IoWMISystemControl

NTSTATUS __stdcall IoWMISystemControl(
        _WMILIB_INFO *WmiLibInfo,
        _DEVICE_OBJECT *DeviceObject,
        _IRP *Irp,
        INT64 a4,
        INT64 a5,
        INT8 a6){
  UINT64 *v6; 
  _IO_STACK_LOCATION *CurrentStackLocation; 
  _DEVICE_OBJECT *Flink; 
  unsigned int v10; 
  int Flink_high; 
  unsigned int MinorFunction; 
  __int64 v13; 
  unsigned int v14; 
  _WMILIB_INFO *v15; 
  unsigned int v16; 
  UINT8 *Buffer; 
  unsigned int v18; 
  int v20; 
  unsigned int v22; 
  NTSTATUS v23; 
  wchar_t *v24; 
  int v25; 
  unsigned __int16 Length; 
  unsigned int v27; 
  __int64 v28; 
  _UNICODE_STRING *v29; 
  unsigned int v30; 
  __int64 v31; 
  __int64 *v32; 
  __int64 *v33; 
  int v34; 
  int v35; 
  unsigned __int16 *v36; 
  int v37; 
  _LIST_ENTRY *v38; 
  __int64 v39; 
  INT64 v40; 
  _LIST_ENTRY *RegEntryByProviderId; 
  UINT64 *InstanceCount; 
  CHAR InstanceLengthArray; 
  UINT64 BufferAvail; 
  _UNICODE_STRING InstanceName; 
  __int128 v46; 
  UINT64 GuidIndex; 
  UINT64 RegFlags; 
  _UNICODE_STRING *RegistryPath; 

  GuidIndex = (UINT64)WmiLibInfo;
  v6 = 0i64;
  CurrentStackLocation = Irp->Tail.CurrentStackLocation;
  Flink = DeviceObject;
  LODWORD(GuidIndex) = 0;
  v10 = 0;
  LODWORD(RegFlags) = 0;
  Flink_high = 0;
  LODWORD(RegistryPath) = 0;
  MinorFunction = CurrentStackLocation->MinorFunction;
  if( (unsigned __int8)MinorFunction > 0xBu
    || (_DEVICE_OBJECT *)CurrentStackLocation->Parameters.SecurityContext != DeviceObject
    || !WmipGuidList && (_BYTE)MinorFunction != 11 && (_BYTE)MinorFunction != 8 )
  {
    v20 = -1073741808;
    goto LABEL_44;
  }
  v13 = *(_QWORD *)&CurrentStackLocation->Parameters.EaLength;
  v14 = *(_DWORD *)&CurrentStackLocation->Parameters.FileAttributes;
  if( (_BYTE)MinorFunction == 11 || (_BYTE)MinorFunction == 8 )
    goto LABEL_10;
  if( WmipFindGuid(
         (GUIDREGINFO *)WmipGuidList,
         7ui64,
         *(_GUID **)&CurrentStackLocation->Parameters.Options,
         &GuidIndex,
         &RegFlags) )
  {
    if( (unsigned __int8)(MinorFunction - 1) <= 2u || (_BYTE)MinorFunction == 9 )
    {
      LODWORD(RegistryPath) = *(_DWORD *)(v13 + 52);
      if( (*(_DWORD *)(v13 + 44) & 0x80u) == 0 )
      {
        v37 = -1073741162;
        goto LABEL_52;
      }
    }
    v10 = GuidIndex;
    Flink_high = RegFlags;
LABEL_10:
    v15 = (_WMILIB_INFO *)MinorFunction;
    if( MinorFunction <= 5 )
    {
      if( MinorFunction == 5 )
        goto LABEL_78;
      if( !(_BYTE)MinorFunction )
      {
        if( v14 < 0x3C )
        {
          LODWORD(InstanceCount) = 60;
          v40 = 3221225507i64;
          return IoWMICompleteRequest(v15, DeviceObject, Irp, v40, (UINT64)InstanceCount, InstanceLengthArray);
        }
        if( v10 > 1 )
        {
LABEL_15:
          if( Flink_high )
          {
            *(_DWORD *)(v13 + 44) &= ~0x10u;
            v16 = (8 * Flink_high + 67) & 0xFFFFFFF8;
            *(_DWORD *)(v13 + 52) = Flink_high;
            *(_DWORD *)(v13 + 48) = v16;
            if( v16 > v14 )
            {
              Buffer = 0i64;
              v18 = 0;
            }
            else
            {
              v6 = (UINT64 *)(v13 + 60);
              Buffer = (UINT8 *)(v13 + v16);
              v18 = v14 - v16;
            }
            LODWORD(BufferAvail) = v18;
            LODWORD(InstanceCount) = Flink_high;
            return WmipQueryWmiDataBlock(Flink, Irp, v10, 0i64, (UINT64)InstanceCount, v6, BufferAvail, Buffer);
          }
          LODWORD(InstanceCount) = 0;
          v40 = 3221226134i64;
          return IoWMICompleteRequest(v15, DeviceObject, Irp, v40, (UINT64)InstanceCount, InstanceLengthArray);
        }
        RegEntryByProviderId = WmipFindRegEntryByProviderId(*(unsigned int *)(v13 + 4));
        if( RegEntryByProviderId )
        {
          Flink = (_DEVICE_OBJECT *)RegEntryByProviderId[1].Flink;
          if( v10 )
            Flink_high = 1;
          else
            Flink_high = HIDWORD(RegEntryByProviderId[3].Flink);
          WmipUnreferenceRegEntry((_REGENTRY *)RegEntryByProviderId);
          goto LABEL_15;
        }
LABEL_69:
        LODWORD(InstanceCount) = 0;
        v40 = 3221226133i64;
        return IoWMICompleteRequest(v15, DeviceObject, Irp, v40, (UINT64)InstanceCount, InstanceLengthArray);
      }
      if( MinorFunction == 1 )
      {
        if( v10 <= 1 )
        {
          v38 = WmipFindRegEntryByProviderId(*(unsigned int *)(v13 + 4));
          if( !v38 )
            goto LABEL_69;
          Flink = (_DEVICE_OBJECT *)v38[1].Flink;
          WmipUnreferenceRegEntry((_REGENTRY *)v38);
        }
        v39 = *(unsigned int *)(v13 + 56);
        LODWORD(BufferAvail) = v14 - v39;
        LODWORD(InstanceCount) = 1;
        return WmipQueryWmiDataBlock(
                 Flink,
                 Irp,
                 v10,
                 (unsigned int)RegistryPath,
                 (UINT64)InstanceCount,
                 (UINT64 *)(v13 + 60),
                 BufferAvail,
                 (UINT8 *)(v13 + v39));
      }
      if( MinorFunction != 2 && MinorFunction != 3 )
        goto LABEL_78;
      v20 = -1073741114;
      Irp->IoStatus.Status = -1073741114;
LABEL_79:
      Irp->IoStatus.Information = 0i64;
      goto LABEL_45;
    }
    if( MinorFunction == 6 || MinorFunction == 7 )
    {
LABEL_78:
      v20 = 0;
      Irp->IoStatus.Status = 0;
      goto LABEL_79;
    }
    if( MinorFunction != 8 )
    {
      if( MinorFunction == 9 )
      {
        v20 = -1073741808;
        Irp->IoStatus.Status = -1073741808;
        goto LABEL_79;
      }
      if( MinorFunction != 11 )
        return -1073741808;
    }
    RegistryPath = 0i64;
    LODWORD(RegFlags) = 0;
    v22 = 0;
    v46 = 0i64;
    InstanceName = 0i64;
    v23 = WmipQueryWmiRegInfo(Flink, &RegFlags, &InstanceName, &RegistryPath);
    v24 = InstanceName.Buffer;
    v20 = v23;
    if( v23 >= 0 )
    {
      v25 = RegFlags;
      if( (RegFlags & 0x20) == 0 && !InstanceName.Buffer )
      {
        v20 = -1073741808;
LABEL_43:
        Irp->IoStatus.Information = v22;
LABEL_44:
        Irp->IoStatus.Status = v20;
LABEL_45:
        IofCompleteRequest(Irp, 0);
        return v20;
      }
      Length = InstanceName.Length;
      if( (RegFlags & 0x20) != 0 )
      {
        v28 = 0i64;
        v27 = 248;
      }
      else
      {
        v25 = RegFlags | 4;
        v27 = InstanceName.Length + 250;
        LODWORD(RegFlags) = RegFlags | 4;
        v28 = 248i64;
      }
      v29 = (_UNICODE_STRING *)&v46;
      if( RegistryPath )
        v29 = RegistryPath;
      RegistryPath = v29;
      if( v27 < 0xF8 || (v30 = v27 + v29->Length + 2, v30 < v27) )
      {
        v22 = 0;
        v20 = -1073741675;
      }
      else
      {
        *(_DWORD *)v13 = v30;
        v20 = 0;
        if( v30 > v14 )
        {
          v22 = 4;
        }
        else
        {
          v31 = 7i64;
          *(_DWORD *)(v13 + 4) = 0;
          *(_DWORD *)(v13 + 16) = 7;
          v32 = (__int64 *)(v13 + 48);
          *(_DWORD *)(v13 + 12) = 0;
          v33 = &WmipGuidList[2];
          *(_DWORD *)(v13 + 8) = v27;
          do
          {
            *(_OWORD *)(v32 - 3) = *((_OWORD *)v33 - 1);
            v34 = v25 | *((_DWORD *)v33 + 1);
            *v32 = v28;
            *((_DWORD *)v32 - 2) = v34;
            v32 += 4;
            v35 = *(_DWORD *)v33;
            v33 += 3;
            *((_DWORD *)v32 - 9) = v35;
            --v31;
          }
          while( v31 );
          if( (v25 & 4) != 0 )
          {
            *(_WORD *)(v13 + 248) = Length;
            memmove((VOID *)(v13 + 250), InstanceName.Buffer, InstanceName.Length);
            v29 = RegistryPath;
          }
          v36 = (unsigned __int16 *)(v13 + v27);
          *v36 = v29->Length;
          memmove(v36 + 1, RegistryPath->Buffer, RegistryPath->Length);
          v24 = InstanceName.Buffer;
          v22 = v30;
        }
      }
    }
    if( v24 )
      ExFreePoolWithTag(v24, 0);
    goto LABEL_43;
  }
  v37 = -1073741163;
LABEL_52:
  Irp->IoStatus.Status = v37;
  IofCompleteRequest(Irp, 0);
  return v37;
}

Referenced by:

No references.