SiGetRegistryValue

NTSTATUS __stdcall SiGetRegistryValue(PWCHAR ValueName, PWCHAR KeyName, PVOID *Buffer, UINT64 *a4){
  UINT8 **v4; 
  ULONG *v5; 
  UINT8 *v6; 
  HANDLE v7; 
  VOID *v9; 
  UINT64 v10; 
  int v11; 
  int v12; 
  NTSTATUS v13; 
  UINT8 *PoolWithTag; 
  UINT8 *v15; 
  struct _UNICODE_STRING DestinationString; 
  ULONG v18; 
  int v19; 
  HANDLE Handle; 
  ULONG ResultLength; 
  UINT8 **v22; 
  ULONG *v23; 
  v19 = HIDWORD(ValueName);
  v4 = v22;
  v5 = v23;
  v18 = 0;
  v6 = 0i64;
  ResultLength = 0;
  v7 = 0i64;
  *v22 = 0i64;
  *v5 = 0;
  DestinationString = 0i64;
  Handle = 0i64;
  RtlInitUnicodeString(&DestinationString, KeyName, (WCHAR)Buffer);
  if( !Buffer || (v11 = SiOpenRegistryKey(v9, (WCHAR *)Buffer, v10, &Handle), v7 = Handle, v12 = v11, v11 >= 0) )
  {
    v13 = ZwQueryValueKey(v7, &DestinationString, KeyValuePartialInformation, 0i64, 0, &ResultLength);
    v12 = v13;
    if( v13 == -1073741789 )
    {
      PoolWithTag = (UINT8 *)ExAllocatePoolWithTag(PagedPool, ResultLength, 0x4B505953ui64);
      v6 = PoolWithTag;
      if( !PoolWithTag )
      {
LABEL_16:
        v12 = -1073741670;
        goto LABEL_9;
      }
      v12 = ZwQueryValueKey(v7, &DestinationString, KeyValuePartialInformation, PoolWithTag, ResultLength, &v18);
      if( v12 < 0 )
        goto LABEL_9;
      if( *((_DWORD *)v6 + 1) == 1 )
      {
        ResultLength -= 12;
        v15 = (UINT8 *)ExAllocatePoolWithTag(PagedPool, ResultLength, 0x4B505953ui64);
        *v4 = v15;
        if( v15 )
        {
          memmove(v15, v6 + 12, ResultLength);
          v12 = 0;
          *v5 = ResultLength;
          goto LABEL_9;
        }
        goto LABEL_16;
      }
      v12 = -1073741788;
    }
    else if( v13 >= 0 )
    {
      v12 = -1073741823;
    }
  }
LABEL_9:
  if( v7 )
    ZwClose(v7);
  if( v6 )
    ExFreePoolWithTag(v6, 0);
  return v12;
}

Referenced by:

SiDisambiguateSystemDevice
SiGetBootDeviceNameFromRegistry
SiIsWinPEBoot