KsepRegistryQueryValue
INT64 __stdcall KsepRegistryQueryValue(
PVOID KeyHandle,
WCHAR *ValueName,
UINT64 *ValueType,
PVOID ValueBuffer,
UINT64 ValueBufferLength,
UINT64 *ActualLength){
UINT64 *v8;
__int64 v10;
__int64 v11;
UINT64 *v12;
__int64 v13;
NTSTATUS v14;
unsigned int v15;
char v16;
__int64 v17;
UINT8 *v19;
UINT8 *v20;
unsigned int v21;
UINT64 v22;
struct _UNICODE_STRING DestinationString;
ULONG ResultLength;
ResultLength = 0;
v8 = ValueType;
DestinationString = 0i64;
if( !KeyHandle )
{
LOWORD(ValueType) = 969;
v10 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
KsepHistoryErrors[2 * v10 + 1] = -1073740768;
KsepHistoryErrors[2 * v10] = 263113;
if( (KsepDebugFlag & 4) != 0 )
RtlAssert("KeyHandle != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3C9u, 0i64);
}
if( !ValueBuffer )
{
LOWORD(ValueType) = 970;
v11 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
KsepHistoryErrors[2 * v11 + 1] = -1073740768;
KsepHistoryErrors[2 * v11] = 263114;
if( (KsepDebugFlag & 4) != 0 )
RtlAssert("ValueBuffer != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3CAu, 0i64);
}
v12 = ActualLength;
if( !ActualLength )
{
v13 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
LOWORD(ValueType) = 971;
KsepHistoryErrors[2 * v13 + 1] = -1073740768;
KsepHistoryErrors[2 * v13] = 263115;
if( (KsepDebugFlag & 4) != 0 )
RtlAssert("ActualLength != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3CBu, 0i64);
}
RtlInitUnicodeString(&DestinationString, ValueName, (WCHAR)ValueType);
v14 = ZwQueryValueKey(KeyHandle, &DestinationString, KeyValuePartialInformation, 0i64, 0, &ResultLength);
v15 = v14;
if( v14 == -1073741789 )
{
KsepPoolAllocatePaged(ResultLength);
v20 = v19;
if( v19 )
{
v21 = ZwQueryValueKey(KeyHandle, &DestinationString, KeyValuePartialInformation, v19, ResultLength, &ResultLength);
if( !v21 )
{
v22 = *((unsigned int *)v20 + 2);
if( v22 <= ValueBufferLength )
{
memmove((UINT8 *)ValueBuffer, v20 + 12, v22);
*(_DWORD *)v8 = *((_DWORD *)v20 + 1);
*v12 = *((unsigned int *)v20 + 2);
}
else
{
*v12 = v22;
v21 = -1073741789;
}
}
KsepPoolFreePaged(v20);
return v21;
}
else
{
return 3221225495i64;
}
}
else
{
if( v14 >= 0 )
{
v16 = KsepDebugFlag;
v17 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
KsepHistoryErrors[2 * v17 + 1] = -1073740768;
KsepHistoryErrors[2 * v17] = 263133;
if( (v16 & 4) != 0 )
RtlAssert("!NT_SUCCESS(Status)", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3DDu, 0i64);
}
return v15;
}
}Referenced by:
KsepDbQueryRegistryDeviceData