodeString_8.Length >> 1) + 1] = 0;
}
}
}
}
v2 = 50;
if( v6 <= 0x32 )
{
v2 = v6;
if( v6 < 0xA )
v2 = 10;
}
v3 = v7;
v6 = v2;
if( v7 > 0x2BF20 )
v3 = 180000;
v7 = v3;
}
EtwpMaxNonPagedPoolUsage = v2;
if( v1 )
EtwpRTBacklogFileRoot = v1;
if( v3 )
EtwpStackCaptureTimeout = v3;
if( DestinationString[0] )
ZwClose(DestinationString[0]);
RtlFreeAnsiString(&UnicodeString_8);
}Referenced by:
EtwpInitialize