EtwpReadConfigParameters

VOID __stdcall EtwpReadConfigParameters(){
  WCHAR v0; 
  const WCHAR *v1; 
  int v2; 
  int v3; 
  UINT8 *PoolWithTag; 
  unsigned __int64 v5; 
  unsigned int v6; 
  unsigned int v7; 
  __int16 UnicodeString; 
  _UNICODE_STRING UnicodeString_8; 
  void *DestinationString[3]; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  int v12; 
  _UNICODE_STRING *p_UnicodeString_8; 
  int v14; 
  unsigned int *v15; 
  int v16; 
  unsigned int *v17; 
  _RTL_QUERY_REGISTRY_TABLE result; 
  INT64(__stdcall *v19)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID); 
  const wchar_t *v20; 
  int *v21; 
  int v22; 
  INT64(__stdcall *v23)(WCHAR *, UINT64, PVOID, UINT64, PVOID, PVOID); 
  const wchar_t *v24; 
  int *v25; 
  int v26; 
  *(_QWORD *)&ObjectAttributes.Length = 48i64;
  memset(DestinationString, 0, sizeof(DestinationString));
  *(_QWORD *)&ObjectAttributes.Attributes = 576i64;
  UnicodeString = 0;
  v7 = 0;
  v6 = 10;
  v1 = 0i64;
  UnicodeString_8 = 0i64;
  RtlInitUnicodeString(
    (PUNICODE_STRING)&DestinationString[1],
    L"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\WMI",
    v0);
  ObjectAttributes.RootDirectory = 0i64;
  ObjectAttributes.ObjectName = (_UNICODE_STRING *)&DestinationString[1];
  *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
  if( ZwOpenKey(DestinationString, 0x20019u, &ObjectAttributes) < 0 )
    goto LABEL_21;
  memset((INT64)&result, 0i64);
  result.QueryRoutine = (int(__fastcall *)(wchar_t *, unsigned int, void *, unsigned int, void *, void *))EtwpQueryRegistryCallback;
  v19 = EtwpQueryRegistryCallback;
  result.EntryContext = &v12;
  v23 = EtwpQueryRegistryCallback;
  result.Name = L"RTBacklogRoot";
  result.DefaultType = 1;
  result.DefaultData = &UnicodeString;
  v12 = 1;
  p_UnicodeString_8 = &UnicodeString_8;
  v21 = &v14;
  v20 = L"MaxNonPagedPoolUsage";
  v15 = &v6;
  v25 = &v16;
  v24 = L"StackCaptureTimeout";
  v17 = &v7;
  v22 = 4;
  v14 = 4;
  v26 = 4;
  v16 = 4;
  if( (int)RtlQueryRegistryValuesEx(0x40000000ui64, (const WCHAR *)DestinationString[0], &result, 0i64, 0i64) < 0 )
  {
LABEL_21:
    v2 = v6;
    v3 = v7;
  }
  else
  {
    if( UnicodeString_8.Buffer )
    {
      if( UnicodeString_8.Length >= 4u )
      {
        PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, UnicodeString_8.MaximumLength + 2i64, 0x50777445ui64);
        v1 = (const WCHAR *)PoolWithTag;
        if( PoolWithTag )
        {
          memmove(PoolWithTag, (UINT8 *)UnicodeString_8.Buffer, UnicodeString_8.MaximumLength);
          v5 = (unsigned __int64)UnicodeString_8.Length >> 1;
          if( v1[v5 - 1] != 92 )
          {
            v1[v5] = 92;
            v1[((unsigned __int64)UnicodeString_8.Length >> 1) + 1] = 0;
          }
        }
      }
    }
    v2 = 50;
    if( v6 <= 0x32 )
    {
      v2 = v6;
      if( v6 < 0xA )
        v2 = 10;
    }
    v3 = v7;
    v6 = v2;
    if( v7 > 0x2BF20 )
      v3 = 180000;
    v7 = v3;
  }
  EtwpMaxNonPagedPoolUsage = v2;
  if( v1 )
    EtwpRTBacklogFileRoot = v1;
  if( v3 )
    EtwpStackCaptureTimeout = v3;
  if( DestinationString[0] )
    ZwClose(DestinationString[0]);
  RtlFreeAnsiString(&UnicodeString_8);
}

Referenced by:

EtwpInitialize