PiGetDeviceRegistryProperty
INT64 __stdcall PiGetDeviceRegistryProperty(
_DEVICE_OBJECT *DeviceObject,
UINT64 ValueType,
WCHAR *ValueName,
WCHAR *KeyName,
PVOID Buffer,
UINT64 *a6){
INT8 *v7;
_ETHREAD *CurrentThread;
int RegistryValue;
WCHAR v10;
_DWORD *v11;
unsigned int v12;
wchar_t *v13;
wchar_t *v14;
WCHAR *v15;
__int64 v16;
WCHAR *v17;
unsigned int i;
INT8 *v19;
__int64 v20;
WCHAR *v21;
char v22;
UINT64 *v23;
UINT64 Length;
char Size[12];
wchar_t *Str;
void *KeyHandle;
PVOID P;
NTSTRSAFE_PWSTR v30;
UINT64 *ReturnLength;
struct _UNICODE_STRING DestinationString;
struct _OBJECT_ATTRIBUTES ObjectAttributes;
INT8 *Arguments;
INT64 result[19];
v30 = (NTSTRSAFE_PWSTR)Buffer;
v7 = 0i64;
KeyHandle = 0i64;
DestinationString = 0i64;
ReturnLength = a6;
CurrentThread = (_ETHREAD *)KeGetCurrentThread();
P = 0i64;
memset(Size, 0, sizeof(Size));
Str = 0i64;
--*((_WORD *)CurrentThread + 242);
ExAcquireResourceExclusiveLite(&PnpRegistryDeviceResource, 1u);
RegistryValue = PnpDeviceObjectToDeviceInstance(DeviceObject, (PVOID *)&Size[4], 0x20019ui64);
if( RegistryValue >= 0 )
{
RtlInitUnicodeString(&DestinationString, L"LogConf", v10);
ObjectAttributes.RootDirectory = *(void **)&Size[4];
*(_QWORD *)&ObjectAttributes.Length = 48i64;
ObjectAttributes.ObjectName = &DestinationString;
*(_QWORD *)&ObjectAttributes.Attributes = 576i64;
*(_OWORD *)&ObjectAttributes.SecurityDescriptor = 0i64;
RegistryValue = ZwOpenKey(&KeyHandle, 0x20019u, &ObjectAttributes);
if( RegistryValue >= 0 )
{
ZwClose(*(HANDLE *)&Size[4]);
*(_QWORD *)&Size[4] = KeyHandle;
RegistryValue = IopGetRegistryValue(
KeyHandle,
(PWCHAR)L"BootConfig",
0x140ui64,
(KEY_VALUE_FULL_INFORMATION **)&P);
}
ZwClose(*(HANDLE *)&Size[4]);
}
ExReleaseResourceLite(&PnpRegistryDeviceResource);
KeLeaveCriticalRegion();
if( RegistryValue >= 0 )
{
v11 = P;
v12 = *((_DWORD *)P + 3);
v13 = (wchar_t *)((char *)P + *((unsigned int *)P + 2));
if( *((_DWORD *)P + 1) == 1
&& (unsigned int)PnpFindAlternateStringData(
(WCHAR *)((char *)P + *((unsigned int *)P + 2)),
v12,
&Str,
(UINT64 *)Size) )
{
v14 = Str;
v12 = *(_DWORD *)Size;
v13 = Str;
v15 = wcsstr(Str, L";(");
v7 = (INT8 *)v15;
if( v15 && (v16 = (v12 >> 1) - 2, v14[v16] == 41) )
{
*v15 = 0;
v7 = (INT8 *)(v15 + 2);
v14[v16] = 0;
memset((INT64)result, 0i64);
v17 = (WCHAR *)v7;
Arguments = v7;
for( i = 1; ; ++i )
{
v21 = wcschr(v17, 0x2Cu);
if( !v21 )
{
v22 = 0;
goto LABEL_15;
}
*v21 = 0;
v19 = (INT8 *)(v21 + 1);
if( i >= 0x13 )
break;
v20 = i;
result[v20 - 1] = (INT64)v19;
v17 = (WCHAR *)v19;
}
v22 = 1;
}
else
{
v22 = 0;
}
}
else
{
v14 = Str;
v22 = 0;
}
LABEL_15:
v23 = ReturnLength;
if( *(_DWORD *)ReturnLength < v12 )
{
RegistryValue = -1073741789;
}
else if( v11[1] == 8 )
{
if( v7 )
{
if( v22 )
{
RegistryValue = -1073741619;
}
else
{
LODWORD(Length) = *(_DWORD *)ReturnLength;
RegistryValue = RtlFormatMessageEx(v14, 0i64, 0, 0, 1u, &Arguments, v30, Length, ReturnLength);
}
}
else
{
memmove((UINT8 *)v30, (UINT8 *)v13, v12);
}
}
else
{
RegistryValue = -1073741584;
}
*(_DWORD *)v23 = v12;
ExFreePoolWithTag(v11, 0);
}
return(unsigned int)RegistryValue;
}Referenced by:
IoGetDeviceProperty