KsepRegistryQueryValue

INT64 __stdcall KsepRegistryQueryValue(
        PVOID KeyHandle,
        WCHAR *ValueName,
        UINT64 *ValueType,
        PVOID ValueBuffer,
        UINT64 ValueBufferLength,
        UINT64 *ActualLength){
  UINT64 *v8; 
  __int64 v10; 
  __int64 v11; 
  UINT64 *v12; 
  __int64 v13; 
  NTSTATUS v14; 
  unsigned int v15; 
  char v16; 
  __int64 v17; 
  UINT8 *v19; 
  UINT8 *v20; 
  unsigned int v21; 
  UINT64 v22; 
  struct _UNICODE_STRING DestinationString; 
  ULONG ResultLength; 
  ResultLength = 0;
  v8 = ValueType;
  DestinationString = 0i64;
  if( !KeyHandle )
  {
    LOWORD(ValueType) = 969;
    v10 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
    KsepHistoryErrors[2 * v10 + 1] = -1073740768;
    KsepHistoryErrors[2 * v10] = 263113;
    if( (KsepDebugFlag & 4) != 0 )
      RtlAssert("KeyHandle != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3C9u, 0i64);
  }
  if( !ValueBuffer )
  {
    LOWORD(ValueType) = 970;
    v11 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
    KsepHistoryErrors[2 * v11 + 1] = -1073740768;
    KsepHistoryErrors[2 * v11] = 263114;
    if( (KsepDebugFlag & 4) != 0 )
      RtlAssert("ValueBuffer != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3CAu, 0i64);
  }
  v12 = ActualLength;
  if( !ActualLength )
  {
    v13 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
    LOWORD(ValueType) = 971;
    KsepHistoryErrors[2 * v13 + 1] = -1073740768;
    KsepHistoryErrors[2 * v13] = 263115;
    if( (KsepDebugFlag & 4) != 0 )
      RtlAssert("ActualLength != NULL", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3CBu, 0i64);
  }
  RtlInitUnicodeString(&DestinationString, ValueName, (WCHAR)ValueType);
  v14 = ZwQueryValueKey(KeyHandle, &DestinationString, KeyValuePartialInformation, 0i64, 0, &ResultLength);
  v15 = v14;
  if( v14 == -1073741789 )
  {
    KsepPoolAllocatePaged(ResultLength);
    v20 = v19;
    if( v19 )
    {
      v21 = ZwQueryValueKey(KeyHandle, &DestinationString, KeyValuePartialInformation, v19, ResultLength, &ResultLength);
      if( !v21 )
      {
        v22 = *((unsigned int *)v20 + 2);
        if( v22 <= ValueBufferLength )
        {
          memmove((UINT8 *)ValueBuffer, v20 + 12, v22);
          *(_DWORD *)v8 = *((_DWORD *)v20 + 1);
          *v12 = *((unsigned int *)v20 + 2);
        }
        else
        {
          *v12 = v22;
          v21 = -1073741789;
        }
      }
      KsepPoolFreePaged(v20);
      return v21;
    }
    else
    {
      return 3221225495i64;
    }
  }
  else
  {
    if( v14 >= 0 )
    {
      v16 = KsepDebugFlag;
      v17 = ((unsigned __int8)_InterlockedExchangeAdd(&KsepHistoryErrorsIndex, 1u) + 1) & 0x3F;
      KsepHistoryErrors[2 * v17 + 1] = -1073740768;
      KsepHistoryErrors[2 * v17] = 263133;
      if( (v16 & 4) != 0 )
        RtlAssert("!NT_SUCCESS(Status)", "minkernel\\ntos\\kshim\\kseregistry.c", 0x3DDu, 0i64);
    }
    return v15;
  }
}

Referenced by:

KsepDbQueryRegistryDeviceData