CmpReplicateKeyToVirtual

INT64 __fastcall CmpReplicateKeyToVirtual(
        _CM_KEY_CONTROL_BLOCK *KeyControlBlock,
        UINT8 RegLockHeldExclusive,
        _CMHIVE **CmHive){
  INT64 *v3; 
  char v4; 
  INT64 v5; 
  _CM_KEY_CONTROL_BLOCK *v7; 
  char v8; 
  ERESOURCE *v9; 
  int VirtualStoreRoot; 
  struct _UNICODE_STRING *v11; 
  _DWORD *v12; 
  __int64 v13; 
  INT64 v14; 
  INT64 v15; 
  struct _UNICODE_STRING *p_DestinationString; 
  unsigned int a3; 
  int v19; 
  struct _UNICODE_STRING DestinationString; 
  PVOID P; 
  INT64 v22; 
  __int64 v23; 
  INT64 *v24; 
  LARGE_INTEGER v25[2]; 
  __int128 v26; 
  v24 = v3;
  v4 = (char)CmHive;
  v19 = 0;
  v5 = RegLockHeldExclusive;
  DestinationString = 0i64;
  v7 = 0i64;
  *(_OWORD *)&v25[0].LowPart = 0i64;
  v26 = 0i64;
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
    EtwGetKernelTraceTimestamp(v25, 0x20000ui64);
  v22 = 0i64;
  P = 0i64;
  a3 = 0;
  v8 = 0;
  RtlInitUnicodeString(&DestinationString, 0i64, (WCHAR)CmHive);
  v23 = 0i64;
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) && KeyControlBlock )
    v7 = KeyControlBlock;
  if( !v4 )
  {
    v8 = CmpTryConvertRegistryExclusive(v9);
    if( !v8 )
    {
      VirtualStoreRoot = -1073741739;
LABEL_22:
      if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
      {
        p_DestinationString = &DestinationString;
        LOBYTE(p_DestinationString) = 26;
        (*(void(__fastcall **)(struct _UNICODE_STRING *, LARGE_INTEGER *, _QWORD, _QWORD, _CM_KEY_CONTROL_BLOCK *, struct _UNICODE_STRING *))((char *)&NlsMbCodePageTag + 7))(
          p_DestinationString,
          v25,
          (unsigned int)VirtualStoreRoot,
          0i64,
          v7,
          &DestinationString);
      }
      if( DestinationString.Buffer )
        RtlFreeAnsiString(&DestinationString);
      return(unsigned int)VirtualStoreRoot;
    }
  }
  CmpUnlockKcb((UINT64)KeyControlBlock);
  VirtualStoreRoot = CmRealKCBToVirtualPath((INT64)KeyControlBlock, 0i64, v5, &DestinationString);
  if( VirtualStoreRoot >= 0 )
  {
    if( (int)CmpBuildVirtualReplicationStack((INT64)KeyControlBlock, (INT64)&DestinationString, &a3, &P) >= 0 )
    {
      v12 = P;
      if( a3 )
      {
        VirtualStoreRoot = CmpGetVirtualStoreRoot(v5, &v22, &v19, &v23);
        if( VirtualStoreRoot >= 0 )
        {
          v13 = v23;
          v14 = v22;
          v15 = a3;
          *v24 = v22;
          v12[8] = *(_DWORD *)(v13 + 40);
          *((_QWORD *)v12 + 2) = v13;
          VirtualStoreRoot = CmpDoBuildVirtualStack((INT64)v12, v15, v14, (INT64)KeyControlBlock, v5);
        }
      }
      else
      {
        VirtualStoreRoot = -1073741811;
      }
      if( v12 )
      {
        CmpDestroyVirtualStack((INT64)v12, a3);
        ExFreePoolWithTag(v12, 0);
      }
    }
    else
    {
      VirtualStoreRoot = -1073741670;
    }
    CmpLockKcbExclusive((__int64)KeyControlBlock);
    if( v8 )
      CmpConvertRegistryShared();
    goto LABEL_22;
  }
  if( *(BOOLEAN **)((char *)&NlsMbCodePageTag + 7) )
  {
    v11 = &DestinationString;
    LOBYTE(v11) = 26;
    (*(void(__fastcall **)(struct _UNICODE_STRING *, LARGE_INTEGER *, _QWORD, _QWORD, _CM_KEY_CONTROL_BLOCK *, struct _UNICODE_STRING *))((char *)&NlsMbCodePageTag + 7))(
      v11,
      v25,
      (unsigned int)VirtualStoreRoot,
      0i64,
      v7,
      &DestinationString);
  }
  return(unsigned int)VirtualStoreRoot;
}

Referenced by:

No references.