IoWMISystemControl
NTSTATUS __stdcall IoWMISystemControl(
_WMILIB_INFO *WmiLibInfo,
_DEVICE_OBJECT *DeviceObject,
_IRP *Irp,
INT64 a4,
INT64 a5,
INT8 a6){
UINT64 *v6;
_IO_STACK_LOCATION *CurrentStackLocation;
_DEVICE_OBJECT *Flink;
unsigned int v10;
int Flink_high;
unsigned int MinorFunction;
__int64 v13;
unsigned int v14;
_WMILIB_INFO *v15;
unsigned int v16;
UINT8 *Buffer;
unsigned int v18;
int v20;
unsigned int v22;
NTSTATUS v23;
wchar_t *v24;
int v25;
unsigned __int16 Length;
unsigned int v27;
__int64 v28;
_UNICODE_STRING *v29;
unsigned int v30;
__int64 v31;
__int64 *v32;
__int64 *v33;
int v34;
int v35;
unsigned __int16 *v36;
int v37;
_LIST_ENTRY *v38;
__int64 v39;
INT64 v40;
_LIST_ENTRY *RegEntryByProviderId;
UINT64 *InstanceCount;
CHAR InstanceLengthArray;
UINT64 BufferAvail;
_UNICODE_STRING InstanceName;
__int128 v46;
UINT64 GuidIndex;
UINT64 RegFlags;
_UNICODE_STRING *RegistryPath;
GuidIndex = (UINT64)WmiLibInfo;
v6 = 0i64;
CurrentStackLocation = Irp->Tail.CurrentStackLocation;
Flink = DeviceObject;
LODWORD(GuidIndex) = 0;
v10 = 0;
LODWORD(RegFlags) = 0;
Flink_high = 0;
LODWORD(RegistryPath) = 0;
MinorFunction = CurrentStackLocation->MinorFunction;
if( (unsigned __int8)MinorFunction > 0xBu
|| (_DEVICE_OBJECT *)CurrentStackLocation->Parameters.SecurityContext != DeviceObject
|| !WmipGuidList && (_BYTE)MinorFunction != 11 && (_BYTE)MinorFunction != 8 )
{
v20 = -1073741808;
goto LABEL_44;
}
v13 = *(_QWORD *)&CurrentStackLocation->Parameters.EaLength;
v14 = *(_DWORD *)&CurrentStackLocation->Parameters.FileAttributes;
if( (_BYTE)MinorFunction == 11 || (_BYTE)MinorFunction == 8 )
goto LABEL_10;
if( WmipFindGuid(
(GUIDREGINFO *)WmipGuidList,
7ui64,
*(_GUID **)&CurrentStackLocation->Parameters.Options,
&GuidIndex,
&RegFlags) )
{
if( (unsigned __int8)(MinorFunction - 1) <= 2u || (_BYTE)MinorFunction == 9 )
{
LODWORD(RegistryPath) = *(_DWORD *)(v13 + 52);
if( (*(_DWORD *)(v13 + 44) & 0x80u) == 0 )
{
v37 = -1073741162;
goto LABEL_52;
}
}
v10 = GuidIndex;
Flink_high = RegFlags;
LABEL_10:
v15 = (_WMILIB_INFO *)MinorFunction;
if( MinorFunction <= 5 )
{
if( MinorFunction == 5 )
goto LABEL_78;
if( !(_BYTE)MinorFunction )
{
if( v14 < 0x3C )
{
LODWORD(InstanceCount) = 60;
v40 = 3221225507i64;
return IoWMICompleteRequest(v15, DeviceObject, Irp, v40, (UINT64)InstanceCount, InstanceLengthArray);
}
if( v10 > 1 )
{
LABEL_15:
if( Flink_high )
{
*(_DWORD *)(v13 + 44) &= ~0x10u;
v16 = (8 * Flink_high + 67) & 0xFFFFFFF8;
*(_DWORD *)(v13 + 52) = Flink_high;
*(_DWORD *)(v13 + 48) = v16;
if( v16 > v14 )
{
Buffer = 0i64;
v18 = 0;
}
else
{
v6 = (UINT64 *)(v13 + 60);
Buffer = (UINT8 *)(v13 + v16);
v18 = v14 - v16;
}
LODWORD(BufferAvail) = v18;
LODWORD(InstanceCount) = Flink_high;
return WmipQueryWmiDataBlock(Flink, Irp, v10, 0i64, (UINT64)InstanceCount, v6, BufferAvail, Buffer);
}
LODWORD(InstanceCount) = 0;
v40 = 3221226134i64;
return IoWMICompleteRequest(v15, DeviceObject, Irp, v40, (UINT64)InstanceCount, InstanceLengthArray);
}
RegEntryByProviderId = WmipFindRegEntryByProviderId(*(unsigned int *)(v13 + 4));
if( RegEntryByProviderId )
{
Flink = (_DEVICE_OBJECT *)RegEntryByProviderId[1].Flink;
if( v10 )
Flink_high = 1;
else
Flink_high = HIDWORD(RegEntryByProviderId[3].Flink);
WmipUnreferenceRegEntry((_REGENTRY *)RegEntryByProviderId);
goto LABEL_15;
}
LABEL_69:
LODWORD(InstanceCount) = 0;
v40 = 3221226133i64;
return IoWMICompleteRequest(v15, DeviceObject, Irp, v40, (UINT64)InstanceCount, InstanceLengthArray);
}
if( MinorFunction == 1 )
{
if( v10 <= 1 )
{
v38 = WmipFindRegEntryByProviderId(*(unsigned int *)(v13 + 4));
if( !v38 )
goto LABEL_69;
Flink = (_DEVICE_OBJECT *)v38[1].Flink;
WmipUnreferenceRegEntry((_REGENTRY *)v38);
}
v39 = *(unsigned int *)(v13 + 56);
LODWORD(BufferAvail) = v14 - v39;
LODWORD(InstanceCount) = 1;
return WmipQueryWmiDataBlock(
Flink,
Irp,
v10,
(unsigned int)RegistryPath,
(UINT64)InstanceCount,
(UINT64 *)(v13 + 60),
BufferAvail,
(UINT8 *)(v13 + v39));
}
if( MinorFunction != 2 && MinorFunction != 3 )
goto LABEL_78;
v20 = -1073741114;
Irp->IoStatus.Status = -1073741114;
LABEL_79:
Irp->IoStatus.Information = 0i64;
goto LABEL_45;
}
if( MinorFunction == 6 || MinorFunction == 7 )
{
LABEL_78:
v20 = 0;
Irp->IoStatus.Status = 0;
goto LABEL_79;
}
if( MinorFunction != 8 )
{
if( MinorFunction == 9 )
{
v20 = -1073741808;
Irp->IoStatus.Status = -1073741808;
goto LABEL_79;
}
if( MinorFunction != 11 )
return -1073741808;
}
RegistryPath = 0i64;
LODWORD(RegFlags) = 0;
v22 = 0;
v46 = 0i64;
InstanceName = 0i64;
v23 = WmipQueryWmiRegInfo(Flink, &RegFlags, &InstanceName, &RegistryPath);
v24 = InstanceName.Buffer;
v20 = v23;
if( v23 >= 0 )
{
v25 = RegFlags;
if( (RegFlags & 0x20) == 0 && !InstanceName.Buffer )
{
v20 = -1073741808;
LABEL_43:
Irp->IoStatus.Information = v22;
LABEL_44:
Irp->IoStatus.Status = v20;
LABEL_45:
IofCompleteRequest(Irp, 0);
return v20;
}
Length = InstanceName.Length;
if( (RegFlags & 0x20) != 0 )
{
v28 = 0i64;
v27 = 248;
}
else
{
v25 = RegFlags | 4;
v27 = InstanceName.Length + 250;
LODWORD(RegFlags) = RegFlags | 4;
v28 = 248i64;
}
v29 = (_UNICODE_STRING *)&v46;
if( RegistryPath )
v29 = RegistryPath;
RegistryPath = v29;
if( v27 < 0xF8 || (v30 = v27 + v29->Length + 2, v30 < v27) )
{
v22 = 0;
v20 = -1073741675;
}
else
{
*(_DWORD *)v13 = v30;
v20 = 0;
if( v30 > v14 )
{
v22 = 4;
}
else
{
v31 = 7i64;
*(_DWORD *)(v13 + 4) = 0;
*(_DWORD *)(v13 + 16) = 7;
v32 = (__int64 *)(v13 + 48);
*(_DWORD *)(v13 + 12) = 0;
v33 = &WmipGuidList[2];
*(_DWORD *)(v13 + 8) = v27;
do
{
*(_OWORD *)(v32 - 3) = *((_OWORD *)v33 - 1);
v34 = v25 | *((_DWORD *)v33 + 1);
*v32 = v28;
*((_DWORD *)v32 - 2) = v34;
v32 += 4;
v35 = *(_DWORD *)v33;
v33 += 3;
*((_DWORD *)v32 - 9) = v35;
--v31;
}
while( v31 );
if( (v25 & 4) != 0 )
{
*(_WORD *)(v13 + 248) = Length;
memmove((VOID *)(v13 + 250), InstanceName.Buffer, InstanceName.Length);
v29 = RegistryPath;
}
v36 = (unsigned __int16 *)(v13 + v27);
*v36 = v29->Length;
memmove(v36 + 1, RegistryPath->Buffer, RegistryPath->Length);
v24 = InstanceName.Buffer;
v22 = v30;
}
}
}
if( v24 )
ExFreePoolWithTag(v24, 0);
goto LABEL_43;
}
v37 = -1073741163;
LABEL_52:
Irp->IoStatus.Status = v37;
IofCompleteRequest(Irp, 0);
return v37;
}Referenced by:
No references.