CmpHiveRootSecurityDescriptor

VOID *__stdcall CmpHiveRootSecurityDescriptor(UINT8 WorldFullAccess){
  unsigned __int8 *PoolWithTag; 
  unsigned __int8 *v2; 
  unsigned __int8 *v3; 
  unsigned __int8 *v4; 
  unsigned __int8 *v5; 
  UINT64 v6; 
  unsigned __int8 *v7; 
  UINT64 v8; 
  UINT64 v9; 
  UINT64 v10; 
  UINT64 v11; 
  UINT32 v12; 
  struct _ACL *v13; 
  ACL *v14; 
  NTSTATUS Acl; 
  int v16; 
  ACL *v17; 
  ACL *v18; 
  SID_IDENTIFIER_AUTHORITY v20; 
  PVOID Ace; 
  struct _SID_IDENTIFIER_AUTHORITY IdentifierAuthority; 
  size_t Size; 
  UNICODE_STRING SourceString; 
  char Src[48]; 
  char Sid[48]; 
  *(_QWORD *)&SourceString.Length = 1703960i64;
  *(_DWORD *)IdentifierAuthority.Value = 0;
  SourceString.Buffer = L"registryRead";
  *(_WORD *)&IdentifierAuthority.Value[4] = 256;
  *(_DWORD *)v20.Value = 0;
  *(_WORD *)&v20.Value[4] = 1280;
  LODWORD(Size) = 0;
  WORD2(Size) = 3840;
  Ace = 0i64;
  PoolWithTag = (unsigned __int8 *)ExAllocatePoolWithTag(PagedPool, 0xCui64, 0x20204D43ui64);
  v2 = (unsigned __int8 *)ExAllocatePoolWithTag(PagedPool, 0xCui64, 0x20204D43ui64);
  v3 = (unsigned __int8 *)ExAllocatePoolWithTag(PagedPool, 0xCui64, 0x20204D43ui64);
  v4 = (unsigned __int8 *)ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x20204D43ui64);
  v5 = (unsigned __int8 *)ExAllocatePoolWithTag(PagedPool, 0x10ui64, 0x20204D43ui64);
  v7 = v5;
  if( !PoolWithTag || !v2 || !v3 || !v4 || !v5 )
    KeBugCheckEx(0x51u, 0xBui64, 1ui64, 0i64, 0i64);
  LOBYTE(v6) = 1;
  if( (int)RtlInitializeSid(PoolWithTag, &IdentifierAuthority, v6) < 0
    || (LOBYTE(v8) = 1, (int)RtlInitializeSid(v2, &v20, v8) < 0)
    || (LOBYTE(v9) = 1, (int)RtlInitializeSid(v3, &v20, v9) < 0)
    || (LOBYTE(v10) = 2, (int)RtlInitializeSid(v4, &v20, v10) < 0)
    || (LOBYTE(v11) = 2, (int)RtlInitializeSid(v7, (SID_IDENTIFIER_AUTHORITY *)&Size, v11) < 0) )
  {
    KeBugCheckEx(0x51u, 0xBui64, 2ui64, 0i64, 0i64);
  }
  *RtlSubAuthoritySid(PoolWithTag, 0i64) = 0;
  *RtlSubAuthoritySid(v2, 0i64) = 12;
  *RtlSubAuthoritySid(v3, 0i64) = 18;
  *RtlSubAuthoritySid(v4, 0i64) = 32;
  *RtlSubAuthoritySid(v4, 1ui64) = 544;
  *RtlSubAuthoritySid(v7, 0i64) = 2;
  *RtlSubAuthoritySid(v7, 1ui64) = 1;
  if( RtlDeriveCapabilitySidsFromName(&SourceString, Sid, Src) < 0 )
    KeBugCheckEx(0x51u, 0xBui64, 3ui64, 0i64, 0i64);
  v12 = 4 * ((unsigned __int8)Src[1] + PoolWithTag[1] + v2[1] + v3[1] + v4[1] + v7[1]) + 104;
  Size = v12;
  v13 = (struct _ACL *)ExAllocatePoolWithTag(PagedPool, v12, 0x20204D43ui64);
  v14 = v13;
  if( !v13 )
    KeBugCheckEx(0x51u, 0xBui64, 4ui64, 0i64, 0i64);
  Acl = RtlCreateAcl(v13, v12, 2u);
  if( Acl < 0 )
    KeBugCheckEx(0x51u, 0xBui64, 5ui64, Acl, 0i64);
  v16 = RtlpAddKnownAce(v14, 2ui64, 0i64, 0xF003Fui64, v3, 0);
  if( v16 < 0
    || (v16 = RtlpAddKnownAce(v14, 2ui64, 0i64, 0xF003Fui64, v4, 0), v16 < 0)
    || (v16 = RtlpAddKnownAce(v14, 2ui64, 0i64, 0x20019ui64, PoolWithTag, 0), v16 < 0)
    || (v16 = RtlpAddKnownAce(v14, 2ui64, 0i64, 0x20019ui64, v2, 0), v16 < 0)
    || (v16 = RtlpAddKnownAce(v14, 2ui64, 0i64, 0x20019ui64, v7, 0), v16 < 0)
    || (v16 = RtlpAddKnownAce(v14, 2ui64, 0i64, 0x20019ui64, Src, 0), v16 < 0) )
  {
    KeBugCheckEx(0x51u, 0xBui64, 6ui64, v16, 0i64);
  }
  RtlGetAce(v14, 0i64, &Ace);
  *((_BYTE *)Ace + 1) |= 2u;
  RtlGetAce(v14, 1ui64, &Ace);
  *((_BYTE *)Ace + 1) |= 2u;
  RtlGetAce(v14, 2ui64, &Ace);
  *((_BYTE *)Ace + 1) |= 2u;
  RtlGetAce(v14, 3ui64, &Ace);
  *((_BYTE *)Ace + 1) |= 2u;
  RtlGetAce(v14, 4ui64, &Ace);
  *((_BYTE *)Ace + 1) |= 2u;
  RtlGetAce(v14, 5ui64, &Ace);
  *((_BYTE *)Ace + 1) |= 2u;
  v17 = (ACL *)ExAllocatePoolWithTag(PagedPool, v12 + 40i64, 0x20204D43ui64);
  v18 = v17;
  if( !v17 )
    KeBugCheckEx(0x51u, 0xBui64, 7ui64, 0i64, 0i64);
  memmove((UINT8 *)&v17[5], (UINT8 *)v14, Size);
  *(_DWORD *)v20.Value = RtlCreateSecurityDescriptor(v18, 1ui64);
  if( *(int *)v20.Value < 0 )
  {
    ExFreePoolWithTag(v18, 0);
    KeBugCheckEx(0x51u, 0xBui64, 8ui64, *(int *)v20.Value, 0i64);
  }
  *(_DWORD *)v20.Value = RtlSetDaclSecurityDescriptor(v18, 1u, v18 + 5, 0);
  if( *(int *)v20.Value < 0 )
  {
    ExFreePoolWithTag(v18, 0);
    KeBugCheckEx(0x51u, 0xBui64, 9ui64, *(int *)v20.Value, 0i64);
  }
  ExFreePoolWithTag(PoolWithTag, 0);
  ExFreePoolWithTag(v2, 0);
  ExFreePoolWithTag(v3, 0);
  ExFreePoolWithTag(v4, 0);
  ExFreePoolWithTag(v7, 0);
  ExFreePoolWithTag(v14, 0);
  return v18;
}

Referenced by:

CmInitSystem1
CmpCreateRegistryRoot
CmpFinishSystemHivesLoad
CmpInitializePreloadedHives
CmpSetVersionData