PiGetDeviceRegistryProperty

INT64 __stdcall PiGetDeviceRegistryProperty(
        _DEVICE_OBJECT *DeviceObject,
        UINT64 ValueType,
        WCHAR *ValueName,
        WCHAR *KeyName,
        PVOID Buffer,
        UINT64 *a6){
  INT8 *v7; 
  _ETHREAD *CurrentThread; 
  int RegistryValue; 
  WCHAR v10; 
  _DWORD *v11; 
  unsigned int v12; 
  wchar_t *v13; 
  wchar_t *v14; 
  WCHAR *v15; 
  __int64 v16; 
  WCHAR *v17; 
  unsigned int i; 
  INT8 *v19; 
  __int64 v20; 
  WCHAR *v21; 
  char v22; 
  UINT64 *v23; 
  UINT64 Length; 
  char Size[12]; 
  wchar_t *Str; 
  void *KeyHandle; 
  PVOID P; 
  NTSTRSAFE_PWSTR v30; 
  UINT64 *ReturnLength; 
  struct _UNICODE_STRING DestinationString; 
  struct _OBJECT_ATTRIBUTES ObjectAttributes; 
  INT8 *Arguments; 
  INT64 result[19]; 
  v30 = (NTSTRSAFE_PWSTR)Buffer;
  v7 = 0i64;
  KeyHandle = 0i64;
  DestinationString = 0i64;
  ReturnLength = a6;
  CurrentThread = (_ETHREAD *)KeGetCurrentThread();
  P = 0i64;
  memset(Size, 0, sizeof(Size));
  Str = 0i64;
  --*((_WORD *)CurrentThread + 242);
  ExAcquireResourceExclusiveLite(&PnpRegistryDeviceResource, 1u);
  RegistryValue = PnpDeviceObjectToDeviceInstance(DeviceObject, (PVOID *)&Size[4], 0x20019ui64);
  if( RegistryValue >= 0 )
  {
    RtlInitUnicodeString(&DestinationString, L"LogConf", v10);
    ObjectAttributes.RootDirectory = *(void **)&Size[4];
    *(_QWORD *)&ObjectAttributes.Length = 48i64;
    ObjectAttributes.ObjectName = &DestinationString;
    *(_QWORD *)&ObjectAttributes.Attributes = 576i64;
    *(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
    RegistryValue = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
    if( RegistryValue >= 0 )
    {
      ZwClose(*(HANDLE *)&Size[4]);
      *(_QWORD *)&Size[4] = KeyHandle;
      RegistryValue = IopGetRegistryValue(
                        KeyHandle,
                        (PWCHAR)L"BootConfig",
                        0x140ui64,
                        (KEY_VALUE_FULL_INFORMATION **)&P);
    }
    ZwClose(*(HANDLE *)&Size[4]);
  }
  ExReleaseResourceLite(&PnpRegistryDeviceResource);
  KeLeaveCriticalRegion();
  if( RegistryValue >= 0 )
  {
    v11 = P;
    v12 = *((_DWORD *)P + 3);
    v13 = (wchar_t *)((char *)P + *((unsigned int *)P + 2));
    if( *((_DWORD *)P + 1) == 1
      && (unsigned int)PnpFindAlternateStringData(
                         (WCHAR *)((char *)P + *((unsigned int *)P + 2)),
                         v12,
                         &Str,
                         (UINT64 *)Size) )
    {
      v14 = Str;
      v12 = *(_DWORD *)Size;
      v13 = Str;
      v15 = wcsstr(Str, L";(");
      v7 = (INT8 *)v15;
      if( v15 && (v16 = (v12 >> 1) - 2, v14[v16] == 41) )
      {
        *v15 = 0;
        v7 = (INT8 *)(v15 + 2);
        v14[v16] = 0;
        memset((INT64)result, 0i64);
        v17 = (WCHAR *)v7;
        Arguments = v7;
        for( i = 1; ; ++i )
        {
          v21 = wcschr(v17, 0x2Cu);
          if( !v21 )
          {
            v22 = 0;
            goto LABEL_15;
          }
          *v21 = 0;
          v19 = (INT8 *)(v21 + 1);
          if( i >= 0x13 )
            break;
          v20 = i;
          result[v20 - 1] = (INT64)v19;
          v17 = (WCHAR *)v19;
        }
        v22 = 1;
      }
      else
      {
        v22 = 0;
      }
    }
    else
    {
      v14 = Str;
      v22 = 0;
    }
LABEL_15:
    v23 = ReturnLength;
    if( *(_DWORD *)ReturnLength < v12 )
    {
      RegistryValue = -1073741789;
    }
    else if( v11[1] == 8 )
    {
      if( v7 )
      {
        if( v22 )
        {
          RegistryValue = -1073741619;
        }
        else
        {
          LODWORD(Length) = *(_DWORD *)ReturnLength;
          RegistryValue = RtlFormatMessageEx(v14, 0i64, 0, 0, 1u, &Arguments, v30, Length, ReturnLength);
        }
      }
      else
      {
        memmove((UINT8 *)v30, (UINT8 *)v13, v12);
      }
    }
    else
    {
      RegistryValue = -1073741584;
    }
    *(_DWORD *)v23 = v12;
    ExFreePoolWithTag(v11, 0);
  }
  return(unsigned int)RegistryValue;
}

Referenced by:

IoGetDeviceProperty